A voir également:
- Virus "c'est pas toi?"
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
46 réponses
slt
Télécharge MSNFix de Laurent
http://sosvirus.changelog.fr/MSNFix.zip
Décompresse-le et double clic sur le fichier MSNFix.bat.
- Exécute l'option R.
--Si l'infection est détectée, exécute l'option N
- Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.
Note :
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.
envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr pour faire evoluer msnfix
----------------------
AVG antispyxare
https://www.01net.com/telecharger/
Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
->Relance AVG AS -> "Analyse" ->"Paramètres"
Sous la question "Comment réagir ?" :
-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse
->Clique sur "Appliquer toutes les actions "
->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
_____________
utilise pour supprimer tes traces
CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
------------
colle le rapport d'un scan en ligne
avec un des suivants:
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
Télécharge MSNFix de Laurent
http://sosvirus.changelog.fr/MSNFix.zip
Décompresse-le et double clic sur le fichier MSNFix.bat.
- Exécute l'option R.
--Si l'infection est détectée, exécute l'option N
- Sauvegarde ce rapport puis fais un copier/coller de ce rapport sur le forum.
Note :
Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal
Sauvegarder et fermer le rapport pour que Windows termine de se lancer normalement.
envoyer le fichier [b] C:\DOCUME~1\florian\Bureau\Upload_Me.zip [/b] sur http://upload.changelog.fr pour faire evoluer msnfix
----------------------
AVG antispyxare
https://www.01net.com/telecharger/
Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
->Relance AVG AS -> "Analyse" ->"Paramètres"
Sous la question "Comment réagir ?" :
-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse
->Clique sur "Appliquer toutes les actions "
->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
_____________
utilise pour supprimer tes traces
CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
------------
colle le rapport d'un scan en ligne
avec un des suivants:
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
Merci beaucoup mais en faisant cette manipulation je n'arrive pas à décompresser le dossier et je n'obtiens pas le dossier MSNFix.bat
Comment je pourrais faire??
Comment je pourrais faire??
Merci beaucoup mais en faisant cette manipulation je n'arrive pas à décompresser le dossier et je n'obtiens pas le dossier MSNFix.bat
Comment je pourrais faire??
Comment je pourrais faire??
ok
a la place de msnfix fais sdfix puis passe a la suite
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
a la place de msnfix fais sdfix puis passe a la suite
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
Voici Le resultat de SDFix ...
SDFix: Version 1.127
Run by Eric on 18/01/2008 at 20:17
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\Eric\Bureau\SDFix
Safe Mode:
Checking Services:
Name:
runtime
Path:
\??\C:\WINDOWS\System32\drivers\runtime.sys
runtime - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\DOCUME~1\Eric\LOCALS~1\Temp\services.exe - Deleted
C:\WINDOWS\mrofinu*.exe - Deleted
C:\WINDOWS\mrofinu*.exe.tmp - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-18 20:29:11
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 66
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"="C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe:*:Disabled:Google Desktop"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Steam\\steamapps\\thierry84\\counter-strike\\hl.exe"="C:\\Program Files\\Steam\\steamapps\\thierry84\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\DOCUME~1\\Eric\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\Eric\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Player2"
"C:\\WINDOWS\\system32\\algs.exe"="C:\\WINDOWS\\system32\\algs.exe:*:Disabled:algs"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
File Backups: - C:\DOCUME~1\Eric\Bureau\SDFix\backups\backups.zip
Files with Hidden Attributes:
Tue 23 Oct 2007 5,903,928 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Wed 28 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 14 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT1.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b8426e25532eb668f59dd4d969b4a550\BITB2.tmp"
Wed 14 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d03f71700772ecd1d20bacc33c473cd5\BIT184C.tmp"
Sun 23 Dec 2007 614,400 A.SH. --- "C:\Documents and Settings\Eric\Bureau\Agathe\Fˆtes 2007\SIV86F.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3e1bc779f4619c0546c190388ad30ab7\download\BITB7.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\794f891ee88c7bba8b5135dcddb15cc4\download\BITB9.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d05de61e582a01d1969c7442eab9add6\download\BITB8.tmp"
Sun 9 Jul 2006 31,232 A..H. --- "C:\Documents and Settings\Eric\Mes documents\Docs Sophie\INTERNAT\Internat\2006-2007\Rentr‚e 2006\~WRL0001.tmp"
Finished!
Que faire ensuite ? ...
Merci Bcp =D
SDFix: Version 1.127
Run by Eric on 18/01/2008 at 20:17
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\Eric\Bureau\SDFix
Safe Mode:
Checking Services:
Name:
runtime
Path:
\??\C:\WINDOWS\System32\drivers\runtime.sys
runtime - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\DOCUME~1\Eric\LOCALS~1\Temp\services.exe - Deleted
C:\WINDOWS\mrofinu*.exe - Deleted
C:\WINDOWS\mrofinu*.exe.tmp - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-18 20:29:11
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 66
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"="C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe:*:Disabled:Google Desktop"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Steam\\steamapps\\thierry84\\counter-strike\\hl.exe"="C:\\Program Files\\Steam\\steamapps\\thierry84\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\DOCUME~1\\Eric\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\Eric\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Player2"
"C:\\WINDOWS\\system32\\algs.exe"="C:\\WINDOWS\\system32\\algs.exe:*:Disabled:algs"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
File Backups: - C:\DOCUME~1\Eric\Bureau\SDFix\backups\backups.zip
Files with Hidden Attributes:
Tue 23 Oct 2007 5,903,928 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Wed 28 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 14 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT1.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b8426e25532eb668f59dd4d969b4a550\BITB2.tmp"
Wed 14 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d03f71700772ecd1d20bacc33c473cd5\BIT184C.tmp"
Sun 23 Dec 2007 614,400 A.SH. --- "C:\Documents and Settings\Eric\Bureau\Agathe\Fˆtes 2007\SIV86F.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\3e1bc779f4619c0546c190388ad30ab7\download\BITB7.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\794f891ee88c7bba8b5135dcddb15cc4\download\BITB9.tmp"
Mon 31 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d05de61e582a01d1969c7442eab9add6\download\BITB8.tmp"
Sun 9 Jul 2006 31,232 A..H. --- "C:\Documents and Settings\Eric\Mes documents\Docs Sophie\INTERNAT\Internat\2006-2007\Rentr‚e 2006\~WRL0001.tmp"
Finished!
Que faire ensuite ? ...
Merci Bcp =D
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bonjour,
ayant eu le virus, j'ai suivi la procédure indiquée, merci pour ces informations et voici le rapport :
SDFix: Version 1.126
Run by a.lenglet on 15/01/2008 at 10:50
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Program Files\Temporary\kernInst.exe - Deleted
C:\DOCUME~1\AB691~1.LEN\LOCALS~1\Temp\services.exe - Deleted
C:\WINDOWS\1?PHolmes*.exe - Deleted
C:\WINDOWS\b12?.exe - Deleted
C:\WINDOWS\mrofinu*.exe - Deleted
C:\WINDOWS\mrofinu*.exe.tmp - Deleted
Folder C:\Program Files\Temporary - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 10:55:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 150
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\DOCUME~1\\AB691~1.LEN\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\AB691~1.LEN\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Player2"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Tue 3 Apr 2007 85,504 A..H. --- "C:\Documents and Settings\a.lenglet\Mes documents\~WRL0005.tmp"
Mon 7 Jan 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 8 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT4.tmp"
Mon 8 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\bbe88a785b5f932c929e655dd1a187d0\BIT5.tmp"
Wed 28 May 2003 65,088 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM"
Wed 28 May 2003 12,732 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM"
Wed 28 May 2003 26,424 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM"
Wed 28 May 2003 28,062 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM"
Wed 28 May 2003 10,710 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM"
Wed 28 May 2003 10,083 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM"
Wed 28 May 2003 10,257 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM"
Wed 28 May 2003 29,499 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM"
Wed 28 May 2003 12,660 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM"
Wed 28 May 2003 11,031 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM"
Wed 28 May 2003 17,952 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM"
Wed 28 May 2003 9,424 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM"
Wed 28 May 2003 13,673 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM"
Wed 28 May 2003 14,438 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM"
Wed 28 May 2003 7,243 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM"
Wed 28 May 2003 24,767 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM"
Wed 28 May 2003 7,463 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM"
Wed 28 May 2003 10,286 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM"
Wed 28 May 2003 25,460 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM"
Wed 28 May 2003 28,866 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM"
Wed 28 May 2003 14,438 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM"
Wed 28 May 2003 8,544 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys"
Wed 28 May 2003 33,149 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys"
Wed 28 May 2003 51,150 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS"
Wed 28 May 2003 35,340 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS"
Wed 28 May 2003 14,378 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS"
Wed 28 May 2003 37,984 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS"
Wed 28 May 2003 44,828 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8U2.SYS"
Wed 28 May 2003 29,628 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS"
Wed 28 May 2003 52,106 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS"
Wed 28 May 2003 49,250 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS"
Wed 28 May 2003 50,600 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS"
Wed 28 May 2003 161,792 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS"
Wed 28 May 2003 174,080 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys"
Wed 28 May 2003 21,971 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTCDROM.SYS"
Wed 28 May 2003 30,955 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTDOSM.SYS"
Wed 28 May 2003 202,517 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE"
Wed 28 May 2003 374,038 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE"
Wed 28 May 2003 22,158 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS"
Wed 28 May 2003 1,608 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DEVICE.COM"
Wed 28 May 2003 15,345 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS"
Wed 28 May 2003 7,840 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS"
Wed 28 May 2003 56,821 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE"
Wed 28 May 2003 64,425 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\FLASHPT.SYS"
Wed 28 May 2003 32,396 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE"
Wed 28 May 2003 14,160 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS"
Wed 28 May 2003 10,898 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYB.COM"
Wed 28 May 2003 53,556 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS"
Wed 28 May 2003 15,777 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MODE.COM"
Wed 28 May 2003 37,681 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MOUSE.COM"
Wed 28 May 2003 354,304 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys"
Wed 28 May 2003 21,180 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE"
Wed 28 May 2003 354,263 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe"
Wed 28 May 2003 8,513 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\NETBIND.COM"
Wed 28 May 2003 41,302 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OAKCDROM.SYS"
Wed 28 May 2003 129,240 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE"
Wed 28 May 2003 28,439 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Paralink.com"
Wed 28 May 2003 13,770 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE"
Wed 28 May 2003 130,980 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE"
Wed 28 May 2003 11,854 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM"
Wed 28 May 2003 52,715 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM"
Wed 28 May 2003 62,391 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM"
Wed 28 May 2003 11,491 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com"
Wed 28 May 2003 17,791 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com"
Wed 28 May 2003 17,043 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com"
Wed 28 May 2003 11,786 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com"
Wed 28 May 2003 18,300 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com"
Wed 28 May 2003 48,224 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com"
Wed 28 May 2003 13,360 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com"
Wed 28 May 2003 9,190 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com"
Wed 28 May 2003 12,567 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com"
Wed 28 May 2003 44,640 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM"
Wed 28 May 2003 56,896 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com"
Wed 28 May 2003 44,640 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com"
Wed 28 May 2003 9,692 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com"
Wed 28 May 2003 9,537 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM"
Wed 28 May 2003 32,484 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com"
Wed 28 May 2003 52,225 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe"
Wed 28 May 2003 48,491 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe"
Wed 28 May 2003 50,405 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com"
Wed 28 May 2003 33,860 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe"
Wed 28 May 2003 50,175 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe"
Wed 28 May 2003 50,795 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe"
Wed 28 May 2003 48,223 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com"
Wed 28 May 2003 48,641 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe"
Wed 28 May 2003 49,015 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com"
Tue 19 Dec 2006 30,720 A..H. --- "C:\Documents and Settings\a.lenglet\Bureau\S.E.R.S.I.M.T\Dr Le Tourneau\CRC Sofinco Clichy\VE\VE avec m‚d du 23.11.06\~WRL0001.tmp"
Wed 28 May 2003 53,786 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\command.com"
Wed 28 May 2003 44,240 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM"
Wed 28 May 2003 42,550 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM"
Tue 3 Apr 2007 36,385,280 A..H. --- "C:\Documents and Settings\a.lenglet\Bureau\S.E.R.S.I.M.T\Dr Le Tourneau\CRC Sofinco Clichy\‚tudes\conseils pour l'am‚agement spatial et l'organisation des postes 19.12.06\rapport\~WRL0353.tmp"
Tue 3 Apr 2007 388,608 A..H. --- "C:\Documents and Settings\a.lenglet\Bureau\S.E.R.S.I.M.T\Dr Le Tourneau\CRC Sofinco Clichy\‚tudes\conseils pour l'am‚agement spatial et l'organisation des postes 19.12.06\rapport\~WRL3407.tmp"
Finished!
ayant eu le virus, j'ai suivi la procédure indiquée, merci pour ces informations et voici le rapport :
SDFix: Version 1.126
Run by a.lenglet on 15/01/2008 at 10:50
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Program Files\Temporary\kernInst.exe - Deleted
C:\DOCUME~1\AB691~1.LEN\LOCALS~1\Temp\services.exe - Deleted
C:\WINDOWS\1?PHolmes*.exe - Deleted
C:\WINDOWS\b12?.exe - Deleted
C:\WINDOWS\mrofinu*.exe - Deleted
C:\WINDOWS\mrofinu*.exe.tmp - Deleted
Folder C:\Program Files\Temporary - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 10:55:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 150
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\DOCUME~1\\AB691~1.LEN\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\AB691~1.LEN\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Player2"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Tue 3 Apr 2007 85,504 A..H. --- "C:\Documents and Settings\a.lenglet\Mes documents\~WRL0005.tmp"
Mon 7 Jan 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Mon 8 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT4.tmp"
Mon 8 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\bbe88a785b5f932c929e655dd1a187d0\BIT5.tmp"
Wed 28 May 2003 65,088 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM"
Wed 28 May 2003 12,732 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM"
Wed 28 May 2003 26,424 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM"
Wed 28 May 2003 28,062 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM"
Wed 28 May 2003 10,710 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM"
Wed 28 May 2003 10,083 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM"
Wed 28 May 2003 10,257 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM"
Wed 28 May 2003 29,499 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM"
Wed 28 May 2003 12,660 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM"
Wed 28 May 2003 11,031 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM"
Wed 28 May 2003 17,952 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM"
Wed 28 May 2003 9,424 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM"
Wed 28 May 2003 13,673 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM"
Wed 28 May 2003 14,438 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM"
Wed 28 May 2003 7,243 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM"
Wed 28 May 2003 24,767 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM"
Wed 28 May 2003 7,463 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM"
Wed 28 May 2003 7,825 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM"
Wed 28 May 2003 10,286 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM"
Wed 28 May 2003 25,460 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM"
Wed 28 May 2003 28,866 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM"
Wed 28 May 2003 14,438 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM"
Wed 28 May 2003 8,544 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys"
Wed 28 May 2003 33,149 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys"
Wed 28 May 2003 51,150 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS"
Wed 28 May 2003 35,340 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS"
Wed 28 May 2003 14,378 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS"
Wed 28 May 2003 37,984 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS"
Wed 28 May 2003 44,828 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8U2.SYS"
Wed 28 May 2003 29,628 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS"
Wed 28 May 2003 52,106 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS"
Wed 28 May 2003 49,250 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS"
Wed 28 May 2003 50,600 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS"
Wed 28 May 2003 161,792 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS"
Wed 28 May 2003 174,080 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys"
Wed 28 May 2003 21,971 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTCDROM.SYS"
Wed 28 May 2003 30,955 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTDOSM.SYS"
Wed 28 May 2003 202,517 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE"
Wed 28 May 2003 374,038 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE"
Wed 28 May 2003 22,158 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS"
Wed 28 May 2003 1,608 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DEVICE.COM"
Wed 28 May 2003 15,345 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS"
Wed 28 May 2003 7,840 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS"
Wed 28 May 2003 56,821 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE"
Wed 28 May 2003 64,425 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\FLASHPT.SYS"
Wed 28 May 2003 32,396 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE"
Wed 28 May 2003 14,160 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS"
Wed 28 May 2003 10,898 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYB.COM"
Wed 28 May 2003 53,556 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS"
Wed 28 May 2003 15,777 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MODE.COM"
Wed 28 May 2003 37,681 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MOUSE.COM"
Wed 28 May 2003 354,304 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys"
Wed 28 May 2003 21,180 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE"
Wed 28 May 2003 354,263 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe"
Wed 28 May 2003 8,513 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\NETBIND.COM"
Wed 28 May 2003 41,302 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OAKCDROM.SYS"
Wed 28 May 2003 129,240 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE"
Wed 28 May 2003 28,439 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Paralink.com"
Wed 28 May 2003 13,770 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE"
Wed 28 May 2003 130,980 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE"
Wed 28 May 2003 11,854 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM"
Wed 28 May 2003 52,715 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM"
Wed 28 May 2003 62,391 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM"
Wed 28 May 2003 11,491 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com"
Wed 28 May 2003 17,791 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com"
Wed 28 May 2003 17,043 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com"
Wed 28 May 2003 11,786 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com"
Wed 28 May 2003 18,300 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com"
Wed 28 May 2003 48,224 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com"
Wed 28 May 2003 13,360 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com"
Wed 28 May 2003 9,190 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com"
Wed 28 May 2003 12,567 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com"
Wed 28 May 2003 44,640 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM"
Wed 28 May 2003 56,896 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com"
Wed 28 May 2003 44,640 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com"
Wed 28 May 2003 9,692 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com"
Wed 28 May 2003 9,537 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM"
Wed 28 May 2003 32,484 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com"
Wed 28 May 2003 52,225 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe"
Wed 28 May 2003 48,491 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe"
Wed 28 May 2003 50,405 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com"
Wed 28 May 2003 33,860 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe"
Wed 28 May 2003 50,175 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe"
Wed 28 May 2003 50,795 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe"
Wed 28 May 2003 48,223 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com"
Wed 28 May 2003 48,641 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe"
Wed 28 May 2003 49,015 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com"
Tue 19 Dec 2006 30,720 A..H. --- "C:\Documents and Settings\a.lenglet\Bureau\S.E.R.S.I.M.T\Dr Le Tourneau\CRC Sofinco Clichy\VE\VE avec m‚d du 23.11.06\~WRL0001.tmp"
Wed 28 May 2003 53,786 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\command.com"
Wed 28 May 2003 44,240 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM"
Wed 28 May 2003 42,550 A..H. --- "C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM"
Tue 3 Apr 2007 36,385,280 A..H. --- "C:\Documents and Settings\a.lenglet\Bureau\S.E.R.S.I.M.T\Dr Le Tourneau\CRC Sofinco Clichy\‚tudes\conseils pour l'am‚agement spatial et l'organisation des postes 19.12.06\rapport\~WRL0353.tmp"
Tue 3 Apr 2007 388,608 A..H. --- "C:\Documents and Settings\a.lenglet\Bureau\S.E.R.S.I.M.T\Dr Le Tourneau\CRC Sofinco Clichy\‚tudes\conseils pour l'am‚agement spatial et l'organisation des postes 19.12.06\rapport\~WRL3407.tmp"
Finished!
comme indiqué dans mon premier message fais ca:
AVG antispyware
https://www.01net.com/
Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
->Relance AVG AS -> "Analyse" ->"Paramètres"
Sous la question "Comment réagir ?" :
-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse
->Clique sur "Appliquer toutes les actions "
->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
_____________
utilise pour supprimer tes traces
CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
https://www.01net.com/
------------
colle le rapport d'un scan en ligne
avec un des suivants:
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
AVG antispyware
https://www.01net.com/
Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
->Relance AVG AS -> "Analyse" ->"Paramètres"
Sous la question "Comment réagir ?" :
-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse
->Clique sur "Appliquer toutes les actions "
->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
_____________
utilise pour supprimer tes traces
CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
https://www.01net.com/
------------
colle le rapport d'un scan en ligne
avec un des suivants:
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
Run by Fanny chaldebas on 15/01/2008 at 17:46
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\DOCUME~1\FANNYC~1\LOCALS~1\Temp\services.exe - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 18:07:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 71
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"="C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat"="C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat:*:Enabled:La Bataille pour la Terre du Milieu(tm)"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\DOCUME~1\\FANNYC~1\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\FANNYC~1\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Player2"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 11 Nov 2006 88 A.SHR --- "C:\i386\0C9A1BD7DE.sys"
Sat 11 Nov 2006 2,828 A.SH. --- "C:\i386\KGyGaAvL.sys"
Mon 31 Dec 2007 168 ..SHR --- "C:\WINDOWS\system32\0C9A1BD7DE.sys"
Mon 31 Dec 2007 5,642 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 11 Feb 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 18 May 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 29 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT37.tmp"
Fri 5 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b8426e25532eb668f59dd4d969b4a550\BIT29.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Finished!
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\DOCUME~1\FANNYC~1\LOCALS~1\Temp\services.exe - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-15 18:07:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 71
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"="C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat"="C:\\Program Files\\EA GAMES\\La Bataille pour la Terre du Milieu(tm)\\game.dat:*:Enabled:La Bataille pour la Terre du Milieu(tm)"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\DOCUME~1\\FANNYC~1\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\FANNYC~1\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Player2"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 11 Nov 2006 88 A.SHR --- "C:\i386\0C9A1BD7DE.sys"
Sat 11 Nov 2006 2,828 A.SH. --- "C:\i386\KGyGaAvL.sys"
Mon 31 Dec 2007 168 ..SHR --- "C:\WINDOWS\system32\0C9A1BD7DE.sys"
Mon 31 Dec 2007 5,642 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 11 Feb 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 18 May 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 29 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT37.tmp"
Fri 5 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b8426e25532eb668f59dd4d969b4a550\BIT29.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp"
Sun 5 Nov 2006 8 A..H. --- "C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp"
Finished!
Moi aussi j'ai egalement reçu ce virus mais quand jarrive a l'étape de mètre " R" et taper entré a MSNFIX rien ne poursuis !
Help !
Help !
Voila mon rapport AVG AS
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 19:20:09 15/01/2008
+ Résultat de l'analyse:
C:\Program Files\Fichiers communs\Uninstall Information\RemoveWebDP.exe -> Adware.DelphinMediaViewer : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\nfomon\nfo.ocx -> Adware.DelphinMediaViewer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-21-1004336348-796845957-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39F25B12-74FF-4079-A51F-1D70F5B08B84} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Mes documents\A_GARDER_SUR_LE_BUREAU\Mes fichiers reçus\GONZOGRINGO525140390\photo album2007.pif -> Backdoor.IRCBot.aaq : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Mes documents\A_GARDER_SUR_LE_BUREAU\Mes fichiers reçus\photo album2007.pif -> Backdoor.IRCBot.aaq : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Dot1XCfg\Dot1XCfg.exe -> Downloader.Adload.pr : Nettoyé et sauvegardé (mise en quarantaine).
[2104] C:\Program Files\Dot1XCfg\Dot1XCfg.exe -> Downloader.Adload.pr : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\b122.exe -> Downloader.Agent.erf : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\17PHolmes1148.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\mrofinu1148.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\mrofinu1148.exe.tmp -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP286\A0296384.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP286\A0296390.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP286\A0296391.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP285\A0296351.exe -> Not-A-Virus.Hacktool.EvID : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.578:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.579:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.580:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.581:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.582:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.583:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.196:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.197:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.198:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.199:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.200:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.201:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.202:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.203:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.204:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.205:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.206:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.207:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.208:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.209:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.212:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.213:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.214:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.215:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.227:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.601:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.659:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.690:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.366:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.71i : Nettoyé.
:mozilla.434:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adjuggler : Nettoyé.
:mozilla.435:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adjuggler : Nettoyé.
:mozilla.702:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.703:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.704:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.705:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.706:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.384:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.45:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.46:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.47:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.48:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.463:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.42:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.217:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.718:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.719:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.720:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.721:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.722:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.723:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.724:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.380:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.381:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.383:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.524:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Cqcounter : Nettoyé.
:mozilla.540:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.541:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.49:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.515:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Esomniture : Nettoyé.
:mozilla.516:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Esomniture : Nettoyé.
:mozilla.762:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Esomniture : Nettoyé.
:mozilla.324:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.138:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.139:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.140:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.142:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.143:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.103:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.104:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.105:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.106:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.236:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.549:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.618:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.650:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.672:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.681:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.475:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.477:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.478:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.479:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.559:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.560:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.370:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Ivwbox : Nettoyé.
:mozilla.362:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Liveperson : Nettoyé.
:mozilla.365:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Liveperson : Nettoyé.
:mozilla.172:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.173:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.26:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.22:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.23:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.24:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.309:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.310:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.311:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.312:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.313:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.314:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.315:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.316:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.33:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.34:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.35:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.36:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.37:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.483:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.488:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.489:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.490:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.495:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.496:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.497:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.498:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.499:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.500:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.501:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.502:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.503:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.504:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.505:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.506:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.273:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.274:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.275:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.276:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.277:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.268:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.38:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.39:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.40:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.41:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.687:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.354:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.355:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.356:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.357:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.358:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.726:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.727:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.728:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
C:\WINDOWS\system32\wnsintsv.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 19:20:09 15/01/2008
+ Résultat de l'analyse:
C:\Program Files\Fichiers communs\Uninstall Information\RemoveWebDP.exe -> Adware.DelphinMediaViewer : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\nfomon\nfo.ocx -> Adware.DelphinMediaViewer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-21-1004336348-796845957-1801674531-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{39F25B12-74FF-4079-A51F-1D70F5B08B84} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Mes documents\A_GARDER_SUR_LE_BUREAU\Mes fichiers reçus\GONZOGRINGO525140390\photo album2007.pif -> Backdoor.IRCBot.aaq : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Mes documents\A_GARDER_SUR_LE_BUREAU\Mes fichiers reçus\photo album2007.pif -> Backdoor.IRCBot.aaq : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Dot1XCfg\Dot1XCfg.exe -> Downloader.Adload.pr : Nettoyé et sauvegardé (mise en quarantaine).
[2104] C:\Program Files\Dot1XCfg\Dot1XCfg.exe -> Downloader.Adload.pr : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\b122.exe -> Downloader.Agent.erf : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\17PHolmes1148.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\mrofinu1148.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\GONZO\Bureau\MSNFix\backup\mrofinu1148.exe.tmp -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP286\A0296384.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP286\A0296390.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP286\A0296391.exe -> Downloader.Agent.gwh : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{F943E54A-A4BC-4315-9C3C-42077260E1A1}\RP285\A0296351.exe -> Not-A-Virus.Hacktool.EvID : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.578:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.579:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.580:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.581:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.582:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.583:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.196:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.197:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.198:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.199:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.200:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.201:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.202:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.203:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.204:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.205:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.206:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.207:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.208:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.209:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.212:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.213:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.214:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.215:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.227:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.601:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.659:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.690:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.366:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.71i : Nettoyé.
:mozilla.434:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adjuggler : Nettoyé.
:mozilla.435:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adjuggler : Nettoyé.
:mozilla.702:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.703:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.704:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.705:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.706:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.384:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.45:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.46:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.47:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.48:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.463:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.42:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.217:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.718:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.719:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.720:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.721:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.722:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.723:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.724:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.380:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.381:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.383:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.524:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Cqcounter : Nettoyé.
:mozilla.540:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.541:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.49:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.515:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Esomniture : Nettoyé.
:mozilla.516:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Esomniture : Nettoyé.
:mozilla.762:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Esomniture : Nettoyé.
:mozilla.324:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.138:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.139:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.140:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.142:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.143:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.103:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.104:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.105:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.106:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.236:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.549:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.618:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.650:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.672:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.681:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.475:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.477:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.478:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.479:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.559:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.560:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.370:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Ivwbox : Nettoyé.
:mozilla.362:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Liveperson : Nettoyé.
:mozilla.365:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Liveperson : Nettoyé.
:mozilla.172:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.173:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.26:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.22:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.23:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.24:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.309:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.310:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.311:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.312:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.313:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.314:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.315:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.316:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.33:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.34:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.35:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.36:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.37:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.483:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.488:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.489:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.490:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.495:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.496:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.497:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.498:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.499:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.500:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.501:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.502:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.503:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.504:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.505:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.506:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.273:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.274:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.275:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.276:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.277:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.268:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.38:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.39:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.40:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.41:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.687:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.354:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.355:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.356:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.357:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.358:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.726:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.727:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.728:C:\Documents and Settings\GONZO\Application Data\Mozilla\Firefox\Profiles\c7ol9yoo.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
C:\WINDOWS\system32\wnsintsv.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
J'ai ce même virus, je suis la procédure mais je n'arrive pas à ouvrir le fichier msnfix.bat,ils me disent de le dcompresser je ne c pas comen faire !
Re
Mon rapport AVG est tellement lourd (!) ... un nombre de cookies défiant toute concurrence (près de 20 000) a été identifié ainsi que 3 trojans ... que je ne peux même pas le poster ... (je souhaite tout de même préciser que je viens de récupérer cet ordi et sans protection .. il est désormais équipé d'un firewall et d'un scan. Une idée pour que je puisse le faire paraître ?? Merci d'avance de la réponse.
Mon rapport AVG est tellement lourd (!) ... un nombre de cookies défiant toute concurrence (près de 20 000) a été identifié ainsi que 3 trojans ... que je ne peux même pas le poster ... (je souhaite tout de même préciser que je viens de récupérer cet ordi et sans protection .. il est désormais équipé d'un firewall et d'un scan. Une idée pour que je puisse le faire paraître ?? Merci d'avance de la réponse.
utilise ccleaner pour virer les cookies
CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
-----------------------
CCLEANER: (lance un nettoyage et répare 3 fois les erreurs) sans installer la barre yahoo
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
-----------------------
Moi aussi, j'ai eu le même virus, je l'ai supprimé avec Avast mais sous le bugue intempestif lié à mSN, j'ai éteins mon ordi à la main.
Depuis, je le rallume, je mets redémarrer normalement ou autres, et après sa tentative de redémarrage, je retombe toujours sur les propositions de rédémarrage.
Quelqu'un a t-il une solution ?
Depuis, je le rallume, je mets redémarrer normalement ou autres, et après sa tentative de redémarrage, je retombe toujours sur les propositions de rédémarrage.
Quelqu'un a t-il une solution ?
CHARMAS !
Pour décompresser le dossier msnfiix.bat
c'est simple tu vas là
==> https://www.commentcamarche.net/telecharger/utilitaires/24097-winrar/
tu cliques sur: " télecharger la version d''évalution "
Ensuite une fois tu as télecharger winrar
tu place la flèche de ta souris sur le programme MSNFIX.bat et tu clique sur le bouton droit de ta souris, il apparait un menu déroulant tu choisis "extraire ici "
Et là le programme va se décompresser là ou tu es.
Ensuite tu fais ce qui a été écrit en haut de cette page et ça marche ,
il n'y a aucun soucis, moi je me suis débarassé de ce virus en 1heure (en fait en meme pas 10 minutes , mais c'est car il faut attendre que lantispyware AVG fasse une analyse entière de ton PC et si t'as bcp de chose, c'est long)
RESOLUTION POUR 2008: ARRETER D'ACCEPTER TT CE QUE MES IMBéCILES DE CONTACT ME BALANCE SUR MSN.
Pour décompresser le dossier msnfiix.bat
c'est simple tu vas là
==> https://www.commentcamarche.net/telecharger/utilitaires/24097-winrar/
tu cliques sur: " télecharger la version d''évalution "
Ensuite une fois tu as télecharger winrar
tu place la flèche de ta souris sur le programme MSNFIX.bat et tu clique sur le bouton droit de ta souris, il apparait un menu déroulant tu choisis "extraire ici "
Et là le programme va se décompresser là ou tu es.
Ensuite tu fais ce qui a été écrit en haut de cette page et ça marche ,
il n'y a aucun soucis, moi je me suis débarassé de ce virus en 1heure (en fait en meme pas 10 minutes , mais c'est car il faut attendre que lantispyware AVG fasse une analyse entière de ton PC et si t'as bcp de chose, c'est long)
RESOLUTION POUR 2008: ARRETER D'ACCEPTER TT CE QUE MES IMBéCILES DE CONTACT ME BALANCE SUR MSN.