.exe n'est pas une application win32 valide

sebjseb -  
 Utilisateur anonyme -
Bonjour à tous,

J'ai un gros souci sur mon pc je ne peux plus lancer d'antivirus!

Un message d'erreur apparait sur mon pc, il s'agit du message suivant:
D:\Programmes\Spybots\Spybot - Search & Destroy\SpybotSD.exe n'est pas une application Win32 valide

Que veux dire ce message?

Je suis alleé sur google et j'ai lancé un scan avec panda et il m'a donné une liste de virus et spyware après le scan, voici la liste du scan:

Incident Statut Analyse

Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@advertising[2].txt
Spyware:Cookie/Atlas DMT No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@atdmt[2].txt
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@bluestreak[2].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@bs.serving-sys[2].txt
Spyware:Cookie/Doubleclick No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@doubleclick[2].txt
Spyware:Cookie/FastClick No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@fastclick[2].txt
Spyware:Cookie/Mediaplex No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@mediaplex[1].txt
Spyware:Cookie/QuestionMarket No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@questionmarket[2].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@serving-sys[2].txt
Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@tradedoubler[1].txt
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@weborama[1].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\Kiki\Cookies\kiki@xiti[1].txt
Spyware:Cookie/Atlas DMT No Désinfecté C:\Documents and Settings\Kiki\Local Settings\Temp\Cookies\kiki@atdmt[2].txt
Spyware:Cookie/Mediaplex No Désinfecté C:\Documents and Settings\Kiki\Local Settings\Temp\Cookies\kiki@mediaplex[1].txt
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Kiki\Local Settings\Temp\Cookies\kiki@weborama[2].txt
Spyware:Cookie/RealMedia No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@247realmedia[1].txt
Spyware:Cookie/YieldManager No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@ad.yieldmanager[2].txt
Spyware:Cookie/PointRoll No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@ads.pointroll[1].txt
Spyware:Cookie/Adtech No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@adtech[2].txt
Spyware:Cookie/Adverserve No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@adverserve[1].txt
Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@advertising[2].txt
Spyware:Cookie/Falkag No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@as-eu.falkag[1].txt
Spyware:Cookie/Falkag No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@as1.falkag[2].txt
Spyware:Cookie/Atlas DMT No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@atdmt[2].txt
Spyware:Cookie/Azjmp No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@azjmp[1].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@bs.serving-sys[1].txt
Spyware:Cookie/Bridgetrack No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@citi.bridgetrack[1].txt
Spyware:Cookie/Doubleclick No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@doubleclick[1].txt
Spyware:Cookie/FastClick No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@fastclick[2].txt
Spyware:Cookie/Comclick No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@fl01.ct2.comclick[1].txt
Spyware:Cookie/Mediaplex No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@mediaplex[1].txt
Spyware:Cookie/Overture No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@overture[2].txt
Spyware:Cookie/QuestionMarket No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@questionmarket[2].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@serving-sys[2].txt
Spyware:Cookie/Smartadserver No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@smartadserver[1].txt
Spyware:Cookie/Valueclick No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@valueclick[1].txt
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@weborama[2].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@xiti[1].txt
Spyware:Cookie/Yadro No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@yadro[2].txt
Spyware:Cookie/Adserver No Désinfecté C:\Documents and Settings\Maman\Cookies\maman@z1.adserver[1].txt
Spyware:Cookie/RealMedia No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@247realmedia[1].txt
Spyware:Cookie/Adtech No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@adtech[1].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@bs.serving-sys[2].txt
Spyware:Cookie/fe.lea.lycos No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@fe.lea.lycos[1].txt
Spyware:Cookie/Comclick No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@fl01.ct2.comclick[1].txt
Spyware:Cookie/MetriWeb No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@metriweb[1].txt
Spyware:Cookie/Overture No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@overture[1].txt
Spyware:Cookie/Serving-sys No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@serving-sys[2].txt
Spyware:Cookie/Smartadserver No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@smartadserver[1].txt
Spyware:Cookie/Weborama No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@weborama[1].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\Seb\Cookies\seb@xiti[1].txt
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\25WXSIZ0\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\25WXSIZ0\b64_1[2].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\25WXSIZ0\b64_1[3].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\25WXSIZ0\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_1[2].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[2].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[3].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[4].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[5].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[6].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[7].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\3KJREC2H\b64_31[8].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\6FWAQX8X\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\KG3NHVDD\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\KG3NHVDD\b64_1[2].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\L3U9KUL3\b64_1[1].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\L3U9KUL3\b64_2[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\L3U9KUL3\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\L3U9KUL3\b64_31[2].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\L3U9KUL3\b64_31[3].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\QWO5951W\b64_1[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\QWO5951W\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_1[1].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_2[1].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_2[2].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_2[3].jpg
Virus:W32/Bagle.QV.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_2[4].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_31[2].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_31[3].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_31[4].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\TQKCX4WV\b64_31[5].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\XKJIT5HA\b64_31[1].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\XKJIT5HA\b64_31[2].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\Documents and Settings\Seb\Local Settings\Temporary Internet Files\Content.IE5\XKJIT5HA\b64_31[3].jpg
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\104843.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\120593.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\14600578.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\14611500.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\1592125.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\1599609.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\1610234.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\228671.exe
Virus:W32/Bagle.QV.worm Désinfecté C:\WINDOWS\system32\drivers\down\3534250.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\3541078.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\3549515.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\376937.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\390281.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\50500.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\51562.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\52531.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\54015.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\54125.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\54312.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\55953.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\61765.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\62375.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\65140.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\65156.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\65796.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\67109.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\70437.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\70859.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\70921.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\70937.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\71859.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\71968.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\72984.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\73031.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\74437.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\76000.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\76484.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\79546.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\80296.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\81812.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\84593.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\85328.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\drivers\down\96109.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\mdelk.exe
Virus:W32/Bagle.RC.worm Désinfecté C:\WINDOWS\system32\wintems.exe
Outil indésirable:Application/Messengerskinner No Désinfecté C:\WINDOWS\Temp\NSIS_Install_WMP.exe[²ÜÇ\NSUtils.dll]

Je suis allé sur google en tapant bagle mais je ne comprends pas ce qui faut faire exactement pour supprimer ce virus!

Qui pourrait m'aider?

Merci d'avance
Configuration: Windows XP
Internet Explorer 7.0
Configuration: Windows XP
Internet Explorer 7.0

9 réponses

  1. Utilisateur anonyme
     
    Bonsoir ,

    Va sur ce site :

    http://www.zonavirus.com/datos/descargas/95/elibagla.asp

    En bas de cette page tu trouveras un outil à télécharger, clique sur "Descargar Elibagla" (le numéro de version change au fur et à mesure des mises à jour)
    installe ce fichier sur le bureau.
    ensuite double-clic sur Elibagla.exe

    Vérifie que la case "eliminar ficheros automaticamente" est cochée

    Clique sur "explorar" puis laisse-le travailler.

    Puis poste moi le rapport situé dans C:\infosat.txt

    *************

    Télécharge HJT

    Place le dans ' C:\programmes\ ' Une fois cela fait , merci de renommer le fichier ' Hijackthis.exe '(situé dans le dossier dans C:\ ) en HJT.exe

    Le chemin d'accés du programme doit être ressemblant à celui-ci : C:\Programme\Hijackthis\HJT.exe

    Puis lance-le et choisi l'option '' do a system scan and save a logfile '' et poste moi le rapport ( qui apparait sur le bloc-note )

    Tuto si tu n'y arrive pas : http://pageperso.aol.fr/balltrap34/demohijack.htm

    A+ ( demain probablement )
    0
    1. sebjseb
       
      Voici le rapport de HJT:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:31:37, on 10/02/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16574)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      D:\Programmes\Daemon\DAEMON Tools\daemon.exe
      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      C:\Program Files\Power Cinema\PowerVCR II\Agent.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\WINDOWS\ZSSnp211.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\Domino.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
      O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programmes\Daemon\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      O4 - HKLM\..\Run: [Agent] C:\Program Files\Power Cinema\PowerVCR II\Agent.exe
      O4 - HKLM\..\Run: [Remote_Agent] C:\Program Files\Power Cinema\PowerVCR II\RemoteAgent.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
      O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [BitTorrent] "D:\Programmes\Bit Torrent\bittorrent.exe" --force_start_minimized
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: Eurobarre.lnk = C:\Program Files\Eurobarre\eb.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: Add to AMV Converter... - C:\Documents and Settings\Seb\Bureau\baladeur\AMVConverter\grab.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Documents and Settings\Seb\Bureau\baladeur\MediaManager\grab.html
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
      O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      0
      1. Utilisateur anonyme > sebjseb
         
        Re ,

        1)Va dans ' poste de travail ' > ' Outil ' > ' Options des dossiers ' > Onglet ' Affichage '

        2)Active le bouton ' Afficher les fichiers et dossiers cachés '
        3)Décoche ' Masquer les fichiers protégés du systeme d'exploitation ( recommandé ) '
        4)Décoche ' Masquer les extensions dont le type est connu '

        5)Va sur ce site --> https://www.virustotal.com/gui/

        Clique sur ' parcourir '

        Cherche ces fichiers en gras : ( envois les 1 par 1 )


        C:\WINDOWS\ZSSnp211.exe


        C:\WINDOWS\Domino.exe






        Clique sur ' send '

        Un rapport va s'élaborer ligne à ligne.

        Attends la fin. Il doit comprendre la taille du fichier envoyé.

        Sauvegarde le rapport avec le bloc-note.

        -> Poste le moi stp.

        *************************

        Puis va sur ce site : http://virusscan.jotti.org/de/


        Et fait analyser le même fichier -> poste le rapport.

        ****************

        Relance hijackthis , Choisis ' Do a system scan ' Et fixe ces lignes : ( coche la case à leurs gauches > ' fixchecked ')

        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

        **********

        C:\Program Files\Eurobarre\eb.exe <-- Eurobarre balance des pubs , a toi de décider si tu le garde ou non.

        *****

        Voila j'attends les rapports ;)
        A+

        0
    2. quiksilver1956
       
      Bonjour,
      J'ai exactement le même probleme, et si vous pouviez m'aider....
      je travaille sur packard bell de bureau IXTREME 9445 Intel pentium 2,4 GHZ
      A la suite de désinstallation d'un programme par ajout/suppr, je pense, je ne peux plus reinstaller de nx logiciels... Cependant il demarre normalement, fonctionne normalement sur internet et les progarmmes installés aussi ... la preuve... Le message est :
      Application .... c:\programs files\ xxxx\yyyy\yyyy.exe n'est pas une application win 32 valide
      pire tous les lecteurs/graveurs ne fonctionnent plus y compris les prises Usb
      J'ai tenté une restauration mais aussi loin que je remonte ...la réponse est : impossible aucune modification n'a été faite
      Je ne dispose que d'une "disquette rouge" qui ne laisse pas l'option reparer... elle formate tout !j'avais tenté l'an dernier et ....
      il me faut absolument trouver une solution de réparation ...sans passer par le formatage car c'est un travail de titan et je ne veux pas perdre sa configuration actuelle programmes installés adresses....
      Donc, j'ai lancé elibaglia ...
      merci de votre aide qui va sans dire et non seulement primordiale, mais Urgente
      Cordialement.
      Christian.
      0
  2. chepa2
     
    ce qui est sûr, c'est que il y a 3 utilisateurs sur ton pc: seb, maman et kiki. si on t'ecartes, il reste 2 suspects: maman et kiki qui peuvent etre coupables. il faudrait les interroger. sauf si tu avoues que tu es le meurtrier.
    en regardant de plus près, je pense que c'est toi le coupable seb, j'ai trouvé la faille dans ton alibi.

    plus serieux, ragardes là. je suis pas allé bien loin pour le trouver, mais au moins c'est en français.
    http://www.microsoft.com/france/securite/alertes/bagle.aspx
    0
  3. sebjseb
     
    Salut et merci pour tes conseils

    Voici ce que j'ai eu dans le fichier infosat apres avoir lancé elibagla:

    Sun Feb 03 14:57:30 2008
    EliBagle v10.96 (c)2008 S.G.H. / Satinfo S.L.
    ----------------------------------------------
    Lista de Acciones (por Acción Directa):
    C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
    C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
    C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
    Por favor, envienos una muestra del fichero
    C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.96
    a "virus@satinfo.es". Gracias.
    C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle Acceso Denegado.
    Restaurada Clave: "SafeBoot\Minimal y Network"

    Sun Feb 03 14:58:43 2008
    EliBagle v10.96 (c)2008 S.G.H. / Satinfo S.L.
    ----------------------------------------------
    Lista de Acciones (por Exploración):
    Explorando Unidad C:\

    Nº Total de Directorios: 4303
    Nº Total de Ficheros: 83429
    Nº de Ficheros Analizados: 10518
    Nº de Ficheros Infectados: 1
    Nº de Ficheros Limpiados: 0

    Sun Feb 10 09:42:03 2008
    EliBagle v10.98 (c)2008 S.G.H. / Satinfo S.L.
    ----------------------------------------------
    Lista de Acciones (por Acción Directa):
    C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
    C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
    C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
    C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado.
    Restaurada Clave: "SafeBoot\Minimal y Network"

    Sun Feb 10 09:42:29 2008
    EliBagle v10.98 (c)2008 S.G.H. / Satinfo S.L.
    ----------------------------------------------
    Lista de Acciones (por Exploración):
    Explorando Unidad C:\
    C:\Muestras\HLDRRR.EXE.MUESTRA ELIBAGLE V10.96 --> Eliminado Bagle.dldr
    C:\Program Files\Google\GoogleToolbarNotifier\GOOGLETOOLBARNOTIFIER.EXE --> Eliminado Bagle.dldr

    Nº Total de Directorios: 4302
    Nº Total de Ficheros: 82177
    Nº de Ficheros Analizados: 10443
    Nº de Ficheros Infectados: 3
    Nº de Ficheros Limpiados: 2

    Ca veut dire quoi?

    Faut il que je fasse ce que tu m'as dis apres (telechargé hijackthis) ou je dois attendre que tu analyse mon fichier infosat?
    0
  4. Utilisateur anonyme
     
    Re ,
    Laisse tomber Hijackthis pour l'instant , on s'en servira plus tard.

    Envoi le fichier "C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.96" a l'adresse mail "virus@satinfo.es" stp ;)

    ************

    Désactive ta restauration système
    Clic sur « Démarrer »
    Clic droit sur « Poste de travail », puis sur « Propriétés »,
    Vas sur l’onglet « Restauration système »
    Tu y coches la case « Désactiver la restauration »
    Termine par [Appliquer] [OK]

    Télécharge ComboFix ici → http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Et enregistre le sur le bureau >>> /!\ IMPORTANT /!\

    Regardes ici, si tu souhaites te familiariser avec son utilisation: https://www.google.fr/?gws_rd=ssl

    AVANT d'utiliser ComboFix :
    → Déconnecte ton PC d'Internet et referme les fenêtres de tous les programmes en cours. /!\
    → Désactive provisoirement (et seulement le temps de l'utilisation de ComboFix), la protection en temps réel de ton Antivirus et de tes Antispywares et de TOUT tes logiciels de protection !!!, (activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil). /!\

    Sur ton bureau double clic sur Combofix.exe.
    Appuies sur la touche 1, pour que le programme commence à s'exécuter et suis les instructions à l'écran.

    /!\ PENDANT TOUTE la durée (ça peut être assez long si le pc est très infecté) du scan de ComboFix, n'ouvres aucun programme, ne touche pas à ta souris et ne surfe pas sur le net /!\

    Soit patient (même si tu penses que le PC est arrêté) ; les temps « d'arrêt apparent » sont parfois de plusieurs minutes (il y a ± 40 étapes d’analyse).

    En cours de nettoyage il est possible, que tu reçoives un avertissement te disant que le pc va redémarrer, laisse le faire.

    Après le redemarrage du pc, un rapport s'ouvrira dans le Bloc notes en fin d'analyse, copie et colle tout son contenu dans ton prochain message.

    (Le fichier rapport Combofix.txt , est ensuite automatiquement sauvegardé dans C:\Combofix.txt)

    Ensuite réactive ta restauration système
    Clic droit sur « Poste de travail », puis sur « Propriétés »,
    Vas sur l’onglet « Restauration système »
    Tu décoches la case « Désactiver la restauration »
    Termine par [Appliquer] [OK]

    A+
    0
    1. sebjseb
       
      Salut j'ai telechargé combo et je l'ai mis sur mon bureau mais quand je double click dessus il me met un message d'erreur comme pour les antivirus:

      C:\Documents and Settings\Seb\Bureau\ComboFix.exe n'est pas une application Win32 valide

      Ca commence a etre compliquer je pense!!
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    Re ,

    Il se fait détecter par bagle :/

    vire ta version actuelle , re-télécharger la -> au moment de l'enregistrer sur ton bureau change le nom du prog' !! fait le avant qu'il soit sur ton pc ! enregistre le sous le nom de ' antibagle '

    a+
    0
    1. sebjseb
       
      J'ai reussi a le telecharger et j'ai changé son nom!

      j'arrive a le lancer mais c'est a quel moment qu'il faut que je tape sur 1?

      en fait j'ai une fenetre "dos" qui s'ouvre et ne fait rien!

      dois je attendre?meme en appuyant sur 1 ca fait rien avec la fenetre "dos"!

      merci
      0
  7. Utilisateur anonyme
     
    Essaye de le lancer en MSE

    A+
    0
    1. sebjseb
       
      j'ai lancé antibagle en mode sans echec l'analyse a commencé et l'ordinateur s'est redemarré a la fin en mode normal et voici l'analyse qui en sort:

      ComboFix 08-02.05.3 - Seb 2008-02-10 18:23:36.1 - NTFSx86 MINIMAL

      Endroit: C:\Documents and Settings\Seb\Bureau\antibagle.exe

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\WINDOWS\pack.epk
      c:\WINDOWS\system32\ajbngkcohz.dat
      c:\WINDOWS\system32\ajbngkcohz_nav.dat
      c:\WINDOWS\system32\ajbngkcohz_navps.dat
      C:\WINDOWS\system32\drivers\down
      C:\WINDOWS\system32\drivers\down\102406.exe
      C:\WINDOWS\system32\drivers\down\102625.exe
      C:\WINDOWS\system32\drivers\down\103203.exe
      C:\WINDOWS\system32\drivers\down\106750.exe
      C:\WINDOWS\system32\drivers\down\108515.exe
      C:\WINDOWS\system32\drivers\down\109781.exe
      C:\WINDOWS\system32\drivers\down\110296.exe
      C:\WINDOWS\system32\drivers\down\110687.exe
      C:\WINDOWS\system32\drivers\down\110765.exe
      C:\WINDOWS\system32\drivers\down\110875.exe
      C:\WINDOWS\system32\drivers\down\111531.exe
      C:\WINDOWS\system32\drivers\down\113468.exe
      C:\WINDOWS\system32\drivers\down\114437.exe
      C:\WINDOWS\system32\drivers\down\115500.exe
      C:\WINDOWS\system32\drivers\down\115687.exe
      C:\WINDOWS\system32\drivers\down\117812.exe
      C:\WINDOWS\system32\drivers\down\117953.exe
      C:\WINDOWS\system32\drivers\down\118578.exe
      C:\WINDOWS\system32\drivers\down\118890.exe
      C:\WINDOWS\system32\drivers\down\120875.exe
      C:\WINDOWS\system32\drivers\down\121250.exe
      C:\WINDOWS\system32\drivers\down\121359.exe
      C:\WINDOWS\system32\drivers\down\122656.exe
      C:\WINDOWS\system32\drivers\down\122703.exe
      C:\WINDOWS\system32\drivers\down\122906.exe
      C:\WINDOWS\system32\drivers\down\124812.exe
      C:\WINDOWS\system32\drivers\down\124953.exe
      C:\WINDOWS\system32\drivers\down\127187.exe
      C:\WINDOWS\system32\drivers\down\129234.exe
      C:\WINDOWS\system32\drivers\down\129562.exe
      C:\WINDOWS\system32\drivers\down\129718.exe
      C:\WINDOWS\system32\drivers\down\130093.exe
      C:\WINDOWS\system32\drivers\down\131031.exe
      C:\WINDOWS\system32\drivers\down\131656.exe
      C:\WINDOWS\system32\drivers\down\131718.exe
      C:\WINDOWS\system32\drivers\down\131906.exe
      C:\WINDOWS\system32\drivers\down\132546.exe
      C:\WINDOWS\system32\drivers\down\132703.exe
      C:\WINDOWS\system32\drivers\down\133265.exe
      C:\WINDOWS\system32\drivers\down\133437.exe
      C:\WINDOWS\system32\drivers\down\134078.exe
      C:\WINDOWS\system32\drivers\down\135765.exe
      C:\WINDOWS\system32\drivers\down\136312.exe
      C:\WINDOWS\system32\drivers\down\136781.exe
      C:\WINDOWS\system32\drivers\down\136890.exe
      C:\WINDOWS\system32\drivers\down\137062.exe
      C:\WINDOWS\system32\drivers\down\137500.exe
      C:\WINDOWS\system32\drivers\down\138328.exe
      C:\WINDOWS\system32\drivers\down\139359.exe
      C:\WINDOWS\system32\drivers\down\139812.exe
      C:\WINDOWS\system32\drivers\down\140000.exe
      C:\WINDOWS\system32\drivers\down\140937.exe
      C:\WINDOWS\system32\drivers\down\140968.exe
      C:\WINDOWS\system32\drivers\down\141546.exe
      C:\WINDOWS\system32\drivers\down\141671.exe
      C:\WINDOWS\system32\drivers\down\142625.exe
      C:\WINDOWS\system32\drivers\down\143078.exe
      C:\WINDOWS\system32\drivers\down\143468.exe
      C:\WINDOWS\system32\drivers\down\143828.exe
      C:\WINDOWS\system32\drivers\down\144703.exe
      C:\WINDOWS\system32\drivers\down\145390.exe
      C:\WINDOWS\system32\drivers\down\145843.exe
      C:\WINDOWS\system32\drivers\down\14610687.exe
      C:\WINDOWS\system32\drivers\down\146187.exe
      C:\WINDOWS\system32\drivers\down\14622984.exe
      C:\WINDOWS\system32\drivers\down\146234.exe
      C:\WINDOWS\system32\drivers\down\14629031.exe
      C:\WINDOWS\system32\drivers\down\14645234.exe
      C:\WINDOWS\system32\drivers\down\14645765.exe
      C:\WINDOWS\system32\drivers\down\14645890.exe
      C:\WINDOWS\system32\drivers\down\14645906.exe
      C:\WINDOWS\system32\drivers\down\14646234.exe
      C:\WINDOWS\system32\drivers\down\14646343.exe
      C:\WINDOWS\system32\drivers\down\14646359.exe
      C:\WINDOWS\system32\drivers\down\14646734.exe
      C:\WINDOWS\system32\drivers\down\14647125.exe
      C:\WINDOWS\system32\drivers\down\14650000.exe
      C:\WINDOWS\system32\drivers\down\14651921.exe
      C:\WINDOWS\system32\drivers\down\14654234.exe
      C:\WINDOWS\system32\drivers\down\14658859.exe
      C:\WINDOWS\system32\drivers\down\14661500.exe
      C:\WINDOWS\system32\drivers\down\146656.exe
      C:\WINDOWS\system32\drivers\down\14667140.exe
      C:\WINDOWS\system32\drivers\down\14670921.exe
      C:\WINDOWS\system32\drivers\down\14671390.exe
      C:\WINDOWS\system32\drivers\down\14674625.exe
      C:\WINDOWS\system32\drivers\down\14675031.exe
      C:\WINDOWS\system32\drivers\down\14678812.exe
      C:\WINDOWS\system32\drivers\down\14678968.exe
      C:\WINDOWS\system32\drivers\down\14679468.exe
      C:\WINDOWS\system32\drivers\down\14680171.exe
      C:\WINDOWS\system32\drivers\down\14683718.exe
      C:\WINDOWS\system32\drivers\down\14700531.exe
      C:\WINDOWS\system32\drivers\down\14700578.exe
      C:\WINDOWS\system32\drivers\down\14707562.exe
      C:\WINDOWS\system32\drivers\down\14709015.exe
      C:\WINDOWS\system32\drivers\down\14709203.exe
      C:\WINDOWS\system32\drivers\down\14712828.exe
      C:\WINDOWS\system32\drivers\down\14714296.exe
      C:\WINDOWS\system32\drivers\down\14715734.exe
      C:\WINDOWS\system32\drivers\down\14718734.exe
      C:\WINDOWS\system32\drivers\down\147203.exe
      C:\WINDOWS\system32\drivers\down\14735562.exe
      C:\WINDOWS\system32\drivers\down\14738109.exe
      C:\WINDOWS\system32\drivers\down\14743953.exe
      C:\WINDOWS\system32\drivers\down\14755593.exe
      C:\WINDOWS\system32\drivers\down\14759015.exe
      C:\WINDOWS\system32\drivers\down\14760546.exe
      C:\WINDOWS\system32\drivers\down\14760781.exe
      C:\WINDOWS\system32\drivers\down\14761125.exe
      C:\WINDOWS\system32\drivers\down\14761328.exe
      C:\WINDOWS\system32\drivers\down\14765640.exe
      C:\WINDOWS\system32\drivers\down\14767296.exe
      C:\WINDOWS\system32\drivers\down\147906.exe
      C:\WINDOWS\system32\drivers\down\147921.exe
      C:\WINDOWS\system32\drivers\down\14801515.exe
      C:\WINDOWS\system32\drivers\down\14805109.exe
      C:\WINDOWS\system32\drivers\down\148531.exe
      C:\WINDOWS\system32\drivers\down\14889796.exe
      C:\WINDOWS\system32\drivers\down\14889812.exe
      C:\WINDOWS\system32\drivers\down\14939703.exe
      C:\WINDOWS\system32\drivers\down\14959437.exe
      C:\WINDOWS\system32\drivers\down\14987312.exe
      C:\WINDOWS\system32\drivers\down\149921.exe
      C:\WINDOWS\system32\drivers\down\149937.exe
      C:\WINDOWS\system32\drivers\down\14998796.exe
      C:\WINDOWS\system32\drivers\down\15044281.exe
      C:\WINDOWS\system32\drivers\down\150546.exe
      C:\WINDOWS\system32\drivers\down\150562.exe
      C:\WINDOWS\system32\drivers\down\15110546.exe
      C:\WINDOWS\system32\drivers\down\15125859.exe
      C:\WINDOWS\system32\drivers\down\15129718.exe
      C:\WINDOWS\system32\drivers\down\15132312.exe
      C:\WINDOWS\system32\drivers\down\15134609.exe
      C:\WINDOWS\system32\drivers\down\15152671.exe
      C:\WINDOWS\system32\drivers\down\15159671.exe
      C:\WINDOWS\system32\drivers\down\151937.exe
      C:\WINDOWS\system32\drivers\down\152140.exe
      C:\WINDOWS\system32\drivers\down\15217906.exe
      C:\WINDOWS\system32\drivers\down\15239578.exe
      C:\WINDOWS\system32\drivers\down\154656.exe
      C:\WINDOWS\system32\drivers\down\154968.exe
      C:\WINDOWS\system32\drivers\down\156593.exe
      C:\WINDOWS\system32\drivers\down\158171.exe
      C:\WINDOWS\system32\drivers\down\158500.exe
      C:\WINDOWS\system32\drivers\down\159250.exe
      C:\WINDOWS\system32\drivers\down\1597484.exe
      C:\WINDOWS\system32\drivers\down\159953.exe
      C:\WINDOWS\system32\drivers\down\160078.exe
      C:\WINDOWS\system32\drivers\down\1616703.exe
      C:\WINDOWS\system32\drivers\down\1621296.exe
      C:\WINDOWS\system32\drivers\down\162968.exe
      C:\WINDOWS\system32\drivers\down\164250.exe
      C:\WINDOWS\system32\drivers\down\165140.exe
      C:\WINDOWS\system32\drivers\down\166203.exe
      C:\WINDOWS\system32\drivers\down\166890.exe
      C:\WINDOWS\system32\drivers\down\168656.exe
      C:\WINDOWS\system32\drivers\down\168875.exe
      C:\WINDOWS\system32\drivers\down\169843.exe
      C:\WINDOWS\system32\drivers\down\170093.exe
      C:\WINDOWS\system32\drivers\down\170625.exe
      C:\WINDOWS\system32\drivers\down\170937.exe
      C:\WINDOWS\system32\drivers\down\171046.exe
      C:\WINDOWS\system32\drivers\down\172296.exe
      C:\WINDOWS\system32\drivers\down\173046.exe
      C:\WINDOWS\system32\drivers\down\173468.exe
      C:\WINDOWS\system32\drivers\down\174234.exe
      C:\WINDOWS\system32\drivers\down\174250.exe
      C:\WINDOWS\system32\drivers\down\175375.exe
      C:\WINDOWS\system32\drivers\down\175593.exe
      C:\WINDOWS\system32\drivers\down\176078.exe
      C:\WINDOWS\system32\drivers\down\176109.exe
      C:\WINDOWS\system32\drivers\down\176125.exe
      C:\WINDOWS\system32\drivers\down\176234.exe
      C:\WINDOWS\system32\drivers\down\178531.exe
      C:\WINDOWS\system32\drivers\down\180093.exe
      C:\WINDOWS\system32\drivers\down\180937.exe
      C:\WINDOWS\system32\drivers\down\182437.exe
      C:\WINDOWS\system32\drivers\down\182625.exe
      C:\WINDOWS\system32\drivers\down\183015.exe
      C:\WINDOWS\system32\drivers\down\183078.exe
      C:\WINDOWS\system32\drivers\down\183390.exe
      C:\WINDOWS\system32\drivers\down\185296.exe
      C:\WINDOWS\system32\drivers\down\186109.exe
      C:\WINDOWS\system32\drivers\down\186343.exe
      C:\WINDOWS\system32\drivers\down\186953.exe
      C:\WINDOWS\system32\drivers\down\187828.exe
      C:\WINDOWS\system32\drivers\down\188015.exe
      C:\WINDOWS\system32\drivers\down\188375.exe
      C:\WINDOWS\system32\drivers\down\188515.exe
      C:\WINDOWS\system32\drivers\down\188703.exe
      C:\WINDOWS\system32\drivers\down\188843.exe
      C:\WINDOWS\system32\drivers\down\190671.exe
      C:\WINDOWS\system32\drivers\down\191078.exe
      C:\WINDOWS\system32\drivers\down\191562.exe
      C:\WINDOWS\system32\drivers\down\192921.exe
      C:\WINDOWS\system32\drivers\down\193203.exe
      C:\WINDOWS\system32\drivers\down\193484.exe
      C:\WINDOWS\system32\drivers\down\193953.exe
      C:\WINDOWS\system32\drivers\down\195375.exe
      C:\WINDOWS\system32\drivers\down\196031.exe
      C:\WINDOWS\system32\drivers\down\196421.exe
      C:\WINDOWS\system32\drivers\down\196453.exe
      C:\WINDOWS\system32\drivers\down\196828.exe
      C:\WINDOWS\system32\drivers\down\197015.exe
      C:\WINDOWS\system32\drivers\down\197656.exe
      C:\WINDOWS\system32\drivers\down\198437.exe
      C:\WINDOWS\system32\drivers\down\198640.exe
      C:\WINDOWS\system32\drivers\down\198984.exe
      C:\WINDOWS\system32\drivers\down\199593.exe
      C:\WINDOWS\system32\drivers\down\200265.exe
      C:\WINDOWS\system32\drivers\down\200968.exe
      C:\WINDOWS\system32\drivers\down\201171.exe
      C:\WINDOWS\system32\drivers\down\201265.exe
      C:\WINDOWS\system32\drivers\down\201687.exe
      C:\WINDOWS\system32\drivers\down\203328.exe
      C:\WINDOWS\system32\drivers\down\203843.exe
      C:\WINDOWS\system32\drivers\down\204109.exe
      C:\WINDOWS\system32\drivers\down\204515.exe
      C:\WINDOWS\system32\drivers\down\204734.exe
      C:\WINDOWS\system32\drivers\down\205796.exe
      C:\WINDOWS\system32\drivers\down\206296.exe
      C:\WINDOWS\system32\drivers\down\207578.exe
      C:\WINDOWS\system32\drivers\down\207703.exe
      C:\WINDOWS\system32\drivers\down\208453.exe
      C:\WINDOWS\system32\drivers\down\208500.exe
      C:\WINDOWS\system32\drivers\down\211375.exe
      C:\WINDOWS\system32\drivers\down\213750.exe
      C:\WINDOWS\system32\drivers\down\214843.exe
      C:\WINDOWS\system32\drivers\down\217421.exe
      C:\WINDOWS\system32\drivers\down\219265.exe
      C:\WINDOWS\system32\drivers\down\219859.exe
      C:\WINDOWS\system32\drivers\down\220468.exe
      C:\WINDOWS\system32\drivers\down\220718.exe
      C:\WINDOWS\system32\drivers\down\220765.exe
      C:\WINDOWS\system32\drivers\down\220890.exe
      C:\WINDOWS\system32\drivers\down\221000.exe
      C:\WINDOWS\system32\drivers\down\224312.exe
      C:\WINDOWS\system32\drivers\down\225031.exe
      C:\WINDOWS\system32\drivers\down\225343.exe
      C:\WINDOWS\system32\drivers\down\225437.exe
      C:\WINDOWS\system32\drivers\down\226281.exe
      C:\WINDOWS\system32\drivers\down\227406.exe
      C:\WINDOWS\system32\drivers\down\228812.exe
      C:\WINDOWS\system32\drivers\down\229937.exe
      C:\WINDOWS\system32\drivers\down\230093.exe
      C:\WINDOWS\system32\drivers\down\230453.exe
      C:\WINDOWS\system32\drivers\down\231125.exe
      C:\WINDOWS\system32\drivers\down\231437.exe
      C:\WINDOWS\system32\drivers\down\234890.exe
      C:\WINDOWS\system32\drivers\down\236515.exe
      C:\WINDOWS\system32\drivers\down\237015.exe
      C:\WINDOWS\system32\drivers\down\238265.exe
      C:\WINDOWS\system32\drivers\down\239156.exe
      C:\WINDOWS\system32\drivers\down\241046.exe
      C:\WINDOWS\system32\drivers\down\244203.exe
      C:\WINDOWS\system32\drivers\down\244218.exe
      C:\WINDOWS\system32\drivers\down\244515.exe
      C:\WINDOWS\system32\drivers\down\244640.exe
      C:\WINDOWS\system32\drivers\down\247609.exe
      C:\WINDOWS\system32\drivers\down\254656.exe
      C:\WINDOWS\system32\drivers\down\256171.exe
      C:\WINDOWS\system32\drivers\down\258765.exe
      C:\WINDOWS\system32\drivers\down\259125.exe
      C:\WINDOWS\system32\drivers\down\264968.exe
      C:\WINDOWS\system32\drivers\down\268906.exe
      C:\WINDOWS\system32\drivers\down\273234.exe
      C:\WINDOWS\system32\drivers\down\275515.exe
      C:\WINDOWS\system32\drivers\down\276109.exe
      C:\WINDOWS\system32\drivers\down\276703.exe
      C:\WINDOWS\system32\drivers\down\277437.exe
      C:\WINDOWS\system32\drivers\down\277625.exe
      C:\WINDOWS\system32\drivers\down\283796.exe
      C:\WINDOWS\system32\drivers\down\286484.exe
      C:\WINDOWS\system32\drivers\down\288968.exe
      C:\WINDOWS\system32\drivers\down\290343.exe
      C:\WINDOWS\system32\drivers\down\29127203.exe
      C:\WINDOWS\system32\drivers\down\29130500.exe
      C:\WINDOWS\system32\drivers\down\291687.exe
      C:\WINDOWS\system32\drivers\down\29240281.exe
      C:\WINDOWS\system32\drivers\down\29245437.exe
      C:\WINDOWS\system32\drivers\down\29250312.exe
      C:\WINDOWS\system32\drivers\down\29260265.exe
      C:\WINDOWS\system32\drivers\down\29260281.exe
      C:\WINDOWS\system32\drivers\down\29264187.exe
      C:\WINDOWS\system32\drivers\down\29265515.exe
      C:\WINDOWS\system32\drivers\down\29267015.exe
      C:\WINDOWS\system32\drivers\down\29268234.exe
      C:\WINDOWS\system32\drivers\down\29269984.exe
      C:\WINDOWS\system32\drivers\down\29275906.exe
      C:\WINDOWS\system32\drivers\down\29278640.exe
      C:\WINDOWS\system32\drivers\down\29279328.exe
      C:\WINDOWS\system32\drivers\down\29279953.exe
      C:\WINDOWS\system32\drivers\down\29280390.exe
      C:\WINDOWS\system32\drivers\down\29281921.exe
      C:\WINDOWS\system32\drivers\down\29283843.exe
      C:\WINDOWS\system32\drivers\down\29310328.exe
      C:\WINDOWS\system32\drivers\down\29312203.exe
      C:\WINDOWS\system32\drivers\down\293390.exe
      C:\WINDOWS\system32\drivers\down\29711656.exe
      C:\WINDOWS\system32\drivers\down\29897625.exe
      C:\WINDOWS\system32\drivers\down\29920687.exe
      C:\WINDOWS\system32\drivers\down\29950015.exe
      C:\WINDOWS\system32\drivers\down\30043750.exe
      C:\WINDOWS\system32\drivers\down\30043843.exe
      C:\WINDOWS\system32\drivers\down\30101640.exe
      C:\WINDOWS\system32\drivers\down\30121500.exe
      C:\WINDOWS\system32\drivers\down\30143515.exe
      C:\WINDOWS\system32\drivers\down\30172984.exe
      C:\WINDOWS\system32\drivers\down\30208968.exe
      C:\WINDOWS\system32\drivers\down\30260390.exe
      C:\WINDOWS\system32\drivers\down\30277437.exe
      C:\WINDOWS\system32\drivers\down\30281875.exe
      C:\WINDOWS\system32\drivers\down\30286828.exe
      C:\WINDOWS\system32\drivers\down\30294281.exe
      C:\WINDOWS\system32\drivers\down\30318453.exe
      C:\WINDOWS\system32\drivers\down\30327234.exe
      C:\WINDOWS\system32\drivers\down\30390890.exe
      C:\WINDOWS\system32\drivers\down\30422734.exe
      C:\WINDOWS\system32\drivers\down\311218.exe
      C:\WINDOWS\system32\drivers\down\322890.exe
      C:\WINDOWS\system32\drivers\down\325015.exe
      C:\WINDOWS\system32\drivers\down\327703.exe
      C:\WINDOWS\system32\drivers\down\32850906.exe
      C:\WINDOWS\system32\drivers\down\32855828.exe
      C:\WINDOWS\system32\drivers\down\32861609.exe
      C:\WINDOWS\system32\drivers\down\32876484.exe
      C:\WINDOWS\system32\drivers\down\32876515.exe
      C:\WINDOWS\system32\drivers\down\32882875.exe
      C:\WINDOWS\system32\drivers\down\32884234.exe
      C:\WINDOWS\system32\drivers\down\32885921.exe
      C:\WINDOWS\system32\drivers\down\32887250.exe
      C:\WINDOWS\system32\drivers\down\32889015.exe
      C:\WINDOWS\system32\drivers\down\32893687.exe
      C:\WINDOWS\system32\drivers\down\32899375.exe
      C:\WINDOWS\system32\drivers\down\32899578.exe
      C:\WINDOWS\system32\drivers\down\32899781.exe
      C:\WINDOWS\system32\drivers\down\32908812.exe
      C:\WINDOWS\system32\drivers\down\32910984.exe
      C:\WINDOWS\system32\drivers\down\32911781.exe
      C:\WINDOWS\system32\drivers\down\32941796.exe
      C:\WINDOWS\system32\drivers\down\32943468.exe
      C:\WINDOWS\system32\drivers\down\32946984.exe
      C:\WINDOWS\system32\drivers\down\339312.exe
      C:\WINDOWS\system32\drivers\down\349218.exe
      C:\WINDOWS\system32\drivers\down\350765.exe
      C:\WINDOWS\system32\drivers\down\3539812.exe
      C:\WINDOWS\system32\drivers\down\3555515.exe
      C:\WINDOWS\system32\drivers\down\3561265.exe
      C:\WINDOWS\system32\drivers\down\356703.exe
      C:\WINDOWS\system32\drivers\down\3580703.exe
      C:\WINDOWS\system32\drivers\down\3581390.exe
      C:\WINDOWS\system32\drivers\down\361671.exe
      C:\WINDOWS\system32\drivers\down\364578.exe
      C:\WINDOWS\system32\drivers\down\368984.exe
      C:\WINDOWS\system32\drivers\down\388203.exe
      C:\WINDOWS\system32\drivers\down\388328.exe
      C:\WINDOWS\system32\drivers\down\396218.exe
      C:\WINDOWS\system32\drivers\down\399781.exe
      C:\WINDOWS\system32\drivers\down\406343.exe
      C:\WINDOWS\system32\drivers\down\409968.exe
      C:\WINDOWS\system32\drivers\down\412250.exe
      C:\WINDOWS\system32\drivers\down\413203.exe
      C:\WINDOWS\system32\drivers\down\420796.exe
      C:\WINDOWS\system32\drivers\down\425781.exe
      C:\WINDOWS\system32\drivers\down\432453.exe
      C:\WINDOWS\system32\drivers\down\433421.exe
      C:\WINDOWS\system32\drivers\down\43724500.exe
      C:\WINDOWS\system32\drivers\down\43725156.exe
      C:\WINDOWS\system32\drivers\down\43732187.exe
      C:\WINDOWS\system32\drivers\down\43736312.exe
      C:\WINDOWS\system32\drivers\down\43748953.exe
      C:\WINDOWS\system32\drivers\down\43749500.exe
      C:\WINDOWS\system32\drivers\down\43753125.exe
      C:\WINDOWS\system32\drivers\down\43754718.exe
      C:\WINDOWS\system32\drivers\down\43756312.exe
      C:\WINDOWS\system32\drivers\down\43757656.exe
      C:\WINDOWS\system32\drivers\down\43759656.exe
      C:\WINDOWS\system32\drivers\down\43765109.exe
      C:\WINDOWS\system32\drivers\down\43767968.exe
      C:\WINDOWS\system32\drivers\down\43768328.exe
      C:\WINDOWS\system32\drivers\down\43769531.exe
      C:\WINDOWS\system32\drivers\down\43769984.exe
      C:\WINDOWS\system32\drivers\down\43771640.exe
      C:\WINDOWS\system32\drivers\down\43774640.exe
      C:\WINDOWS\system32\drivers\down\43800546.exe
      C:\WINDOWS\system32\drivers\down\43802718.exe
      C:\WINDOWS\system32\drivers\down\440421.exe
      C:\WINDOWS\system32\drivers\down\443718.exe
      C:\WINDOWS\system32\drivers\down\446046.exe
      C:\WINDOWS\system32\drivers\down\448328.exe
      C:\WINDOWS\system32\drivers\down\450421.exe
      C:\WINDOWS\system32\drivers\down\461781.exe
      C:\WINDOWS\system32\drivers\down\467187.exe
      C:\WINDOWS\system32\drivers\down\471578.exe
      C:\WINDOWS\system32\drivers\down\472125.exe
      C:\WINDOWS\system32\drivers\down\47359500.exe
      C:\WINDOWS\system32\drivers\down\47360437.exe
      C:\WINDOWS\system32\drivers\down\47366984.exe
      C:\WINDOWS\system32\drivers\down\47371203.exe
      C:\WINDOWS\system32\drivers\down\473765.exe
      C:\WINDOWS\system32\drivers\down\47378218.exe
      C:\WINDOWS\system32\drivers\down\47396843.exe
      C:\WINDOWS\system32\drivers\down\47397562.exe
      C:\WINDOWS\system32\drivers\down\47403406.exe
      C:\WINDOWS\system32\drivers\down\47405421.exe
      C:\WINDOWS\system32\drivers\down\47407328.exe
      C:\WINDOWS\system32\drivers\down\47409031.exe
      C:\WINDOWS\system32\drivers\down\47410921.exe
      C:\WINDOWS\system32\drivers\down\47416343.exe
      C:\WINDOWS\system32\drivers\down\47419203.exe
      C:\WINDOWS\system32\drivers\down\47419609.exe
      C:\WINDOWS\system32\drivers\down\47427000.exe
      C:\WINDOWS\system32\drivers\down\47429218.exe
      C:\WINDOWS\system32\drivers\down\47431578.exe
      C:\WINDOWS\system32\drivers\down\47458156.exe
      C:\WINDOWS\system32\drivers\down\47460812.exe
      C:\WINDOWS\system32\drivers\down\47465562.exe
      C:\WINDOWS\system32\drivers\down\477656.exe
      C:\WINDOWS\system32\drivers\down\480187.exe
      C:\WINDOWS\system32\drivers\down\481359.exe
      C:\WINDOWS\system32\drivers\down\484390.exe
      C:\WINDOWS\system32\drivers\down\489250.exe
      C:\WINDOWS\system32\drivers\down\512390.exe
      C:\WINDOWS\system32\drivers\down\519921.exe
      C:\WINDOWS\system32\drivers\down\58244234.exe
      C:\WINDOWS\system32\drivers\down\58258359.exe
      C:\WINDOWS\system32\drivers\down\58265281.exe
      C:\WINDOWS\system32\drivers\down\58295984.exe
      C:\WINDOWS\system32\drivers\down\58296031.exe
      C:\WINDOWS\system32\drivers\down\58305171.exe
      C:\WINDOWS\system32\drivers\down\58310140.exe
      C:\WINDOWS\system32\drivers\down\58312500.exe
      C:\WINDOWS\system32\drivers\down\58314000.exe
      C:\WINDOWS\system32\drivers\down\58320906.exe
      C:\WINDOWS\system32\drivers\down\58355171.exe
      C:\WINDOWS\system32\drivers\down\58366906.exe
      C:\WINDOWS\system32\drivers\down\58369437.exe
      C:\WINDOWS\system32\drivers\down\58371578.exe
      C:\WINDOWS\system32\drivers\down\58372859.exe
      C:\WINDOWS\system32\drivers\down\58379296.exe
      C:\WINDOWS\system32\drivers\down\58384375.exe
      C:\WINDOWS\system32\drivers\down\58415125.exe
      C:\WINDOWS\system32\drivers\down\58418906.exe
      C:\WINDOWS\system32\drivers\down\61885421.exe
      C:\WINDOWS\system32\drivers\down\61892234.exe
      C:\WINDOWS\system32\drivers\down\61914031.exe
      C:\WINDOWS\system32\drivers\down\61918687.exe
      C:\WINDOWS\system32\drivers\down\61922750.exe
      C:\WINDOWS\system32\drivers\down\61941062.exe
      C:\WINDOWS\system32\drivers\down\61943984.exe
      C:\WINDOWS\system32\drivers\down\61945406.exe
      C:\WINDOWS\system32\drivers\down\61947218.exe
      C:\WINDOWS\system32\drivers\down\61948343.exe
      C:\WINDOWS\system32\drivers\down\61951031.exe
      C:\WINDOWS\system32\drivers\down\61955859.exe
      C:\WINDOWS\system32\drivers\down\61959296.exe
      C:\WINDOWS\system32\drivers\down\61959531.exe
      C:\WINDOWS\system32\drivers\down\61959718.exe
      C:\WINDOWS\system32\drivers\down\61960296.exe
      C:\WINDOWS\system32\drivers\down\61961765.exe
      C:\WINDOWS\system32\drivers\down\61962281.exe
      C:\WINDOWS\system32\drivers\down\61988734.exe
      C:\WINDOWS\system32\drivers\down\61990546.exe
      C:\WINDOWS\system32\drivers\down\61993875.exe
      C:\WINDOWS\system32\drivers\down\63609.exe
      C:\WINDOWS\system32\drivers\down\64953.exe
      C:\WINDOWS\system32\drivers\down\65906.exe
      C:\WINDOWS\system32\drivers\down\66812.exe
      C:\WINDOWS\system32\drivers\down\68625.exe
      C:\WINDOWS\system32\drivers\down\70000.exe
      C:\WINDOWS\system32\drivers\down\71828.exe
      C:\WINDOWS\system32\drivers\down\72203.exe
      C:\WINDOWS\system32\drivers\down\72879140.exe
      C:\WINDOWS\system32\drivers\down\72894187.exe
      C:\WINDOWS\system32\drivers\down\72938765.exe
      C:\WINDOWS\system32\drivers\down\72938781.exe
      C:\WINDOWS\system32\drivers\down\72952296.exe
      C:\WINDOWS\system32\drivers\down\72957937.exe
      C:\WINDOWS\system32\drivers\down\72962062.exe
      C:\WINDOWS\system32\drivers\down\72963140.exe
      C:\WINDOWS\system32\drivers\down\72979437.exe
      C:\WINDOWS\system32\drivers\down\73009609.exe
      C:\WINDOWS\system32\drivers\down\73019515.exe
      C:\WINDOWS\system32\drivers\down\73022109.exe
      C:\WINDOWS\system32\drivers\down\73023312.exe
      C:\WINDOWS\system32\drivers\down\73060312.exe
      C:\WINDOWS\system32\drivers\down\73066468.exe
      C:\WINDOWS\system32\drivers\down\73116437.exe
      C:\WINDOWS\system32\drivers\down\73136703.exe
      C:\WINDOWS\system32\drivers\down\73703.exe
      C:\WINDOWS\system32\drivers\down\74953.exe
      C:\WINDOWS\system32\drivers\down\75031.exe
      C:\WINDOWS\system32\drivers\down\76671.exe
      C:\WINDOWS\system32\drivers\down\77328.exe
      C:\WINDOWS\system32\drivers\down\78156.exe
      C:\WINDOWS\system32\drivers\down\78406.exe
      C:\WINDOWS\system32\drivers\down\78593.exe
      C:\WINDOWS\system32\drivers\down\78890.exe
      C:\WINDOWS\system32\drivers\down\79765.exe
      C:\WINDOWS\system32\drivers\down\80515.exe
      C:\WINDOWS\system32\drivers\down\81265.exe
      C:\WINDOWS\system32\drivers\down\82328.exe
      C:\WINDOWS\system32\drivers\down\82984.exe
      C:\WINDOWS\system32\drivers\down\84062.exe
      C:\WINDOWS\system32\drivers\down\84250.exe
      C:\WINDOWS\system32\drivers\down\84828.exe
      C:\WINDOWS\system32\drivers\down\85218.exe
      C:\WINDOWS\system32\drivers\down\86593.exe
      C:\WINDOWS\system32\drivers\down\86656.exe
      C:\WINDOWS\system32\drivers\down\87571984.exe
      C:\WINDOWS\system32\drivers\down\87589984.exe
      C:\WINDOWS\system32\drivers\down\87597281.exe
      C:\WINDOWS\system32\drivers\down\87607531.exe
      C:\WINDOWS\system32\drivers\down\87663984.exe
      C:\WINDOWS\system32\drivers\down\87666109.exe
      C:\WINDOWS\system32\drivers\down\87686375.exe
      C:\WINDOWS\system32\drivers\down\87694906.exe
      C:\WINDOWS\system32\drivers\down\87706390.exe
      C:\WINDOWS\system32\drivers\down\87711500.exe
      C:\WINDOWS\system32\drivers\down\87715000.exe
      C:\WINDOWS\system32\drivers\down\87728593.exe
      C:\WINDOWS\system32\drivers\down\87739187.exe
      C:\WINDOWS\system32\drivers\down\87741765.exe
      C:\WINDOWS\system32\drivers\down\87742671.exe
      C:\WINDOWS\system32\drivers\down\87766578.exe
      C:\WINDOWS\system32\drivers\down\87774031.exe
      C:\WINDOWS\system32\drivers\down\87782765.exe
      C:\WINDOWS\system32\drivers\down\87813484.exe
      C:\WINDOWS\system32\drivers\down\87822906.exe
      C:\WINDOWS\system32\drivers\down\88078.exe
      C:\WINDOWS\system32\drivers\down\88812.exe
      C:\WINDOWS\system32\drivers\down\89734.exe
      C:\WINDOWS\system32\drivers\down\89843.exe
      C:\WINDOWS\system32\drivers\down\89859.exe
      C:\WINDOWS\system32\drivers\down\92421.exe
      C:\WINDOWS\system32\drivers\down\93500.exe
      C:\WINDOWS\system32\drivers\down\93921.exe
      C:\WINDOWS\system32\drivers\down\94921.exe
      C:\WINDOWS\system32\drivers\down\95375.exe
      C:\WINDOWS\system32\drivers\down\96343.exe
      C:\WINDOWS\system32\drivers\down\98640.exe
      C:\WINDOWS\system32\drivers\down\99875.exe
      C:\WINDOWS\system32\drivers\hldrrr.exe
      C:\WINDOWS\system32\drivers\srosa.sys
      C:\WINDOWS\system32\mdelk.exe
      C:\WINDOWS\system32\wintems.exe

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

      .
      -------\LEGACY_SROSA
      -------\srosa


      ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-10 to 2008-02-10 ))))))))))))))))))))))))))))))))))))
      .

      2008-02-08 19:15 . 2008-02-08 19:15 <REP> d-------- C:\Program Files\Trend Micro
      2008-02-03 15:29 . 2008-02-03 15:29 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
      2008-02-03 15:29 . 2008-02-03 15:29 1,406 --a------ C:\WINDOWS\system32\Help.ico
      2008-02-03 14:57 . 2008-02-10 09:44 <REP> d-------- C:\Muestras
      2008-02-02 17:35 . 2008-02-02 18:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-02-10 17:22 --------- d-----w C:\Program Files\Wanadoo
      2008-02-09 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-02-03 15:49 --------- d-----w C:\Program Files\MSN Messenger
      2008-02-03 15:31 --------- d-----w C:\Program Files\Google
      2008-02-02 16:32 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
      2008-02-02 12:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
      2007-12-29 21:27 --------- d-----w C:\Documents and Settings\Maman\Application Data\Sports Interactive
      2007-12-16 17:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2007-11-17 11:43 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
      .

      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09 15360]
      "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [ ]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
      "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 09:59 204288]
      "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
      "BitTorrent"="D:\Programmes\Bit Torrent\bittorrent.exe" [ ]
      "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 16:22 7618560]
      "nwiz"="nwiz.exe" [2006-06-01 16:22 1519616 C:\WINDOWS\system32\nwiz.exe]
      "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-06-01 16:22 86016]
      "SoundMan"="SOUNDMAN.EXE" [2006-06-21 04:42 577536 C:\WINDOWS\soundman.exe]
      "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
      "DAEMON Tools"="D:\Programmes\Daemon\DAEMON Tools\daemon.exe" [2006-09-14 21:09 157592]
      "MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-05-20 19:51 90112]
      "Agent"="C:\Program Files\Power Cinema\PowerVCR II\Agent.exe" [2002-05-21 04:52 94208]
      "Remote_Agent"="C:\Program Files\Power Cinema\PowerVCR II\RemoteAgent.exe" [2002-05-21 04:52 32768]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
      "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49 20480]
      "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55 32768]
      "ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-08-19 10:37 49152]
      "Domino"="C:\WINDOWS\Domino.exe" [2006-08-18 15:58 49152]
      "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-23 23:08 49152]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15:09 15360]

      R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys [2003-05-22 16:44]
      R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 15:43]
      S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
      S3 ZSMC211;Webcam (ZS0211);C:\WINDOWS\system32\Drivers\ZS211.sys [2006-10-18 08:23]

      .
      **************************************************************************

      catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-02-10 18:30:21
      Windows 5.1.2600 Service Pack 2 NTFS

      Balayage processus cach‚s ...

      Balayage cach‚ autostart entries ...

      Balayage des fichiers cach‚s ...

      C:\WINDOWS\system32\ban_list.txt 5679 bytes

      Scan termin‚ avec succŠs
      Les fichiers cach‚s: 1

      **************************************************************************
      .
      ------------------------ Other Running Processes ------------------------
      .
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\Windows Media Player\WMPNetwk.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      .
      **************************************************************************
      .
      Temps d'accomplissement: 2008-02-10 18:34:13 - machine was rebooted
      ComboFix-quarantined-files.txt 2008-02-10 17:34:10
      .
      2008-01-09 18:02:02 --- E O F ---



      Que dois je faire maintenant?
      0
  8. sebjseb
     
    j'ai lancé antibagle en mode sans echec l'analyse a commencé et l'ordinateur s'est redemarré a la fin en mode normal et voici l'analyse qui en sort:

    ComboFix 08-02.05.3 - Seb 2008-02-10 18:23:36.1 - NTFSx86 MINIMAL

    Endroit: C:\Documents and Settings\Seb\Bureau\antibagle.exe

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\pack.epk
    c:\WINDOWS\system32\ajbngkcohz.dat
    c:\WINDOWS\system32\ajbngkcohz_nav.dat
    c:\WINDOWS\system32\ajbngkcohz_navps.dat
    C:\WINDOWS\system32\drivers\down
    C:\WINDOWS\system32\drivers\down\102406.exe
    C:\WINDOWS\system32\drivers\down\102625.exe
    C:\WINDOWS\system32\drivers\down\103203.exe
    C:\WINDOWS\system32\drivers\down\106750.exe
    C:\WINDOWS\system32\drivers\down\108515.exe
    C:\WINDOWS\system32\drivers\down\109781.exe
    C:\WINDOWS\system32\drivers\down\110296.exe
    C:\WINDOWS\system32\drivers\down\110687.exe
    C:\WINDOWS\system32\drivers\down\110765.exe
    C:\WINDOWS\system32\drivers\down\110875.exe
    C:\WINDOWS\system32\drivers\down\111531.exe
    C:\WINDOWS\system32\drivers\down\113468.exe
    C:\WINDOWS\system32\drivers\down\114437.exe
    C:\WINDOWS\system32\drivers\down\115500.exe
    C:\WINDOWS\system32\drivers\down\115687.exe
    C:\WINDOWS\system32\drivers\down\117812.exe
    C:\WINDOWS\system32\drivers\down\117953.exe
    C:\WINDOWS\system32\drivers\down\118578.exe
    C:\WINDOWS\system32\drivers\down\118890.exe
    C:\WINDOWS\system32\drivers\down\120875.exe
    C:\WINDOWS\system32\drivers\down\121250.exe
    C:\WINDOWS\system32\drivers\down\121359.exe
    C:\WINDOWS\system32\drivers\down\122656.exe
    C:\WINDOWS\system32\drivers\down\122703.exe
    C:\WINDOWS\system32\drivers\down\122906.exe
    C:\WINDOWS\system32\drivers\down\124812.exe
    C:\WINDOWS\system32\drivers\down\124953.exe
    C:\WINDOWS\system32\drivers\down\127187.exe
    C:\WINDOWS\system32\drivers\down\129234.exe
    C:\WINDOWS\system32\drivers\down\129562.exe
    C:\WINDOWS\system32\drivers\down\129718.exe
    C:\WINDOWS\system32\drivers\down\130093.exe
    C:\WINDOWS\system32\drivers\down\131031.exe
    C:\WINDOWS\system32\drivers\down\131656.exe
    C:\WINDOWS\system32\drivers\down\131718.exe
    C:\WINDOWS\system32\drivers\down\131906.exe
    C:\WINDOWS\system32\drivers\down\132546.exe
    C:\WINDOWS\system32\drivers\down\132703.exe
    C:\WINDOWS\system32\drivers\down\133265.exe
    C:\WINDOWS\system32\drivers\down\133437.exe
    C:\WINDOWS\system32\drivers\down\134078.exe
    C:\WINDOWS\system32\drivers\down\135765.exe
    C:\WINDOWS\system32\drivers\down\136312.exe
    C:\WINDOWS\system32\drivers\down\136781.exe
    C:\WINDOWS\system32\drivers\down\136890.exe
    C:\WINDOWS\system32\drivers\down\137062.exe
    C:\WINDOWS\system32\drivers\down\137500.exe
    C:\WINDOWS\system32\drivers\down\138328.exe
    C:\WINDOWS\system32\drivers\down\139359.exe
    C:\WINDOWS\system32\drivers\down\139812.exe
    C:\WINDOWS\system32\drivers\down\140000.exe
    C:\WINDOWS\system32\drivers\down\140937.exe
    C:\WINDOWS\system32\drivers\down\140968.exe
    C:\WINDOWS\system32\drivers\down\141546.exe
    C:\WINDOWS\system32\drivers\down\141671.exe
    C:\WINDOWS\system32\drivers\down\142625.exe
    C:\WINDOWS\system32\drivers\down\143078.exe
    C:\WINDOWS\system32\drivers\down\143468.exe
    C:\WINDOWS\system32\drivers\down\143828.exe
    C:\WINDOWS\system32\drivers\down\144703.exe
    C:\WINDOWS\system32\drivers\down\145390.exe
    C:\WINDOWS\system32\drivers\down\145843.exe
    C:\WINDOWS\system32\drivers\down\14610687.exe
    C:\WINDOWS\system32\drivers\down\146187.exe
    C:\WINDOWS\system32\drivers\down\14622984.exe
    C:\WINDOWS\system32\drivers\down\146234.exe
    C:\WINDOWS\system32\drivers\down\14629031.exe
    C:\WINDOWS\system32\drivers\down\14645234.exe
    C:\WINDOWS\system32\drivers\down\14645765.exe
    C:\WINDOWS\system32\drivers\down\14645890.exe
    C:\WINDOWS\system32\drivers\down\14645906.exe
    C:\WINDOWS\system32\drivers\down\14646234.exe
    C:\WINDOWS\system32\drivers\down\14646343.exe
    C:\WINDOWS\system32\drivers\down\14646359.exe
    C:\WINDOWS\system32\drivers\down\14646734.exe
    C:\WINDOWS\system32\drivers\down\14647125.exe
    C:\WINDOWS\system32\drivers\down\14650000.exe
    C:\WINDOWS\system32\drivers\down\14651921.exe
    C:\WINDOWS\system32\drivers\down\14654234.exe
    C:\WINDOWS\system32\drivers\down\14658859.exe
    C:\WINDOWS\system32\drivers\down\14661500.exe
    C:\WINDOWS\system32\drivers\down\146656.exe
    C:\WINDOWS\system32\drivers\down\14667140.exe
    C:\WINDOWS\system32\drivers\down\14670921.exe
    C:\WINDOWS\system32\drivers\down\14671390.exe
    C:\WINDOWS\system32\drivers\down\14674625.exe
    C:\WINDOWS\system32\drivers\down\14675031.exe
    C:\WINDOWS\system32\drivers\down\14678812.exe
    C:\WINDOWS\system32\drivers\down\14678968.exe
    C:\WINDOWS\system32\drivers\down\14679468.exe
    C:\WINDOWS\system32\drivers\down\14680171.exe
    C:\WINDOWS\system32\drivers\down\14683718.exe
    C:\WINDOWS\system32\drivers\down\14700531.exe
    C:\WINDOWS\system32\drivers\down\14700578.exe
    C:\WINDOWS\system32\drivers\down\14707562.exe
    C:\WINDOWS\system32\drivers\down\14709015.exe
    C:\WINDOWS\system32\drivers\down\14709203.exe
    C:\WINDOWS\system32\drivers\down\14712828.exe
    C:\WINDOWS\system32\drivers\down\14714296.exe
    C:\WINDOWS\system32\drivers\down\14715734.exe
    C:\WINDOWS\system32\drivers\down\14718734.exe
    C:\WINDOWS\system32\drivers\down\147203.exe
    C:\WINDOWS\system32\drivers\down\14735562.exe
    C:\WINDOWS\system32\drivers\down\14738109.exe
    C:\WINDOWS\system32\drivers\down\14743953.exe
    C:\WINDOWS\system32\drivers\down\14755593.exe
    C:\WINDOWS\system32\drivers\down\14759015.exe
    C:\WINDOWS\system32\drivers\down\14760546.exe
    C:\WINDOWS\system32\drivers\down\14760781.exe
    C:\WINDOWS\system32\drivers\down\14761125.exe
    C:\WINDOWS\system32\drivers\down\14761328.exe
    C:\WINDOWS\system32\drivers\down\14765640.exe
    C:\WINDOWS\system32\drivers\down\14767296.exe
    C:\WINDOWS\system32\drivers\down\147906.exe
    C:\WINDOWS\system32\drivers\down\147921.exe
    C:\WINDOWS\system32\drivers\down\14801515.exe
    C:\WINDOWS\system32\drivers\down\14805109.exe
    C:\WINDOWS\system32\drivers\down\148531.exe
    C:\WINDOWS\system32\drivers\down\14889796.exe
    C:\WINDOWS\system32\drivers\down\14889812.exe
    C:\WINDOWS\system32\drivers\down\14939703.exe
    C:\WINDOWS\system32\drivers\down\14959437.exe
    C:\WINDOWS\system32\drivers\down\14987312.exe
    C:\WINDOWS\system32\drivers\down\149921.exe
    C:\WINDOWS\system32\drivers\down\149937.exe
    C:\WINDOWS\system32\drivers\down\14998796.exe
    C:\WINDOWS\system32\drivers\down\15044281.exe
    C:\WINDOWS\system32\drivers\down\150546.exe
    C:\WINDOWS\system32\drivers\down\150562.exe
    C:\WINDOWS\system32\drivers\down\15110546.exe
    C:\WINDOWS\system32\drivers\down\15125859.exe
    C:\WINDOWS\system32\drivers\down\15129718.exe
    C:\WINDOWS\system32\drivers\down\15132312.exe
    C:\WINDOWS\system32\drivers\down\15134609.exe
    C:\WINDOWS\system32\drivers\down\15152671.exe
    C:\WINDOWS\system32\drivers\down\15159671.exe
    C:\WINDOWS\system32\drivers\down\151937.exe
    C:\WINDOWS\system32\drivers\down\152140.exe
    C:\WINDOWS\system32\drivers\down\15217906.exe
    C:\WINDOWS\system32\drivers\down\15239578.exe
    C:\WINDOWS\system32\drivers\down\154656.exe
    C:\WINDOWS\system32\drivers\down\154968.exe
    C:\WINDOWS\system32\drivers\down\156593.exe
    C:\WINDOWS\system32\drivers\down\158171.exe
    C:\WINDOWS\system32\drivers\down\158500.exe
    C:\WINDOWS\system32\drivers\down\159250.exe
    C:\WINDOWS\system32\drivers\down\1597484.exe
    C:\WINDOWS\system32\drivers\down\159953.exe
    C:\WINDOWS\system32\drivers\down\160078.exe
    C:\WINDOWS\system32\drivers\down\1616703.exe
    C:\WINDOWS\system32\drivers\down\1621296.exe
    C:\WINDOWS\system32\drivers\down\162968.exe
    C:\WINDOWS\system32\drivers\down\164250.exe
    C:\WINDOWS\system32\drivers\down\165140.exe
    C:\WINDOWS\system32\drivers\down\166203.exe
    C:\WINDOWS\system32\drivers\down\166890.exe
    C:\WINDOWS\system32\drivers\down\168656.exe
    C:\WINDOWS\system32\drivers\down\168875.exe
    C:\WINDOWS\system32\drivers\down\169843.exe
    C:\WINDOWS\system32\drivers\down\170093.exe
    C:\WINDOWS\system32\drivers\down\170625.exe
    C:\WINDOWS\system32\drivers\down\170937.exe
    C:\WINDOWS\system32\drivers\down\171046.exe
    C:\WINDOWS\system32\drivers\down\172296.exe
    C:\WINDOWS\system32\drivers\down\173046.exe
    C:\WINDOWS\system32\drivers\down\173468.exe
    C:\WINDOWS\system32\drivers\down\174234.exe
    C:\WINDOWS\system32\drivers\down\174250.exe
    C:\WINDOWS\system32\drivers\down\175375.exe
    C:\WINDOWS\system32\drivers\down\175593.exe
    C:\WINDOWS\system32\drivers\down\176078.exe
    C:\WINDOWS\system32\drivers\down\176109.exe
    C:\WINDOWS\system32\drivers\down\176125.exe
    C:\WINDOWS\system32\drivers\down\176234.exe
    C:\WINDOWS\system32\drivers\down\178531.exe
    C:\WINDOWS\system32\drivers\down\180093.exe
    C:\WINDOWS\system32\drivers\down\180937.exe
    C:\WINDOWS\system32\drivers\down\182437.exe
    C:\WINDOWS\system32\drivers\down\182625.exe
    C:\WINDOWS\system32\drivers\down\183015.exe
    C:\WINDOWS\system32\drivers\down\183078.exe
    C:\WINDOWS\system32\drivers\down\183390.exe
    C:\WINDOWS\system32\drivers\down\185296.exe
    C:\WINDOWS\system32\drivers\down\186109.exe
    C:\WINDOWS\system32\drivers\down\186343.exe
    C:\WINDOWS\system32\drivers\down\186953.exe
    C:\WINDOWS\system32\drivers\down\187828.exe
    C:\WINDOWS\system32\drivers\down\188015.exe
    C:\WINDOWS\system32\drivers\down\188375.exe
    C:\WINDOWS\system32\drivers\down\188515.exe
    C:\WINDOWS\system32\drivers\down\188703.exe
    C:\WINDOWS\system32\drivers\down\188843.exe
    C:\WINDOWS\system32\drivers\down\190671.exe
    C:\WINDOWS\system32\drivers\down\191078.exe
    C:\WINDOWS\system32\drivers\down\191562.exe
    C:\WINDOWS\system32\drivers\down\192921.exe
    C:\WINDOWS\system32\drivers\down\193203.exe
    C:\WINDOWS\system32\drivers\down\193484.exe
    C:\WINDOWS\system32\drivers\down\193953.exe
    C:\WINDOWS\system32\drivers\down\195375.exe
    C:\WINDOWS\system32\drivers\down\196031.exe
    C:\WINDOWS\system32\drivers\down\196421.exe
    C:\WINDOWS\system32\drivers\down\196453.exe
    C:\WINDOWS\system32\drivers\down\196828.exe
    C:\WINDOWS\system32\drivers\down\197015.exe
    C:\WINDOWS\system32\drivers\down\197656.exe
    C:\WINDOWS\system32\drivers\down\198437.exe
    C:\WINDOWS\system32\drivers\down\198640.exe
    C:\WINDOWS\system32\drivers\down\198984.exe
    C:\WINDOWS\system32\drivers\down\199593.exe
    C:\WINDOWS\system32\drivers\down\200265.exe
    C:\WINDOWS\system32\drivers\down\200968.exe
    C:\WINDOWS\system32\drivers\down\201171.exe
    C:\WINDOWS\system32\drivers\down\201265.exe
    C:\WINDOWS\system32\drivers\down\201687.exe
    C:\WINDOWS\system32\drivers\down\203328.exe
    C:\WINDOWS\system32\drivers\down\203843.exe
    C:\WINDOWS\system32\drivers\down\204109.exe
    C:\WINDOWS\system32\drivers\down\204515.exe
    C:\WINDOWS\system32\drivers\down\204734.exe
    C:\WINDOWS\system32\drivers\down\205796.exe
    C:\WINDOWS\system32\drivers\down\206296.exe
    C:\WINDOWS\system32\drivers\down\207578.exe
    C:\WINDOWS\system32\drivers\down\207703.exe
    C:\WINDOWS\system32\drivers\down\208453.exe
    C:\WINDOWS\system32\drivers\down\208500.exe
    C:\WINDOWS\system32\drivers\down\211375.exe
    C:\WINDOWS\system32\drivers\down\213750.exe
    C:\WINDOWS\system32\drivers\down\214843.exe
    C:\WINDOWS\system32\drivers\down\217421.exe
    C:\WINDOWS\system32\drivers\down\219265.exe
    C:\WINDOWS\system32\drivers\down\219859.exe
    C:\WINDOWS\system32\drivers\down\220468.exe
    C:\WINDOWS\system32\drivers\down\220718.exe
    C:\WINDOWS\system32\drivers\down\220765.exe
    C:\WINDOWS\system32\drivers\down\220890.exe
    C:\WINDOWS\system32\drivers\down\221000.exe
    C:\WINDOWS\system32\drivers\down\224312.exe
    C:\WINDOWS\system32\drivers\down\225031.exe
    C:\WINDOWS\system32\drivers\down\225343.exe
    C:\WINDOWS\system32\drivers\down\225437.exe
    C:\WINDOWS\system32\drivers\down\226281.exe
    C:\WINDOWS\system32\drivers\down\227406.exe
    C:\WINDOWS\system32\drivers\down\228812.exe
    C:\WINDOWS\system32\drivers\down\229937.exe
    C:\WINDOWS\system32\drivers\down\230093.exe
    C:\WINDOWS\system32\drivers\down\230453.exe
    C:\WINDOWS\system32\drivers\down\231125.exe
    C:\WINDOWS\system32\drivers\down\231437.exe
    C:\WINDOWS\system32\drivers\down\234890.exe
    C:\WINDOWS\system32\drivers\down\236515.exe
    C:\WINDOWS\system32\drivers\down\237015.exe
    C:\WINDOWS\system32\drivers\down\238265.exe
    C:\WINDOWS\system32\drivers\down\239156.exe
    C:\WINDOWS\system32\drivers\down\241046.exe
    C:\WINDOWS\system32\drivers\down\244203.exe
    C:\WINDOWS\system32\drivers\down\244218.exe
    C:\WINDOWS\system32\drivers\down\244515.exe
    C:\WINDOWS\system32\drivers\down\244640.exe
    C:\WINDOWS\system32\drivers\down\247609.exe
    C:\WINDOWS\system32\drivers\down\254656.exe
    C:\WINDOWS\system32\drivers\down\256171.exe
    C:\WINDOWS\system32\drivers\down\258765.exe
    C:\WINDOWS\system32\drivers\down\259125.exe
    C:\WINDOWS\system32\drivers\down\264968.exe
    C:\WINDOWS\system32\drivers\down\268906.exe
    C:\WINDOWS\system32\drivers\down\273234.exe
    C:\WINDOWS\system32\drivers\down\275515.exe
    C:\WINDOWS\system32\drivers\down\276109.exe
    C:\WINDOWS\system32\drivers\down\276703.exe
    C:\WINDOWS\system32\drivers\down\277437.exe
    C:\WINDOWS\system32\drivers\down\277625.exe
    C:\WINDOWS\system32\drivers\down\283796.exe
    C:\WINDOWS\system32\drivers\down\286484.exe
    C:\WINDOWS\system32\drivers\down\288968.exe
    C:\WINDOWS\system32\drivers\down\290343.exe
    C:\WINDOWS\system32\drivers\down\29127203.exe
    C:\WINDOWS\system32\drivers\down\29130500.exe
    C:\WINDOWS\system32\drivers\down\291687.exe
    C:\WINDOWS\system32\drivers\down\29240281.exe
    C:\WINDOWS\system32\drivers\down\29245437.exe
    C:\WINDOWS\system32\drivers\down\29250312.exe
    C:\WINDOWS\system32\drivers\down\29260265.exe
    C:\WINDOWS\system32\drivers\down\29260281.exe
    C:\WINDOWS\system32\drivers\down\29264187.exe
    C:\WINDOWS\system32\drivers\down\29265515.exe
    C:\WINDOWS\system32\drivers\down\29267015.exe
    C:\WINDOWS\system32\drivers\down\29268234.exe
    C:\WINDOWS\system32\drivers\down\29269984.exe
    C:\WINDOWS\system32\drivers\down\29275906.exe
    C:\WINDOWS\system32\drivers\down\29278640.exe
    C:\WINDOWS\system32\drivers\down\29279328.exe
    C:\WINDOWS\system32\drivers\down\29279953.exe
    C:\WINDOWS\system32\drivers\down\29280390.exe
    C:\WINDOWS\system32\drivers\down\29281921.exe
    C:\WINDOWS\system32\drivers\down\29283843.exe
    C:\WINDOWS\system32\drivers\down\29310328.exe
    C:\WINDOWS\system32\drivers\down\29312203.exe
    C:\WINDOWS\system32\drivers\down\293390.exe
    C:\WINDOWS\system32\drivers\down\29711656.exe
    C:\WINDOWS\system32\drivers\down\29897625.exe
    C:\WINDOWS\system32\drivers\down\29920687.exe
    C:\WINDOWS\system32\drivers\down\29950015.exe
    C:\WINDOWS\system32\drivers\down\30043750.exe
    C:\WINDOWS\system32\drivers\down\30043843.exe
    C:\WINDOWS\system32\drivers\down\30101640.exe
    C:\WINDOWS\system32\drivers\down\30121500.exe
    C:\WINDOWS\system32\drivers\down\30143515.exe
    C:\WINDOWS\system32\drivers\down\30172984.exe
    C:\WINDOWS\system32\drivers\down\30208968.exe
    C:\WINDOWS\system32\drivers\down\30260390.exe
    C:\WINDOWS\system32\drivers\down\30277437.exe
    C:\WINDOWS\system32\drivers\down\30281875.exe
    C:\WINDOWS\system32\drivers\down\30286828.exe
    C:\WINDOWS\system32\drivers\down\30294281.exe
    C:\WINDOWS\system32\drivers\down\30318453.exe
    C:\WINDOWS\system32\drivers\down\30327234.exe
    C:\WINDOWS\system32\drivers\down\30390890.exe
    C:\WINDOWS\system32\drivers\down\30422734.exe
    C:\WINDOWS\system32\drivers\down\311218.exe
    C:\WINDOWS\system32\drivers\down\322890.exe
    C:\WINDOWS\system32\drivers\down\325015.exe
    C:\WINDOWS\system32\drivers\down\327703.exe
    C:\WINDOWS\system32\drivers\down\32850906.exe
    C:\WINDOWS\system32\drivers\down\32855828.exe
    C:\WINDOWS\system32\drivers\down\32861609.exe
    C:\WINDOWS\system32\drivers\down\32876484.exe
    C:\WINDOWS\system32\drivers\down\32876515.exe
    C:\WINDOWS\system32\drivers\down\32882875.exe
    C:\WINDOWS\system32\drivers\down\32884234.exe
    C:\WINDOWS\system32\drivers\down\32885921.exe
    C:\WINDOWS\system32\drivers\down\32887250.exe
    C:\WINDOWS\system32\drivers\down\32889015.exe
    C:\WINDOWS\system32\drivers\down\32893687.exe
    C:\WINDOWS\system32\drivers\down\32899375.exe
    C:\WINDOWS\system32\drivers\down\32899578.exe
    C:\WINDOWS\system32\drivers\down\32899781.exe
    C:\WINDOWS\system32\drivers\down\32908812.exe
    C:\WINDOWS\system32\drivers\down\32910984.exe
    C:\WINDOWS\system32\drivers\down\32911781.exe
    C:\WINDOWS\system32\drivers\down\32941796.exe
    C:\WINDOWS\system32\drivers\down\32943468.exe
    C:\WINDOWS\system32\drivers\down\32946984.exe
    C:\WINDOWS\system32\drivers\down\339312.exe
    C:\WINDOWS\system32\drivers\down\349218.exe
    C:\WINDOWS\system32\drivers\down\350765.exe
    C:\WINDOWS\system32\drivers\down\3539812.exe
    C:\WINDOWS\system32\drivers\down\3555515.exe
    C:\WINDOWS\system32\drivers\down\3561265.exe
    C:\WINDOWS\system32\drivers\down\356703.exe
    C:\WINDOWS\system32\drivers\down\3580703.exe
    C:\WINDOWS\system32\drivers\down\3581390.exe
    C:\WINDOWS\system32\drivers\down\361671.exe
    C:\WINDOWS\system32\drivers\down\364578.exe
    C:\WINDOWS\system32\drivers\down\368984.exe
    C:\WINDOWS\system32\drivers\down\388203.exe
    C:\WINDOWS\system32\drivers\down\388328.exe
    C:\WINDOWS\system32\drivers\down\396218.exe
    C:\WINDOWS\system32\drivers\down\399781.exe
    C:\WINDOWS\system32\drivers\down\406343.exe
    C:\WINDOWS\system32\drivers\down\409968.exe
    C:\WINDOWS\system32\drivers\down\412250.exe
    C:\WINDOWS\system32\drivers\down\413203.exe
    C:\WINDOWS\system32\drivers\down\420796.exe
    C:\WINDOWS\system32\drivers\down\425781.exe
    C:\WINDOWS\system32\drivers\down\432453.exe
    C:\WINDOWS\system32\drivers\down\433421.exe
    C:\WINDOWS\system32\drivers\down\43724500.exe
    C:\WINDOWS\system32\drivers\down\43725156.exe
    C:\WINDOWS\system32\drivers\down\43732187.exe
    C:\WINDOWS\system32\drivers\down\43736312.exe
    C:\WINDOWS\system32\drivers\down\43748953.exe
    C:\WINDOWS\system32\drivers\down\43749500.exe
    C:\WINDOWS\system32\drivers\down\43753125.exe
    C:\WINDOWS\system32\drivers\down\43754718.exe
    C:\WINDOWS\system32\drivers\down\43756312.exe
    C:\WINDOWS\system32\drivers\down\43757656.exe
    C:\WINDOWS\system32\drivers\down\43759656.exe
    C:\WINDOWS\system32\drivers\down\43765109.exe
    C:\WINDOWS\system32\drivers\down\43767968.exe
    C:\WINDOWS\system32\drivers\down\43768328.exe
    C:\WINDOWS\system32\drivers\down\43769531.exe
    C:\WINDOWS\system32\drivers\down\43769984.exe
    C:\WINDOWS\system32\drivers\down\43771640.exe
    C:\WINDOWS\system32\drivers\down\43774640.exe
    C:\WINDOWS\system32\drivers\down\43800546.exe
    C:\WINDOWS\system32\drivers\down\43802718.exe
    C:\WINDOWS\system32\drivers\down\440421.exe
    C:\WINDOWS\system32\drivers\down\443718.exe
    C:\WINDOWS\system32\drivers\down\446046.exe
    C:\WINDOWS\system32\drivers\down\448328.exe
    C:\WINDOWS\system32\drivers\down\450421.exe
    C:\WINDOWS\system32\drivers\down\461781.exe
    C:\WINDOWS\system32\drivers\down\467187.exe
    C:\WINDOWS\system32\drivers\down\471578.exe
    C:\WINDOWS\system32\drivers\down\472125.exe
    C:\WINDOWS\system32\drivers\down\47359500.exe
    C:\WINDOWS\system32\drivers\down\47360437.exe
    C:\WINDOWS\system32\drivers\down\47366984.exe
    C:\WINDOWS\system32\drivers\down\47371203.exe
    C:\WINDOWS\system32\drivers\down\473765.exe
    C:\WINDOWS\system32\drivers\down\47378218.exe
    C:\WINDOWS\system32\drivers\down\47396843.exe
    C:\WINDOWS\system32\drivers\down\47397562.exe
    C:\WINDOWS\system32\drivers\down\47403406.exe
    C:\WINDOWS\system32\drivers\down\47405421.exe
    C:\WINDOWS\system32\drivers\down\47407328.exe
    C:\WINDOWS\system32\drivers\down\47409031.exe
    C:\WINDOWS\system32\drivers\down\47410921.exe
    C:\WINDOWS\system32\drivers\down\47416343.exe
    C:\WINDOWS\system32\drivers\down\47419203.exe
    C:\WINDOWS\system32\drivers\down\47419609.exe
    C:\WINDOWS\system32\drivers\down\47427000.exe
    C:\WINDOWS\system32\drivers\down\47429218.exe
    C:\WINDOWS\system32\drivers\down\47431578.exe
    C:\WINDOWS\system32\drivers\down\47458156.exe
    C:\WINDOWS\system32\drivers\down\47460812.exe
    C:\WINDOWS\system32\drivers\down\47465562.exe
    C:\WINDOWS\system32\drivers\down\477656.exe
    C:\WINDOWS\system32\drivers\down\480187.exe
    C:\WINDOWS\system32\drivers\down\481359.exe
    C:\WINDOWS\system32\drivers\down\484390.exe
    C:\WINDOWS\system32\drivers\down\489250.exe
    C:\WINDOWS\system32\drivers\down\512390.exe
    C:\WINDOWS\system32\drivers\down\519921.exe
    C:\WINDOWS\system32\drivers\down\58244234.exe
    C:\WINDOWS\system32\drivers\down\58258359.exe
    C:\WINDOWS\system32\drivers\down\58265281.exe
    C:\WINDOWS\system32\drivers\down\58295984.exe
    C:\WINDOWS\system32\drivers\down\58296031.exe
    C:\WINDOWS\system32\drivers\down\58305171.exe
    C:\WINDOWS\system32\drivers\down\58310140.exe
    C:\WINDOWS\system32\drivers\down\58312500.exe
    C:\WINDOWS\system32\drivers\down\58314000.exe
    C:\WINDOWS\system32\drivers\down\58320906.exe
    C:\WINDOWS\system32\drivers\down\58355171.exe
    C:\WINDOWS\system32\drivers\down\58366906.exe
    C:\WINDOWS\system32\drivers\down\58369437.exe
    C:\WINDOWS\system32\drivers\down\58371578.exe
    C:\WINDOWS\system32\drivers\down\58372859.exe
    C:\WINDOWS\system32\drivers\down\58379296.exe
    C:\WINDOWS\system32\drivers\down\58384375.exe
    C:\WINDOWS\system32\drivers\down\58415125.exe
    C:\WINDOWS\system32\drivers\down\58418906.exe
    C:\WINDOWS\system32\drivers\down\61885421.exe
    C:\WINDOWS\system32\drivers\down\61892234.exe
    C:\WINDOWS\system32\drivers\down\61914031.exe
    C:\WINDOWS\system32\drivers\down\61918687.exe
    C:\WINDOWS\system32\drivers\down\61922750.exe
    C:\WINDOWS\system32\drivers\down\61941062.exe
    C:\WINDOWS\system32\drivers\down\61943984.exe
    C:\WINDOWS\system32\drivers\down\61945406.exe
    C:\WINDOWS\system32\drivers\down\61947218.exe
    C:\WINDOWS\system32\drivers\down\61948343.exe
    C:\WINDOWS\system32\drivers\down\61951031.exe
    C:\WINDOWS\system32\drivers\down\61955859.exe
    C:\WINDOWS\system32\drivers\down\61959296.exe
    C:\WINDOWS\system32\drivers\down\61959531.exe
    C:\WINDOWS\system32\drivers\down\61959718.exe
    C:\WINDOWS\system32\drivers\down\61960296.exe
    C:\WINDOWS\system32\drivers\down\61961765.exe
    C:\WINDOWS\system32\drivers\down\61962281.exe
    C:\WINDOWS\system32\drivers\down\61988734.exe
    C:\WINDOWS\system32\drivers\down\61990546.exe
    C:\WINDOWS\system32\drivers\down\61993875.exe
    C:\WINDOWS\system32\drivers\down\63609.exe
    C:\WINDOWS\system32\drivers\down\64953.exe
    C:\WINDOWS\system32\drivers\down\65906.exe
    C:\WINDOWS\system32\drivers\down\66812.exe
    C:\WINDOWS\system32\drivers\down\68625.exe
    C:\WINDOWS\system32\drivers\down\70000.exe
    C:\WINDOWS\system32\drivers\down\71828.exe
    C:\WINDOWS\system32\drivers\down\72203.exe
    C:\WINDOWS\system32\drivers\down\72879140.exe
    C:\WINDOWS\system32\drivers\down\72894187.exe
    C:\WINDOWS\system32\drivers\down\72938765.exe
    C:\WINDOWS\system32\drivers\down\72938781.exe
    C:\WINDOWS\system32\drivers\down\72952296.exe
    C:\WINDOWS\system32\drivers\down\72957937.exe
    C:\WINDOWS\system32\drivers\down\72962062.exe
    C:\WINDOWS\system32\drivers\down\72963140.exe
    C:\WINDOWS\system32\drivers\down\72979437.exe
    C:\WINDOWS\system32\drivers\down\73009609.exe
    C:\WINDOWS\system32\drivers\down\73019515.exe
    C:\WINDOWS\system32\drivers\down\73022109.exe
    C:\WINDOWS\system32\drivers\down\73023312.exe
    C:\WINDOWS\system32\drivers\down\73060312.exe
    C:\WINDOWS\system32\drivers\down\73066468.exe
    C:\WINDOWS\system32\drivers\down\73116437.exe
    C:\WINDOWS\system32\drivers\down\73136703.exe
    C:\WINDOWS\system32\drivers\down\73703.exe
    C:\WINDOWS\system32\drivers\down\74953.exe
    C:\WINDOWS\system32\drivers\down\75031.exe
    C:\WINDOWS\system32\drivers\down\76671.exe
    C:\WINDOWS\system32\drivers\down\77328.exe
    C:\WINDOWS\system32\drivers\down\78156.exe
    C:\WINDOWS\system32\drivers\down\78406.exe
    C:\WINDOWS\system32\drivers\down\78593.exe
    C:\WINDOWS\system32\drivers\down\78890.exe
    C:\WINDOWS\system32\drivers\down\79765.exe
    C:\WINDOWS\system32\drivers\down\80515.exe
    C:\WINDOWS\system32\drivers\down\81265.exe
    C:\WINDOWS\system32\drivers\down\82328.exe
    C:\WINDOWS\system32\drivers\down\82984.exe
    C:\WINDOWS\system32\drivers\down\84062.exe
    C:\WINDOWS\system32\drivers\down\84250.exe
    C:\WINDOWS\system32\drivers\down\84828.exe
    C:\WINDOWS\system32\drivers\down\85218.exe
    C:\WINDOWS\system32\drivers\down\86593.exe
    C:\WINDOWS\system32\drivers\down\86656.exe
    C:\WINDOWS\system32\drivers\down\87571984.exe
    C:\WINDOWS\system32\drivers\down\87589984.exe
    C:\WINDOWS\system32\drivers\down\87597281.exe
    C:\WINDOWS\system32\drivers\down\87607531.exe
    C:\WINDOWS\system32\drivers\down\87663984.exe
    C:\WINDOWS\system32\drivers\down\87666109.exe
    C:\WINDOWS\system32\drivers\down\87686375.exe
    C:\WINDOWS\system32\drivers\down\87694906.exe
    C:\WINDOWS\system32\drivers\down\87706390.exe
    C:\WINDOWS\system32\drivers\down\87711500.exe
    C:\WINDOWS\system32\drivers\down\87715000.exe
    C:\WINDOWS\system32\drivers\down\87728593.exe
    C:\WINDOWS\system32\drivers\down\87739187.exe
    C:\WINDOWS\system32\drivers\down\87741765.exe
    C:\WINDOWS\system32\drivers\down\87742671.exe
    C:\WINDOWS\system32\drivers\down\87766578.exe
    C:\WINDOWS\system32\drivers\down\87774031.exe
    C:\WINDOWS\system32\drivers\down\87782765.exe
    C:\WINDOWS\system32\drivers\down\87813484.exe
    C:\WINDOWS\system32\drivers\down\87822906.exe
    C:\WINDOWS\system32\drivers\down\88078.exe
    C:\WINDOWS\system32\drivers\down\88812.exe
    C:\WINDOWS\system32\drivers\down\89734.exe
    C:\WINDOWS\system32\drivers\down\89843.exe
    C:\WINDOWS\system32\drivers\down\89859.exe
    C:\WINDOWS\system32\drivers\down\92421.exe
    C:\WINDOWS\system32\drivers\down\93500.exe
    C:\WINDOWS\system32\drivers\down\93921.exe
    C:\WINDOWS\system32\drivers\down\94921.exe
    C:\WINDOWS\system32\drivers\down\95375.exe
    C:\WINDOWS\system32\drivers\down\96343.exe
    C:\WINDOWS\system32\drivers\down\98640.exe
    C:\WINDOWS\system32\drivers\down\99875.exe
    C:\WINDOWS\system32\drivers\hldrrr.exe
    C:\WINDOWS\system32\drivers\srosa.sys
    C:\WINDOWS\system32\mdelk.exe
    C:\WINDOWS\system32\wintems.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    -------\LEGACY_SROSA
    -------\srosa

    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-10 to 2008-02-10 ))))))))))))))))))))))))))))))))))))
    .

    2008-02-08 19:15 . 2008-02-08 19:15 <REP> d-------- C:\Program Files\Trend Micro
    2008-02-03 15:29 . 2008-02-03 15:29 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
    2008-02-03 15:29 . 2008-02-03 15:29 1,406 --a------ C:\WINDOWS\system32\Help.ico
    2008-02-03 14:57 . 2008-02-10 09:44 <REP> d-------- C:\Muestras
    2008-02-02 17:35 . 2008-02-02 18:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-02-10 17:22 --------- d-----w C:\Program Files\Wanadoo
    2008-02-09 21:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-02-03 15:49 --------- d-----w C:\Program Files\MSN Messenger
    2008-02-03 15:31 --------- d-----w C:\Program Files\Google
    2008-02-02 16:32 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-02-02 12:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
    2007-12-29 21:27 --------- d-----w C:\Documents and Settings\Maman\Application Data\Sports Interactive
    2007-12-16 17:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-11-17 11:43 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09 15360]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [ ]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 09:59 204288]
    "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
    "BitTorrent"="D:\Programmes\Bit Torrent\bittorrent.exe" [ ]
    "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 16:22 7618560]
    "nwiz"="nwiz.exe" [2006-06-01 16:22 1519616 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-06-01 16:22 86016]
    "SoundMan"="SOUNDMAN.EXE" [2006-06-21 04:42 577536 C:\WINDOWS\soundman.exe]
    "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
    "DAEMON Tools"="D:\Programmes\Daemon\DAEMON Tools\daemon.exe" [2006-09-14 21:09 157592]
    "MMTray"="C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-05-20 19:51 90112]
    "Agent"="C:\Program Files\Power Cinema\PowerVCR II\Agent.exe" [2002-05-21 04:52 94208]
    "Remote_Agent"="C:\Program Files\Power Cinema\PowerVCR II\RemoteAgent.exe" [2002-05-21 04:52 32768]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
    "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49 20480]
    "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55 32768]
    "ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-08-19 10:37 49152]
    "Domino"="C:\WINDOWS\Domino.exe" [2006-08-18 15:58 49152]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-23 23:08 49152]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15:09 15360]

    R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys [2003-05-22 16:44]
    R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 15:43]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
    S3 ZSMC211;Webcam (ZS0211);C:\WINDOWS\system32\Drivers\ZS211.sys [2006-10-18 08:23]

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-02-10 18:30:21
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    C:\WINDOWS\system32\ban_list.txt 5679 bytes

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 1

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Windows Media Player\WMPNetwk.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-02-10 18:34:13 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-02-10 17:34:10
    .
    2008-01-09 18:02:02 --- E O F ---

    Que dois je faire maintenant?
    0
  9. Utilisateur anonyme
     
    Re ,

    réactive ta restauration système
    Clic droit sur « Poste de travail », puis sur « Propriétés »,
    Vas sur l’onglet « Restauration système »
    Tu décoches la case « Désactiver la restauration »
    Termine par [Appliquer] [OK]

    ******

    Lance Hijackthis ( voir mon 1er message )

    a+
    0
    1. sebjseb
       
      Voici le rapport de HJT:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:31:37, on 10/02/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16574)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      D:\Programmes\Daemon\DAEMON Tools\daemon.exe
      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      C:\Program Files\Power Cinema\PowerVCR II\Agent.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\WINDOWS\ZSSnp211.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\WINDOWS\Domino.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
      O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programmes\Daemon\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      O4 - HKLM\..\Run: [Agent] C:\Program Files\Power Cinema\PowerVCR II\Agent.exe
      O4 - HKLM\..\Run: [Remote_Agent] C:\Program Files\Power Cinema\PowerVCR II\RemoteAgent.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
      O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [BitTorrent] "D:\Programmes\Bit Torrent\bittorrent.exe" --force_start_minimized
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: Eurobarre.lnk = C:\Program Files\Eurobarre\eb.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: Add to AMV Converter... - C:\Documents and Settings\Seb\Bureau\baladeur\AMVConverter\grab.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Documents and Settings\Seb\Bureau\baladeur\MediaManager\grab.html
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
      O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

      End of file - 6991 bytes


      Alors que faire maintenant?
      merci en tout cas pour tous tes conseils
      0
      1. Utilisateur anonyme > sebjseb
         
        Re ,

        Procédure plus haut ;)

        A+
        0
      2. sebjseb > Utilisateur anonyme
         
        alors voici les deux analyse avec le premier site

        Fichier Domino.exe reçu le 2008.02.10 17:04:35 (CET)
        Situation actuelle: terminé

        Résultat: 0/32 (0.00%)
        Formaté Impression des résultats
        Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2008.2.6.10 2008.02.05 -
        AntiVir 7.6.0.62 2008.02.08 -
        Authentium 4.93.8 2008.02.08 -
        Avast 4.7.1098.0 2008.02.09 -
        AVG 7.5.0.516 2008.02.10 -
        BitDefender 7.2 2008.02.10 -
        CAT-QuickHeal None 2008.02.08 -
        ClamAV 0.92 2008.02.10 -
        DrWeb 4.44.0.09170 2008.02.10 -
        eSafe 7.0.15.0 2008.01.28 -
        eTrust-Vet 31.3.5522 2008.02.08 -
        Ewido 4.0 2008.02.10 -
        FileAdvisor 1 2008.02.10 -
        Fortinet 3.14.0.0 2008.02.10 -
        F-Prot 4.4.2.54 2008.02.10 -
        F-Secure 6.70.13260.0 2008.02.10 -
        Ikarus T3.1.1.20 2008.02.10 -
        Kaspersky 7.0.0.125 2008.02.10 -
        McAfee 5226 2008.02.08 -
        Microsoft 1.3204 2008.02.10 -
        NOD32v2 2861 2008.02.09 -
        Norman 5.80.02 2008.02.08 -
        Panda 9.0.0.4 2008.02.10 -
        Prevx1 V2 2008.02.10 -
        Rising 20.29.22.00 2008.01.30 -
        Sophos 4.26.0 2008.02.10 -
        Sunbelt 2.2.907.0 2008.02.09 -
        Symantec 10 2008.02.10 -
        TheHacker 6.2.9.215 2008.02.09 -
        VBA32 3.12.6.0 2008.02.09 -
        VirusBuster 4.3.26:9 2008.02.09 -
        Webwasher-Gateway 6.6.2 2008.02.10 -
        Information additionnelle
        File size: 49152 bytes
        MD5: 5603c2c8940f5e43864d4000304ab175
        SHA1: f22234ed04ad1220b28cacaabc2ab0361ce6fe11
        PEiD: InstallShield 2000



        voici la deuxieme avec le premier site

        Fichier ZSSnp211.EXE reçu le 2008.02.10 11:25:52 (CET)
        Situation actuelle: terminé

        Résultat: 0/32 (0.00%)
        Formaté Impression des résultats
        Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2008.2.6.10 2008.02.05 -
        AntiVir 7.6.0.62 2008.02.08 -
        Authentium 4.93.8 2008.02.08 -
        Avast 4.7.1098.0 2008.02.09 -
        AVG 7.5.0.516 2008.02.09 -
        BitDefender 7.2 2008.02.10 -
        CAT-QuickHeal None 2008.02.08 -
        ClamAV 0.92 2008.02.10 -
        DrWeb 4.44.0.09170 2008.02.09 -
        eSafe 7.0.15.0 2008.01.28 -
        eTrust-Vet 31.3.5522 2008.02.08 -
        Ewido 4.0 2008.02.09 -
        FileAdvisor 1 2008.02.10 -
        Fortinet 3.14.0.0 2008.02.10 -
        F-Prot 4.4.2.54 2008.02.10 -
        F-Secure 6.70.13260.0 2008.02.09 -
        Ikarus T3.1.1.20 2008.02.10 -
        Kaspersky 7.0.0.125 2008.02.10 -
        McAfee 5226 2008.02.08 -
        Microsoft 1.3204 2008.02.10 -
        NOD32v2 2861 2008.02.09 -
        Norman 5.80.02 2008.02.08 -
        Panda 9.0.0.4 2008.02.09 -
        Prevx1 V2 2008.02.10 -
        Rising 20.29.22.00 2008.01.30 -
        Sophos 4.26.0 2008.02.10 -
        Sunbelt 2.2.907.0 2008.02.09 -
        Symantec 10 2008.02.10 -
        TheHacker 6.2.9.215 2008.02.09 -
        VBA32 3.12.6.0 2008.02.09 -
        VirusBuster 4.3.26:9 2008.02.09 -
        Webwasher-Gateway 6.6.2 2008.02.10 -
        Information additionnelle
        File size: 49152 bytes
        MD5: 6409f6271afe9b4fe449db849042e240
        SHA1: 7c8475f7d37f0b72a10c04316b143f28cf0cf43b
        PEiD: InstallShield 2000


        avec l'autre site il m'a trouvé aucun virus(c'etait marqué en allemand)

        je viens de relancer hjt j'attends la reponse!!
        0
  10. Utilisateur anonyme
     
    Re , ok

    Poste un new rapport hijackthis stp
    a+
    0
    1. quiksilver1956
       
      Bonjour Cyril,

      J'ai suivi les explications que tu as donné a Seb car c'était le même pb. en utikisant combo fix ça a tout remis à sa place et tt refonctionne normalement ! merci pour ton aide
      et bravo!!
      christian
      0
      1. Utilisateur anonyme > quiksilver1956
         
        Bonjour ,

        Tu as eu de la chance , combofix est un outil très puissant qui peut faire planter complètement ton pc en cas d'utilisation inappropriée ....
        Mais bon si tu as résolu ton problème ( quoique il doit rester un peu de saloperies ) c'est tant mieux ;)
        A+ et bonne continuation.
        0