Avast et spybot appli.win32 non valide
woody67
Messages postés
12
Statut
Membre
-
giny_2 -
giny_2 -
Bonjour,
Je ne peux plus demarrer avast, spybot et ccleaner. Lors du lancenement, il m'est indiqué application non valide win32.
A priori en regardant sur les forums, il pourrait s'agir d'une infection type bagle, mais même elibagl ne demarre pas....
Des messages d'alertes windows se sont egalement affichées, demandant l'insertion du cd windows xp que je n'ai pas (mis a part un cd "product recovery cd_rom" recu a l'achat dont je ne comprend pas l'utilisation)
Je dois imprimer des photos du mariage de ma belle soeur et au vus de l'etat de mon pc c'est imossible!! je suis dans la m.....
Papyber, tu serais pas dans le coin des fois???????
merci d'avance pour votre aide
cdt
Je ne peux plus demarrer avast, spybot et ccleaner. Lors du lancenement, il m'est indiqué application non valide win32.
A priori en regardant sur les forums, il pourrait s'agir d'une infection type bagle, mais même elibagl ne demarre pas....
Des messages d'alertes windows se sont egalement affichées, demandant l'insertion du cd windows xp que je n'ai pas (mis a part un cd "product recovery cd_rom" recu a l'achat dont je ne comprend pas l'utilisation)
Je dois imprimer des photos du mariage de ma belle soeur et au vus de l'etat de mon pc c'est imossible!! je suis dans la m.....
Papyber, tu serais pas dans le coin des fois???????
merci d'avance pour votre aide
cdt
A voir également:
- Avast et spybot appli.win32 non valide
- Ethernet n'a pas de configuration ip valide - Guide
- Spybot - Télécharger - Antivirus & Antimalwares
- Désinstaller avast - Télécharger - Antivirus & Antimalwares
- Ora-00904 identificateur non valide ✓ - Forum Bases de données
- Paiement validé mais pas la commande - Forum Consommation & Internet
3 réponses
Hello, j'ai eu le meme probleme, a premiere vue pour tes anti-virus et tout le tralala, c'est un BUGLE. Il empeche les anti-virus de marcher. Telecharger Elibagle. http://www.zonavirus.com/datos/archivos/Descargas/Utilidades%20SATINFO/ELIBAGLA.%D8D%D8HB%D8%D8H.EXE Voila bisous et dit moi si ca a marcher . . .
Merci pour ta reponse, mais je n'arrive pas a lancer elibagle, je l'ai sauvé sur le bureau, il s'ouvre... et rien ne se passe.
La fenetre disparait au bout d'un moment.. j'sais pas quoi faire
La fenetre disparait au bout d'un moment.. j'sais pas quoi faire
a l'attention de gen-hackman
voici le rapport apres sppression, ceci dis je ne peux plus accede a mon compte "comment ca marche," ni meme en créer un nouveau moyennement pratique en pleine manip.
Malwarebytes' Anti-Malware 1.35
Version de la base de données: 1933
Windows 5.1.2600 Service Pack 3
03/04/2009 06:27:16
mbam-log-2009-04-03 (06-27-16).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 154203
Temps écoulé: 40 minute(s), 56 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 24
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 35
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\IGB (Malware.Trace) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP962\A0231687.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP963\A0232103.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP964\A0232265.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232487.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232653.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232660.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232680.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232689.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232704.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232729.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0233724.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0233739.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234739.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234765.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234829.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234857.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234874.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0235874.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236874.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236886.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236893.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236909.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP966\A0237245.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP968\A0237462.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP969\A0237529.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP969\A0237565.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP969\A0237589.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0237641.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238654.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238685.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238704.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238728.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238747.exe (Rootkit.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238749.exe (Trojan.Packed) -> Quarantined and deleted successfully.
voici le rapport apres sppression, ceci dis je ne peux plus accede a mon compte "comment ca marche," ni meme en créer un nouveau moyennement pratique en pleine manip.
Malwarebytes' Anti-Malware 1.35
Version de la base de données: 1933
Windows 5.1.2600 Service Pack 3
03/04/2009 06:27:16
mbam-log-2009-04-03 (06-27-16).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 154203
Temps écoulé: 40 minute(s), 56 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 24
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 35
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\IGB (Malware.Trace) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP962\A0231687.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP963\A0232103.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP964\A0232265.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232487.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232653.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232660.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232680.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232689.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232704.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0232729.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0233724.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0233739.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234739.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234765.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234829.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234857.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0234874.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0235874.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236874.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236886.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236893.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP965\A0236909.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP966\A0237245.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP968\A0237462.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP969\A0237529.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP969\A0237565.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP969\A0237589.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0237641.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238654.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238685.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238704.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238728.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238747.exe (Rootkit.Dropper) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D197F9F-881B-4A44-8CE0-0DDBFEF069BB}\RP972\A0238749.exe (Trojan.Packed) -> Quarantined and deleted successfully.
même souci pour avast et sptbot, en cherchant sur le site j'ai qu'il fallai prendre Findykill.. je l'ai installé et lancé (ci joint le rapport) mais maintenant je fais quoi???!!
merci d'avance toute aide est la bienvenu...
############################## [ FindyKill V4.721 ]
# User : alex (Administrateurs) # ALEX-C1DB4965DD
# Update on 29/03/09 by Chiquitine29
# Start at: 11:49:47 | 01/04/2009
# Website : http://pagesperso-orange.fr/FindyKill.Ad.Remover/
# AMD Athlon(tm) processor
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 14,62 Go (5,37 Go free) [WinXP] # NTFS
# D:\ # Disque fixe local # 37,31 Go (35,78 Go free) [40Go] # NTFS
# E:\ # Disque fixe local # 14 Go (8,99 Go free) # FAT32
# F:\ # Disque CD-ROM # 701,67 Mo (0 Mo free) [My Disc] # CDFS
# G:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\alex\Application Data\drivers\winupgro.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Documents and Settings\alex\Application Data\m\flec006.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\wintems.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Processus infectieux stoppés ]
"C:\Documents and Settings\alex\Application Data\drivers\winupgro.exe" (1556)
"C:\Documents and Settings\alex\Application Data\m\flec006.exe" (2792)
"C:\WINDOWS\system32\wintems.exe" (1072)
################## [ Fichiers / Dossiers infectieux C:\ ]
################## [ C:\WINDOWS & C:\WINDOWS\Prefetch ]
Found ! - C:\WINDOWS\prefetch\15143635.EXE-3467C9EC.pf
Found ! - C:\WINDOWS\prefetch\15224972.EXE-0DFEBA18.pf
Found ! - C:\WINDOWS\prefetch\15266762.EXE-32F3E424.pf
Found ! - C:\WINDOWS\prefetch\15270858.EXE-3760776C.pf
Found ! - C:\WINDOWS\prefetch\15277317.EXE-23B99462.pf
Found ! - C:\WINDOWS\prefetch\15545142.EXE-04D70746.pf
Found ! - C:\WINDOWS\prefetch\216821.EXE-01D6B646.pf
Found ! - C:\WINDOWS\prefetch\292961.EXE-36C6C023.pf
Found ! - C:\WINDOWS\prefetch\294633.EXE-10CB8606.pf
Found ! - C:\WINDOWS\prefetch\30001830.EXE-008072C0.pf
Found ! - C:\WINDOWS\prefetch\30126770.EXE-1D5B7483.pf
Found ! - C:\WINDOWS\prefetch\30131707.EXE-1C97074A.pf
Found ! - C:\WINDOWS\prefetch\30141120.EXE-223B37EC.pf
Found ! - C:\WINDOWS\prefetch\30362539.EXE-020B05C2.pf
Found ! - C:\WINDOWS\prefetch\340379.EXE-1DE31047.pf
Found ! - C:\WINDOWS\prefetch\347960.EXE-1C76815C.pf
Found ! - C:\WINDOWS\prefetch\356242.EXE-2F295B53.pf
Found ! - C:\WINDOWS\prefetch\374137.EXE-2F943715.pf
Found ! - C:\WINDOWS\prefetch\44814359.EXE-1C08BFB3.pf
Found ! - C:\WINDOWS\prefetch\44890689.EXE-281E7188.pf
Found ! - C:\WINDOWS\prefetch\44931187.EXE-18E2330E.pf
Found ! - C:\WINDOWS\prefetch\44937256.EXE-251986E1.pf
Found ! - C:\WINDOWS\prefetch\44942854.EXE-10F69710.pf
Found ! - C:\WINDOWS\prefetch\45084908.EXE-07AEC097.pf
Found ! - C:\WINDOWS\prefetch\59539753.EXE-2E63FFC6.pf
Found ! - C:\WINDOWS\prefetch\59611797.EXE-36F391DE.pf
Found ! - C:\WINDOWS\prefetch\59745729.EXE-07A05419.pf
Found ! - C:\WINDOWS\prefetch\59752119.EXE-323CB84A.pf
Found ! - C:\WINDOWS\prefetch\59759219.EXE-1EB76298.pf
Found ! - C:\WINDOWS\prefetch\59905329.EXE-05F6BA86.pf
Found ! - C:\WINDOWS\prefetch\606722.EXE-184C3699.pf
Found ! - C:\WINDOWS\prefetch\78009261.EXE-03C6BEAF.pf
Found ! - C:\WINDOWS\prefetch\78089907.EXE-02223D4A.pf
Found ! - C:\WINDOWS\prefetch\78128633.EXE-2D3F936A.pf
Found ! - C:\WINDOWS\prefetch\78137756.EXE-05FF40D6.pf
Found ! - C:\WINDOWS\prefetch\78146969.EXE-06700E0A.pf
Found ! - C:\WINDOWS\prefetch\78298767.EXE-1737E3F6.pf
Found ! - C:\WINDOWS\prefetch\CRAC.EXE-00066BFE.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-256D8097.pf
Found ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
################## [ C:\WINDOWS\system32 ]
Found ! - C:\WINDOWS\system32\mdelk.exe
Found ! - C:\WINDOWS\system32\wintems.exe
Found ! - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
Found ! - "C:\WINDOWS\system32\drivers\down"
################## [ C:\.. Application Data ... ]
Found ! - "C:\Documents and Settings\alex\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\alex\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\alex\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\alex\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\alex\Application Data\m\shared"
Found ! - "C:\Documents and Settings\alex\Application Data\m"
Found ! - "C:\Documents and Settings\alex\Application Data\drivers"
Found ! - "C:\Documents and Settings\alex\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\alex\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\alex\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\alex\Application Data\drivers\downld"
################## [ C:\Users...\Temp Files... ]
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\A8RT4YKS\b64[1].jpg
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\A8RT4YKS\b64_1[1].jpg
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\A8RT4YKS\b64_6[1].jpg
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\A8RT4YKS\file[1].txt
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\PY86OYGJ\b64_3[1].jpg
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\PY86OYGJ\b64_3[2].jpg
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\XGVARYKS\b64_2[1].jpg
Found ! - C:\Documents and Settings\alex\Local Settings\Temporary Internet Files\Content.IE5\XGVARYKS\servernames[1].htm
################## [ Registre / Clés infectieuses ]
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
Found ! - HKEY_USERS\S-1-5-21-606747145-1708537768-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
# HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
# HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
################## [ Recherche dans supports amovibles]
# Présence des fichiers :
################## [ Registre / Mountpoint2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.721 ! ]