Euh... c'est chaud la je crois...!

mactyer -  
crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   -
Bonjour,

et bien je fais appel a vous car j'ai vu qu'il semblait y avoir plein de gens calés en virus etc...!
Moi, je suis sur que j'en ai pleins car mon ordi galere de plus en plus!!!
Mais je ne sais pas comment faire, quel scan utiliser et je sais encore moins les interpreter...

Voila voila quoi, si quelqu'un pourrait m'aider a resoudres ces problemes de virus a la con ca serait bien cool!
Configuration: Windows XP
Firefox 2.0.0.17

17 réponses

  1. Utilisateur anonyme
     
    Telecharge malwarebytes

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

    Copie et colle le rapport stp.

    PS : les rapport sont aussi rangé dans l onglet rapport/log
    1
  2. mactyer
     
    ok. quand je veux ouvrir hijack ca me met un message comme quoi l'application n'est pas une application valide win32, donc je ne peux pas ouvrir hijack...
    0
  3. mactyer
     
    ok, merci, voila ce que ca donne:

    ----------------- FindyKill V4.005 ------------------

    * User : ben - XPSP2-85BA31B6A
    * Emplacement : C:\Program Files\FindyKill
    * Outils Mis a jours le 17/10/08 par Chiquitine29
    * Recherche effectuée à 0:30:04 le 19/10/2008
    * Windows XP - Internet Explorer 6.0.2900.2180

    ((((((((((((((((( *** Recherche *** ))))))))))))))))))

    --------------- [ Processus actifs ] ----------------

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    C:\Acer\Empowering Technology\admServ.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\LAUNCH~1\LManager.exe
    C:\Program Files\Fichiers communs\AOL\1203807828\ee\aolsoftware.exe
    C:\Acer\Empowering Technology\admtray.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    C:\WINDOWS\system32\drivers\hldrrr.exe
    C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
    C:\WINDOWS\system32\drivers\hldrrr.exe
    C:\Program Files\AOL 9.0b\aoltray.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wintems.exe
    C:\Documents and Settings\ben\Application Data\m\flec006.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\DOCUME~1\ben\LOCALS~1\Temp\RtkBtMnt.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
    C:\Program Files\Intel\WiFi\bin\ZCfgsvc.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\Fichiers communs\Intel\WirelessCommon\ifrmewrk.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    --------------- [ Processus infectieux stoppés ] ----------------

    "C:\WINDOWS\system32\drivers\hldrrr.exe" (2088)
    "C:\WINDOWS\system32\drivers\hldrrr.exe" (2496)
    "C:\WINDOWS\system32\wintems.exe" (2976)
    "C:\Documents and Settings\ben\Application Data\m\flec006.exe" (4068)

    --------------- [ Fichiers/Dossiers infectieux ] ----------------

    »»»» Presence des fichiers dans C:

    Présent ! - C:\InfoSat.txt

    »»»» Presence des fichiers dans C:\WINDOWS

    »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

    Present ! - C:\WINDOWS\prefetch\HLDRRR.EXE-106798BB.pf

    »»»» Presence des fichiers dans C:\WINDOWS\system32

    Présent ! - C:\WINDOWS\system32\mdelk.exe
    Présent ! - C:\WINDOWS\system32\wintems.exe
    Présent ! - C:\WINDOWS\system32\ban_list.txt

    »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

    Présent ! - C:\WINDOWS\system32\drivers\srosa.sys
    Présent ! - C:\WINDOWS\system32\drivers\hldrrr.exe
    Présent ! - "C:\WINDOWS\system32\drivers\downld"
    Present ! - C:\WINDOWS\system32\drivers\downld\182640.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\202750.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\208250.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\314140.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\323500.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\339750.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\345000.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\347140.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\397140.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41358890.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41467750.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\580500.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\142531.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\169781.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\177671.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\180171.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\197421.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\241781.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\246031.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\248781.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\253171.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\301281.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\309531.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\331171.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\361671.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41394671.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41431671.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41443171.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41447671.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\134812.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\187562.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\277312.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\321312.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\480312.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\142703.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\195703.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\209593.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\227843.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\298343.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\331453.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\346703.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41396593.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41415343.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41568093.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\622453.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\198984.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\243984.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\300734.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41332484.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\176765.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\205265.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\206265.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\217015.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\256515.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\270015.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\316875.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\368765.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41366515.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41421765.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41491265.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\550765.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\121546.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\151406.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\154046.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\183046.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\196046.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\199406.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\206406.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\229906.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\267656.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41313656.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41452156.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\451906.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\539156.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\593656.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\177687.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\182187.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\212187.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41280937.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41353937.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\138578.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\155468.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\167578.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\183078.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\195218.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\223328.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\224468.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\248328.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\249468.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\267078.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\291968.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41281828.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41316218.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41341328.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41346218.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\41592468.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\632718.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\117359.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\158359.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\165859.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\232609.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\270359.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\425859.exe
    Present ! - C:\WINDOWS\system32\drivers\downld\515109.exe

    »»»» Presence des fichiers dans C:\Documents and Settings\ben\Application Data

    Présent ! - "C:\Documents and Settings\ben\Application Data\m\flec006.exe"
    Présent ! - "C:\Documents and Settings\ben\Application Data\m\list.oct"
    Présent ! - "C:\Documents and Settings\ben\Application Data\m\data.oct"
    Présent ! - "C:\Documents and Settings\ben\Application Data\m\srvlist.oct"
    Présent ! - "C:\Documents and Settings\ben\Application Data\m\shared"
    Présent ! - "C:\Documents and Settings\ben\Application Data\m"

    »»»» Presence des fichiers dans C:\DOCUME~1\ben\LOCALS~1\Temp

    --------------- [ Registre / Startup ] ----------------

    ! REG.EXE VERSION 3.0

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    AOLSAV REG_SZ C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
    AOLDialer REG_SZ "C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe"
    LManager REG_SZ C:\PROGRA~1\LAUNCH~1\LManager.exe
    ADMTray.exe REG_SZ "C:\Acer\Empowering Technology\admtray.exe"
    SynTPEnh REG_SZ "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
    NvCplDaemon REG_SZ "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
    nwiz REG_SZ "nwiz.exe" /install
    NvMediaCenter REG_SZ "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    RTHDCPL REG_SZ RTHDCPL.EXE
    SkyTel REG_SZ SkyTel.EXE
    AzMixerSel REG_SZ "C:\Program Files\Realtek\InstallShield\AzMixerSel.exe"
    eDataSecurity Loader REG_SZ "C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe"
    HostManager REG_SZ "C:\Program Files\Fichiers communs\AOL\1203807828\ee\AOLSoftware.exe"
    SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    KiweeHook REG_SZ "C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe"
    Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    RealTray REG_SZ C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    BVRPLiveUpdate REG_SZ C:\Program Files\Avanquest update\Engine\Setup.exe -s /PATCH,/SRCUPDATEC:\DOCUME~1\ALLUSE~1\APPLIC~1\SONYER~1\SONYER~1\LIVEUP~1\LISTOF~1.DAT
    NBKeyScan REG_SZ "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    IntelZeroConfig REG_SZ "C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe"
    IntelWireless REG_SZ "C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

    ! REG.EXE VERSION 3.0

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    ares REG_SZ "C:\Program Files\Ares\Ares.exe" -h
    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
    Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
    BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} REG_SZ "C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
    Google Update REG_SZ "C:\Documents and Settings\ben\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

    --------------- [ Registre / Clés infectieuses ] ----------------

    Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\Local AppWizard-Generated Applications\hldrrr
    Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\bisoft
    Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\DateTime4
    Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\FirtR
    Présent ! - HKEY_USERS\S-1-5-21-796845957-1123561945-725345543-1003\Software\MuleAppData
    Présent ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\hldrrr
    Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
    Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
    Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
    Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
    Présent ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
    Présent ! - HKEY_CURRENT_USER\Software\bisoft
    Présent ! - HKEY_CURRENT_USER\Software\DateTime4
    Présent ! - HKEY_CURRENT_USER\Software\FirtR

    --------------- [ Etat / Services ] ----------------

    +- Services : [ Auto=2 Demande=3 Désactivé=4 ]

    /!\ Ndisuio - Type de démarrage = 4

    /!\ Ip6Fw - Type de démarrage = 4

    /!\ SharedAccess - Type de démarrage = 4

    /!\ wuauserv - Type de démarrage = 4

    /!\ wscsvc - Type de démarrage = 4

    --------------- [ Recherche dans supports amovibles] ----------------

    +- Informations :

    C: - Lecteur fixe

    +- presence des fichiers :

    --------------- [ Registre / Moutpoint2 ] ----------------

    -> Recherche négative.

    ------------------- ! Fin du rapport ! --------------------
    0
  4. mactyer
     
    euh ca ne marche pas...
    en fait il me dit d'appuyer sur une touche pour commencer l'elimination et que ca va redemarrer *2 fois.
    donc la j'appuie sur une touche, et puis tu sais ca me fait comme un bug, c'est a dire qu'une page bleue avec des ecritures blanches s'affiche une demi seconde et ca fai redemarrer l'ordi, mais a la normale pas avec findy kill. genre l'ordi a bugé et redemarre quoi? tu vois ce que je veux dire?

    j'ai pu apercevoir sur cette page bleue un message qui dit que le probleme peut etre causé par le fichier srosa.sys
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    Salut,

    ça peux arriver srosa.sys fait partie de l infection , réitère l option 2 stp

    @+
    0
    1. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
       
      Merci t'chiki.
      -1
  7. mactyer
     
    ouai je reessaye d'accord. mais j'ai deja réessayé deux fois et ca a fait pareil snifffffffff... je suis desesperé. allez je reessaye encore une fois et je te dis quoi
    0
  8. mactyer
     
    ca me met que j'ai supprimé un fichier et que findykill ne peut donc plus fonctionner
    0
  9. mactyer
     
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.554 [GMT 2:00]
    Lancé depuis: C:\Documents and Settings\ben\Bureau\killbagle.exe
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run -------
    .
    C:\Documents and Settings\ben\Application Data\m
    C:\Documents and Settings\ben\Application Data\m\data.oct
    C:\Documents and Settings\ben\Application Data\m\flec006.exe
    C:\Documents and Settings\ben\Application Data\m\list.oct
    C:\Documents and Settings\ben\Application Data\m\shared\4U_Video_Converter_2.1.47.zip
    C:\Documents and Settings\ben\Application Data\m\shared\A1Monitor_Network_Monitoring_&_Server_Monitor_7.0.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Advanced Mailbox Processor 3.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Advanced Shell for UPX 2.03.zip
    C:\Documents and Settings\ben\Application Data\m\shared\America Online (Windows 2000) 6.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Anime Smileys 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Anonymous_Friend_2.7.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Anti_Tracks_6.9.23.zip
    C:\Documents and Settings\ben\Application Data\m\shared\AquaButton Control 2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\ArcSoft_PhotoBase_4.5.zip
    C:\Documents and Settings\ben\Application Data\m\shared\AudioSyncer 1.3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Avast.antivirus.mise.a.jour.04-2006special.adeware.zip
    C:\Documents and Settings\ben\Application Data\m\shared\AVI_to_DivX_3.1.5.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Avignon Font 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Baby_Diary_2.5.500_Key+Serial.zip
    C:\Documents and Settings\ben\Application Data\m\shared\BARONIAL_MONOGRAMS_1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\BingoTrack_5.3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Brain_Builder_1.12.zip
    C:\Documents and Settings\ben\Application Data\m\shared\BRUTUS toolbar for IE 4.5.131.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\CAD_Viewer_4.5_[KeyGen].zip
    C:\Documents and Settings\ben\Application Data\m\shared\Cfont_Pro_2.5.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Club_Accounting_3.0.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\ColorCache_4.0.0.1_KeyGen.zip
    C:\Documents and Settings\ben\Application Data\m\shared\CompuCram_Series_7_6_rev_4_(Patch).zip
    C:\Documents and Settings\ben\Application Data\m\shared\Custo 3.0.4.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Database Designer for MySQL 1.9.3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Delete_Add_or_Remove_Programs_List_Entries_Software_7.0_(Serial).zip
    C:\Documents and Settings\ben\Application Data\m\shared\DO SEX toolbar for IE 4.5.132.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Domain Name Tools 1.3.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Drupal.org_RSS_Feed_1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\DéKiBulle_3.24.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Easy Vista Manager 1.8.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Easy_Registry_Optimizer_2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\ebComposer_UBL_1.0.4_(Serial).zip
    C:\Documents and Settings\ben\Application Data\m\shared\eLoft_Database_2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\eMyPasswords Organizer 1.05.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Ewido.Security.Suite.4+serial.zip
    C:\Documents and Settings\ben\Application Data\m\shared\eXPert_PDF_Reader_1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\FastChords_Lite_3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Ferrets Screensaver 1.0.6.2634.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Flash SlideShow Maker 4.75.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Flight_Simulator_2000_Professional_Edition_Update_2.0b.zip
    C:\Documents and Settings\ben\Application Data\m\shared\For Sale By Owner Kit 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Forge_for_SwordSearcher_1.0.2.5.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Freespace XP 1.0.10.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Full Map 2.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Garden Australia Screen Saver 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Google_Ranking_Search_Engine_Optimization_Tool_1.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Grand_Theft_Auto_Vice_City_Multi_Theft_Auto_mod_0.5.zip
    C:\Documents and Settings\ben\Application Data\m\shared\HD-X-Lock_1.40.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Health_Tracker_3.0.0_[Cracked].zip
    C:\Documents and Settings\ben\Application Data\m\shared\Hide Drive 1.5.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\HideDesktop 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\History_of_The_Nations_and_Empires_Involved_and_a_Study_of_the_Events.zip
    C:\Documents and Settings\ben\Application Data\m\shared\iDo_Wedding_Couple_Edition_7.8.zip
    C:\Documents and Settings\ben\Application Data\m\shared\ImageRing_1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Imagery_3D_0.1.4.zip
    C:\Documents and Settings\ben\Application Data\m\shared\InFormEnter 0.5.5.2.zip
    C:\Documents and Settings\ben\Application Data\m\shared\InnerSoft CAD for AutoCAD 2006 1.2b.zip
    C:\Documents and Settings\ben\Application Data\m\shared\iPod VideoConstructor FREE 2.2.0.28.zip
    C:\Documents and Settings\ben\Application Data\m\shared\IPxWorkX 0.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Jingle 4.02.zip
    C:\Documents and Settings\ben\Application Data\m\shared\JoyToKey 3.7.9.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Just_Another_Analog_Clock_1.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\JustFTP 3.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Karnaugh_Minimizer_2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\LoanAmortizer Professional Edition 3.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Love Screensaver 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\LTC_Manager_5.3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Master Hammond B3 VSTi 2.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Math Foundation 3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Meta_Image_Search_2.00_(Crack).zip
    C:\Documents and Settings\ben\Application Data\m\shared\MoveOnBoot_1.95_(Cracked).zip
    C:\Documents and Settings\ben\Application Data\m\shared\MS_Access_Split_Fields_Software_7.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Myjewchat_1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\MyLinkTool 1.10.zip
    C:\Documents and Settings\ben\Application Data\m\shared\NexTag Toolbar 1.0.20.zip
    C:\Documents and Settings\ben\Application Data\m\shared\NxV 0.43.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Orbital's_SQL_Decryptor_2.2.zip
    C:\Documents and Settings\ben\Application Data\m\shared\OsenXPSuite 2006 Enterprise Edition 11.24.0.90.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Oven Fresh HTML Button Maker 2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Ovusoft_Fertility_Software_1.6.zip
    C:\Documents and Settings\ben\Application Data\m\shared\OZEXE_3.10_With_Crack.zip
    C:\Documents and Settings\ben\Application Data\m\shared\PerfX_Prints_1.0.20.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Personal C Sharp 1.51.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Personal_Notepad_2.1.23.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Planet_Photo_Screensaver_1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\PostView_1.3.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Print Tracker 5.7.4.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Proficient_Blackjack_1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\R2V 1.25.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Rainbow_5.07_[Key].zip
    C:\Documents and Settings\ben\Application Data\m\shared\Redsauce Post Master 1.0.0.7.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Repro_2.3_(Patch).zip
    C:\Documents and Settings\ben\Application Data\m\shared\Scripture Challenge 5.11.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Sea_Lion_Family_1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Silver Pilot 1.12.zip
    C:\Documents and Settings\ben\Application Data\m\shared\SimGangster_Free_Edition_1.0.2481.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Sirana SpamCenter 2.0 Patch.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Small Business Break-Even Analyzer 1.6.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Sophos.Antivirus.v5.2.5.Win2kXP2k3.Multilingual.Retail-ARN.zip
    C:\Documents and Settings\ben\Application Data\m\shared\SPac_1.6.0.28_KeyGen.zip
    C:\Documents and Settings\ben\Application Data\m\shared\SpellServer.NET_2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\SQLClean 2.3.76.zip
    C:\Documents and Settings\ben\Application Data\m\shared\SSSP.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Stardust_Impressionist_Paintings_Screen_Saver_3.0.149.zip
    C:\Documents and Settings\ben\Application Data\m\shared\String Checker 1.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Swiftpage for Excel 1.0.8.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Symantec.-.WinFax.Pro.10.04.update.from.10.03.zip
    C:\Documents and Settings\ben\Application Data\m\shared\teardrop_screensaver_01.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Text to Speech Maker 1.5.2.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Think_Ink_Tattoo_Screen_Saver_Collection_2.0_[KeyGen].zip
    C:\Documents and Settings\ben\Application Data\m\shared\Tims Movie Site V 2 1.0.0.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\TNT_Buttons_2.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\TweakNow_PowerPack_2006_Standard_1.6.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\txt2palm 1.6.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Ultimate_Screen_Clock_2.0a_Patch_36_(Patch).zip
    C:\Documents and Settings\ben\Application Data\m\shared\UltimateMenu_1.0_KeyGen.zip
    C:\Documents and Settings\ben\Application Data\m\shared\VPN-X Server 2.2.1.24.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Warcraft_III_-_Fall_of_the_Lion_Episode_IV_map.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Water_Lily_Screensaver_v2_5.07.zip
    C:\Documents and Settings\ben\Application Data\m\shared\WebTester_5.0.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Winsole_2.1_Standalone_2.1.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Word_Frequency_Count_Software_7.0_Key.zip
    C:\Documents and Settings\ben\Application Data\m\shared\Wsnap_1.3.79.zip
    C:\Documents and Settings\ben\Application Data\m\shared\XSS_IP_Monitor_1.8.zip
    C:\Documents and Settings\ben\Application Data\m\shared\yLend_1.0.2.zip
    C:\Documents and Settings\ben\Application Data\m\shared\ZeemMD5 1.1.zip
    C:\Documents and Settings\ben\Application Data\m\srvlist.oct
    C:\Documents and Settings\ben\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
    C:\Documents and Settings\ben\Local Settings\Temporary Internet Files\bestwiner.stt
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
    C:\InfoSat.txt
    C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
    C:\WINDOWS\IE4 Error Log.txt
    C:\WINDOWS\Install.txt
    C:\WINDOWS\system32\ban_list.txt
    C:\WINDOWS\system32\drivers\downld
    C:\WINDOWS\system32\drivers\downld\117359.exe
    C:\WINDOWS\system32\drivers\downld\121546.exe
    C:\WINDOWS\system32\drivers\downld\134812.exe
    C:\WINDOWS\system32\drivers\downld\134828.exe
    C:\WINDOWS\system32\drivers\downld\138578.exe
    C:\WINDOWS\system32\drivers\downld\142531.exe
    C:\WINDOWS\system32\drivers\downld\142703.exe
    C:\WINDOWS\system32\drivers\downld\151406.exe
    C:\WINDOWS\system32\drivers\downld\153843.exe
    C:\WINDOWS\system32\drivers\downld\154046.exe
    C:\WINDOWS\system32\drivers\downld\155468.exe
    C:\WINDOWS\system32\drivers\downld\158359.exe
    C:\WINDOWS\system32\drivers\downld\162781.exe
    C:\WINDOWS\system32\drivers\downld\165859.exe
    C:\WINDOWS\system32\drivers\downld\167578.exe
    C:\WINDOWS\system32\drivers\downld\167890.exe
    C:\WINDOWS\system32\drivers\downld\169781.exe
    C:\WINDOWS\system32\drivers\downld\176765.exe
    C:\WINDOWS\system32\drivers\downld\177671.exe
    C:\WINDOWS\system32\drivers\downld\177687.exe
    C:\WINDOWS\system32\drivers\downld\180062.exe
    C:\WINDOWS\system32\drivers\downld\180156.exe
    C:\WINDOWS\system32\drivers\downld\180171.exe
    C:\WINDOWS\system32\drivers\downld\182187.exe
    C:\WINDOWS\system32\drivers\downld\182640.exe
    C:\WINDOWS\system32\drivers\downld\183046.exe
    C:\WINDOWS\system32\drivers\downld\183078.exe
    C:\WINDOWS\system32\drivers\downld\187562.exe
    C:\WINDOWS\system32\drivers\downld\189968.exe
    C:\WINDOWS\system32\drivers\downld\195218.exe
    C:\WINDOWS\system32\drivers\downld\195703.exe
    C:\WINDOWS\system32\drivers\downld\196046.exe
    C:\WINDOWS\system32\drivers\downld\197421.exe
    C:\WINDOWS\system32\drivers\downld\198984.exe
    C:\WINDOWS\system32\drivers\downld\199406.exe
    C:\WINDOWS\system32\drivers\downld\202750.exe
    C:\WINDOWS\system32\drivers\downld\205265.exe
    C:\WINDOWS\system32\drivers\downld\206265.exe
    C:\WINDOWS\system32\drivers\downld\206406.exe
    C:\WINDOWS\system32\drivers\downld\208250.exe
    C:\WINDOWS\system32\drivers\downld\209593.exe
    C:\WINDOWS\system32\drivers\downld\212187.exe
    C:\WINDOWS\system32\drivers\downld\212625.exe
    C:\WINDOWS\system32\drivers\downld\214109.exe
    C:\WINDOWS\system32\drivers\downld\217015.exe
    C:\WINDOWS\system32\drivers\downld\223328.exe
    C:\WINDOWS\system32\drivers\downld\224468.exe
    C:\WINDOWS\system32\drivers\downld\227843.exe
    C:\WINDOWS\system32\drivers\downld\229906.exe
    C:\WINDOWS\system32\drivers\downld\232609.exe
    C:\WINDOWS\system32\drivers\downld\235437.exe
    C:\WINDOWS\system32\drivers\downld\241781.exe
    C:\WINDOWS\system32\drivers\downld\243984.exe
    C:\WINDOWS\system32\drivers\downld\246031.exe
    C:\WINDOWS\system32\drivers\downld\247109.exe
    C:\WINDOWS\system32\drivers\downld\248328.exe
    C:\WINDOWS\system32\drivers\downld\248781.exe
    C:\WINDOWS\system32\drivers\downld\249468.exe
    C:\WINDOWS\system32\drivers\downld\253171.exe
    C:\WINDOWS\system32\drivers\downld\256515.exe
    C:\WINDOWS\system32\drivers\downld\257859.exe
    C:\WINDOWS\system32\drivers\downld\262078.exe
    C:\WINDOWS\system32\drivers\downld\267078.exe
    C:\WINDOWS\system32\drivers\downld\267656.exe
    C:\WINDOWS\system32\drivers\downld\270015.exe
    C:\WINDOWS\system32\drivers\downld\270359.exe
    C:\WINDOWS\system32\drivers\downld\272484.exe
    C:\WINDOWS\system32\drivers\downld\277312.exe
    C:\WINDOWS\system32\drivers\downld\288921.exe
    C:\WINDOWS\system32\drivers\downld\291968.exe
    C:\WINDOWS\system32\drivers\downld\297406.exe
    C:\WINDOWS\system32\drivers\downld\298343.exe
    C:\WINDOWS\system32\drivers\downld\300734.exe
    C:\WINDOWS\system32\drivers\downld\301281.exe
    C:\WINDOWS\system32\drivers\downld\306734.exe
    C:\WINDOWS\system32\drivers\downld\309531.exe
    C:\WINDOWS\system32\drivers\downld\312968.exe
    C:\WINDOWS\system32\drivers\downld\314140.exe
    C:\WINDOWS\system32\drivers\downld\316875.exe
    C:\WINDOWS\system32\drivers\downld\320718.exe
    C:\WINDOWS\system32\drivers\downld\321312.exe
    C:\WINDOWS\system32\drivers\downld\323500.exe
    C:\WINDOWS\system32\drivers\downld\331171.exe
    C:\WINDOWS\system32\drivers\downld\331453.exe
    C:\WINDOWS\system32\drivers\downld\339750.exe
    C:\WINDOWS\system32\drivers\downld\345000.exe
    C:\WINDOWS\system32\drivers\downld\346703.exe
    C:\WINDOWS\system32\drivers\downld\347140.exe
    C:\WINDOWS\system32\drivers\downld\359093.exe
    C:\WINDOWS\system32\drivers\downld\361671.exe
    C:\WINDOWS\system32\drivers\downld\368765.exe
    C:\WINDOWS\system32\drivers\downld\375500.exe
    C:\WINDOWS\system32\drivers\downld\397140.exe
    C:\WINDOWS\system32\drivers\downld\398578.exe
    C:\WINDOWS\system32\drivers\downld\41280937.exe
    C:\WINDOWS\system32\drivers\downld\41281828.exe
    C:\WINDOWS\system32\drivers\downld\41313656.exe
    C:\WINDOWS\system32\drivers\downld\41316218.exe
    C:\WINDOWS\system32\drivers\downld\41332484.exe
    C:\WINDOWS\system32\drivers\downld\41341328.exe
    C:\WINDOWS\system32\drivers\downld\41346218.exe
    C:\WINDOWS\system32\drivers\downld\41353937.exe
    C:\WINDOWS\system32\drivers\downld\41358890.exe
    C:\WINDOWS\system32\drivers\downld\41366515.exe
    C:\WINDOWS\system32\drivers\downld\41394671.exe
    C:\WINDOWS\system32\drivers\downld\41396593.exe
    C:\WINDOWS\system32\drivers\downld\41415343.exe
    C:\WINDOWS\system32\drivers\downld\41421765.exe
    C:\WINDOWS\system32\drivers\downld\41431671.exe
    C:\WINDOWS\system32\drivers\downld\41443171.exe
    C:\WINDOWS\system32\drivers\downld\41447671.exe
    C:\WINDOWS\system32\drivers\downld\41452156.exe
    C:\WINDOWS\system32\drivers\downld\41467750.exe
    C:\WINDOWS\system32\drivers\downld\41491265.exe
    C:\WINDOWS\system32\drivers\downld\41568093.exe
    C:\WINDOWS\system32\drivers\downld\41592468.exe
    C:\WINDOWS\system32\drivers\downld\416703.exe
    C:\WINDOWS\system32\drivers\downld\425859.exe
    C:\WINDOWS\system32\drivers\downld\451906.exe
    C:\WINDOWS\system32\drivers\downld\480312.exe
    C:\WINDOWS\system32\drivers\downld\515109.exe
    C:\WINDOWS\system32\drivers\downld\539156.exe
    C:\WINDOWS\system32\drivers\downld\550765.exe
    C:\WINDOWS\system32\drivers\downld\580500.exe
    C:\WINDOWS\system32\drivers\downld\593656.exe
    C:\WINDOWS\system32\drivers\downld\622453.exe
    C:\WINDOWS\system32\drivers\downld\632718.exe
    C:\WINDOWS\system32\drivers\hldrrr.exe
    C:\WINDOWS\system32\drivers\srosa.sys
    C:\WINDOWS\system32\Install.txt
    C:\WINDOWS\system32\mdelk.exe
    C:\WINDOWS\system32\tmp0_349841824778.bk
    C:\WINDOWS\system32\tmp0_371238598482.bk
    C:\WINDOWS\system32\tmp0_662801634402.bk
    C:\WINDOWS\system32\tmp1_810319751072.bk
    C:\WINDOWS\system32\tmp5_64452449317.bk
    C:\WINDOWS\system32\tpszxyd.sys
    C:\WINDOWS\system32\wintems.exe
    0
  10. mactyer
     
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_AFINDING
    -------\Legacy_AFISICX
    -------\Legacy_MABIDWE
    -------\Legacy_MACIDWE
    -------\Legacy_MSBRND
    -------\Legacy_NOBICYT
    -------\Legacy_NOXTCYR
    -------\Legacy_NOYTCYR
    -------\Legacy_PERFMONS
    -------\Legacy_PERFS
    -------\Legacy_ROUTING
    -------\Legacy_ROXTCTM
    -------\Legacy_ROYTCTM
    -------\Legacy_SOBICYT
    -------\Legacy_SOTPECA
    -------\Legacy_SOXPECA
    -------\Legacy_TDXDOWKC
    -------\Legacy_TDYDOWKC
    -------\Legacy_WSERVING
    -------\Legacy_WSLDOEKD
    -------\Service_msbrnd

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-18 au 2008-10-18 ))))))))))))))))))))))))))))))))))))
    .

    2008-10-19 01:20 . 2008-10-19 01:20 <REP> d-------- C:\WINDOWS\LastGood
    2008-10-19 00:29 . 2008-10-19 00:30 <REP> d-------- C:\Program Files\FindyKill
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\NetworkService\Application Data\Intel
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT\Application Data\Intel
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.003\Application Data\Intel
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.002\Application Data\Intel
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.001\Application Data\Intel
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\LocalService.AUTORITE NT.000\Application Data\Intel
    2008-10-19 00:26 . 2008-10-19 00:26 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intel
    2008-10-19 00:25 . 2008-08-28 23:34 3,632,384 --a------ C:\WINDOWS\system32\drivers\NETw5x32.sys
    2008-10-19 00:25 . 2008-06-20 10:33 2,756,608 --a------ C:\WINDOWS\system32\NETw5r32.dll
    2008-10-19 00:25 . 2008-06-20 10:32 663,552 --a------ C:\WINDOWS\system32\NETw5c32.dll
    2008-10-19 00:22 . 2008-10-19 00:22 <REP> d-------- C:\Program Files\Fichiers communs\Intel
    2008-10-19 00:08 . 2008-10-19 00:08 <REP> d-------- C:\Program Files\Trend Micro
    2008-10-18 23:37 . 2008-10-18 23:37 <REP> d-------- C:\Program Files\ma-config.com
    2008-10-18 23:37 . 2008-10-18 23:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
    2008-10-18 01:49 . 2008-10-18 01:50 <REP> d-------- C:\Program Files\splus
    2008-10-18 01:49 . 2005-10-17 18:13 447,488 --a------ C:\WINDOWS\system32\splus.cpl
    2008-10-17 23:28 . 2008-10-17 23:28 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-17 23:28 . 2008-10-17 23:28 <REP> d-------- C:\Documents and Settings\ben\Application Data\Malwarebytes
    2008-10-17 23:28 . 2008-10-17 23:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-17 23:28 . 2008-10-16 20:25 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-10-17 23:28 . 2008-10-16 20:25 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-10-17 23:22 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
    2008-10-17 23:20 . 2008-10-18 02:01 <REP> d-------- C:\Program Files\Panda Security
    2008-10-17 23:00 . 2008-10-17 23:00 <REP> d-------- C:\Program Files\Alwil Software
    2008-10-17 02:44 . 2008-10-17 02:47 <REP> d-------- C:\Program Files\DrWeb
    2008-10-17 01:15 . 2008-10-17 01:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
    2008-10-17 00:41 . 2008-10-17 00:47 46 --ah----- C:\WINDOWS\system32\InternetAccelerator_sysquict.dat
    2008-10-17 00:40 . 2008-10-17 00:51 <REP> d-------- C:\Program Files\Okoker Internet Accelerator
    2008-10-16 00:53 . 2008-10-16 00:53 <REP> d-------- C:\Program Files\Lavasoft
    2008-10-16 00:53 . 2008-10-16 00:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-10-15 23:03 . 2008-10-16 12:06 <REP> d-------- C:\Program Files\ESET
    2008-10-15 13:16 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
    2008-10-15 13:16 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
    2008-10-15 13:16 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
    2008-10-15 13:16 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
    2008-10-15 13:16 . 2008-06-23 23:34 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
    2008-10-15 13:16 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
    2008-10-15 13:16 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
    2008-10-15 13:16 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
    2008-10-15 13:16 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
    2008-10-09 07:09 . 2008-10-09 07:09 244 --ah----- C:\sqmnoopt18.sqm
    2008-10-09 07:09 . 2008-10-09 07:09 232 --ah----- C:\sqmdata18.sqm
    2008-09-29 14:25 . 2008-09-29 14:25 <REP> d--hs---- C:\found.000
    2008-09-23 17:54 . 2008-09-23 17:54 244 --ah----- C:\sqmnoopt17.sqm
    2008-09-23 17:54 . 2008-09-23 17:54 232 --ah----- C:\sqmdata17.sqm
    2008-09-23 14:20 . 2008-09-23 14:20 268 --ah----- C:\sqmdata16.sqm
    2008-09-23 14:20 . 2008-09-23 14:20 244 --ah----- C:\sqmnoopt16.sqm
    2008-09-22 20:49 . 2008-09-22 20:49 268 --ah----- C:\sqmdata15.sqm
    2008-09-22 20:49 . 2008-09-22 20:49 244 --ah----- C:\sqmnoopt15.sqm
    2008-09-22 20:48 . 2008-09-22 20:48 268 --ah----- C:\sqmdata14.sqm
    2008-09-22 20:48 . 2008-09-22 20:48 244 --ah----- C:\sqmnoopt14.sqm

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-18 22:22 --------- d-----w C:\Program Files\Intel
    2008-10-18 21:38 --------- d-----w C:\Program Files\eMule
    2008-10-17 23:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-10-17 22:50 --------- d-----w C:\Program Files\PE
    2008-10-17 22:50 --------- d-----w C:\Program Files\nsj4C1
    2008-10-17 00:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-10-15 22:16 --------- d-----w C:\Program Files\epson
    2008-10-15 21:26 4,906 ----a-w C:\WINDOWS\system32\tmp.reg
    2008-10-01 13:47 --------- d-----w C:\Documents and Settings\ben\Application Data\dvdcss
    2008-09-20 21:35 --------- d-----w C:\Program Files\Everest Poker
    2008-08-27 22:18 --------- d-----w C:\Program Files\Alcohol Soft
    2008-08-20 14:15 208,896 ----a-w C:\WINDOWS\system32\NetProvCredMan.dll
    2008-08-03 12:49 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
    2008-08-03 11:41 53,248 ----a-w C:\WINDOWS\system32\comrepl.exe
    2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
    2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
    2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
    2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
    2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
    2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
    2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
    2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
    2008-02-21 01:27 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
    2007-02-09 17:34 420,816 ----a-w C:\Documents and Settings\ben\Application Data\wunauclt.exe
    .

    ((((((((((((((((((((((((((((( snapshot_2008-10-19_ 1.19.12.15 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-10-18 22:27:16 64,706 ----a-w C:\WINDOWS\system32\perfc009.dat
    + 2008-10-18 23:20:46 64,706 ----a-w C:\WINDOWS\system32\perfc009.dat
    - 2008-10-18 22:27:17 78,354 ----a-w C:\WINDOWS\system32\perfc00C.dat
    + 2008-10-18 23:20:46 78,354 ----a-w C:\WINDOWS\system32\perfc00C.dat
    - 2008-10-18 22:27:16 409,566 ----a-w C:\WINDOWS\system32\perfh009.dat
    + 2008-10-18 23:20:46 409,566 ----a-w C:\WINDOWS\system32\perfh009.dat
    - 2008-10-18 22:27:17 477,728 ----a-w C:\WINDOWS\system32\perfh00C.dat
    + 2008-10-18 23:20:46 477,728 ----a-w C:\WINDOWS\system32\perfh00C.dat
    .
    -- Instantané actualisé --
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]

    [HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
    [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
    [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
    2008-04-03 10:52 265360 --a------ C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar2\1.5.131\KiweeIEToolbar.dll" [2008-04-03 265360]

    [HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
    [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
    [HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
    [HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
    "ares"="C:\Program Files\Ares\Ares.exe" [BU]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
    "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [BU]
    "Google Update"="C:\Documents and Settings\ben\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-12 133104]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AOLSAV"="C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe" [BU]
    "AOLDialer"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe" [2007-06-21 70952]
    "LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2006-07-20 593920]
    "ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 761946]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-12 7577600]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-06-12 86016]
    "AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-08-16 53248]
    "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 69632]
    "HostManager"="C:\Program Files\Fichiers communs\AOL\1203807828\ee\AOLSoftware.exe" [2006-09-26 50736]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
    "KiweeHook"="C:\Program Files\Kiwee Toolbar2\1.5.131\kwtbaim.exe" [2008-04-03 56456]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2008-03-16 26112]
    "BVRPLiveUpdate"="C:\Program Files\Avanquest update\Engine\Setup.exe" [BU]
    "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU]
    "IntelZeroConfig"="C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-08-20 1368064]
    "IntelWireless"="C:\Program Files\Fichiers communs\Intel\WirelessCommon\iFrmewrk.exe" [2008-08-20 1191936]
    "nwiz"="nwiz.exe" [2006-06-12 C:\WINDOWS\system32\nwiz.exe]
    "RTHDCPL"="RTHDCPL.EXE" [2006-08-16 C:\WINDOWS\RTHDCPL.exe]
    "SkyTel"="SkyTel.EXE" [2006-08-16 C:\WINDOWS\SkyTel.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "nlsf"="move" [X]
    "Config"="C:\WINDOWS\system32\run.cmd" [2006-02-14 248]
    "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 44544]

    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    AOL 9.0 Ic“ne AOL.lnk - C:\Program Files\AOL 9.0b\aoltray.exe [2008-03-16 156784]
    AOL Compagnon.lnk - C:\Program Files\AOL Compagnon\companion.exe [2008-02-21 255088]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSMHelp"= 1 (0x1)
    "MemCheckBoxInRunDlg"= 1 (0x1)
    "NoSMBalloonTip"= 1 (0x1)
    "NoDesktopCleanupWizard"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)
    "NoAutoUpdate"= 1 (0x1)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "NoSMHelp"= 1 (0x1)
    "MemCheckBoxInRunDlg"= 1 (0x1)
    "NoSMBalloonTip"= 1 (0x1)
    "NoDesktopCleanupWizard"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)
    "NoAutoUpdate"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
    "C:\\Program Files\\AOL 9.0\\waol.exe"=
    "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "C:\\Program Files\\Fichiers communs\\AOL\\1203807828\\ee\\aolsoftware.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\AOL 9.0a\\waol.exe"=
    "C:\\Program Files\\AOL 9.0b\\waol.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=

    R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
    R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 12106]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
    R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2006-01-23 4096]
    R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2006-01-23 78208]
    R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 7296]
    R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 4010]
    R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 4392]
    R3 NETw5x32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;C:\WINDOWS\system32\DRIVERS\NETw5x32.sys [2008-08-28 3632384]
    S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-09-02 191656]
    .
    Contenu du dossier 'Tâches planifiées'

    2008-09-22 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]

    2008-10-18 C:\WINDOWS\Tasks\GoogleUpdateTaskUser.job
    - C:\Documents and Settings\ben\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-12 00:31]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    Toolbar-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)

    .
    ------- Examen supplémentaire -------
    .
    FireFox -: Profile - C:\Documents and Settings\ben\Application Data\Mozilla\Firefox\Profiles\h96vxtmc.default\
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-10-19 01:27:41
    Windows 5.1.2600 Service Pack 2 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    Heure de fin: 2008-10-19 1:30:48
    ComboFix-quarantined-files.txt 2008-10-18 23:30:45
    ComboFix2.txt 2008-08-05 22:20:39

    Avant-CF: 24,956,530,688 octets libres
    Après-CF: 24,629,547,008 octets libres

    544 --- E O F --- 2008-09-10 15:44:46
    0
  11. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    T'en es où avec ton problème ?
    0
  12. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    Salut,
    - Télécharge HijackThis Version 2.02 :
    http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

    - Enregistre HJTInstall.exe sur ton bureau.
    - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
    - Clique sur Install ensuite sur I Accept
    - Clique sur Do a scan system and save log file
    - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    Petit tuto si besoin : http://pageperso.aol.fr/balltrap34/demohijack.htm
    -1
  13. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    ok.
    Télécharge FindyKill (Merci à Chiquitine29 !!)

    Fais un clic droit sur le lien, enregister sous .....sur le bureau
    => http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

    Dézippe le sur le bureau

    Entre dans le dossier FindyKill
    Double clique sur FindyKill.exe
    Choisis l'option 1 (recherche)
    Un rapport va s'ouvrir, poste le dans ta prochaine réponse stp

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque (C:\FindyKill.txt)
    -1
  14. crapoulou Messages postés 28002 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   8 046
     
    Parfait.

    Nettoyage :

    --> Double clic sur le raccourci FindyKill sur ton bureau

    --> Au menu principal, choisis l’option 2 (Suppression)

    /!\ il y aura 2 redémarrages, laisse travailler l’outil jusqu’à l’apparition du message "nettoyage effectué"

    /!\ Ne te sers pas du pc durant la suppression, ton bureau ne sera pas accessible c’est normal !

    -------> ensuite poste le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
    Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tapes explorer.exe et valides
    -1
  15. Utilisateur anonyme
     
    tente ceci stp

    va dans menu demarre / programmefile

    entre dans le dossier findykill puis fixreg et supprime fixsrosa.reg

    ensuite refais l option 2
    -1
  16. Utilisateur anonyme
     
    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Avant de telecharger clic sur enregistrer renome le en killbagle et enregistre le sur le bureau

    -> Double clique sur killbagle.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    Une fois fait, sur ton bureau double-clic sur killbagle.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
    -1