Winupgro.exe

Fermé
dab - 18 déc. 2008 à 09:48
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 - 19 déc. 2008 à 04:10
Bonjour,

bonjour, j'ai comme un virus qui traine on dirait ....

donc winupgro.exe tourne dans mes processus et mon antivirus (Kaspersky) n'estplus ouvert et ne peut plus s'ouvrir.
après qql recherche je suis tombé ici, j'ai déjà lancé FindyKill dont le rapport est ci-dessous

dois-je lancer la suppression findyKill ?
et que dois-je faire après ?

merci pour votre aide.



----------------- FindyKill V4.709 ------------------

* User : Damien - DAMIEN-PC
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 10/12/08 par Chiquitine29
* Recherche effectuée à 19:55:21 le 17/12/2008
* Windows XP - Internet Explorer 7.0.5730.11

((((((((((((((((( *** Recherche *** ))))))))))))))))))


--------------- [ Processus actifs ] ----------------


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\vs.a01012\PlaxoHelper_fr.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\RescueTime\RescueTime.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Documents and Settings\Damien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Damien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Damien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Damien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Documents and Settings\Damien\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

--------------- [ Fichiers/Dossiers infectieux ] ----------------


»»»» Presence des fichiers dans C:


»»»» Presence des fichiers dans C:\WINDOWS


»»»» Presence des fichiers dans C:\WINDOWS\Prefetch

Found ! - C:\WINDOWS\prefetch\169937.EXE-24670DCF.pf
Found ! - C:\WINDOWS\prefetch\325265.EXE-296603CE.pf
Found ! - C:\WINDOWS\prefetch\376703.EXE-15F7B4DE.pf
Found ! - C:\WINDOWS\prefetch\506781.EXE-3206D720.pf
Found ! - C:\WINDOWS\prefetch\565562.EXE-1B00EB41.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-000DD5A6.pf
Found ! - C:\WINDOWS\prefetch\MDELK.EXE-1D176F91.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
Found ! - C:\WINDOWS\Prefetch\INSTALL_CRACK.EXE-2C46E1E5.pf
Found ! - C:\WINDOWS\Prefetch\INSTALL_CRACK.EXE-2C46E1E5.pf

»»»» Presence des fichiers dans C:\WINDOWS\system32

Found ! [17/12/2008 19:43] - C:\WINDOWS\system32\mdelk.exe
Found ! [17/12/2008 19:43] - C:\WINDOWS\system32\wintems.exe
Found ! [17/12/2008 19:44] - C:\WINDOWS\system32\ban_list.txt

»»»» Presence des fichiers dans C:\WINDOWS\system32\config\systemprofile\AppData\Roaming


»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers


»»»» Presence des fichiers dans C:\Documents and Settings\Damien\Application Data

Found ! [17/12/2008 18:11] - "C:\Documents and Settings\Damien\Application Data\m\flec006.exe"
Found ! [17/12/2008 18:11] - "C:\Documents and Settings\Damien\Application Data\m\list.oct"
Found ! [17/12/2008 18:11] - "C:\Documents and Settings\Damien\Application Data\m\data.oct"
Found ! [17/12/2008 18:11] - "C:\Documents and Settings\Damien\Application Data\m\srvlist.oct"
Found ! [17/12/2008 19:44] - "C:\Documents and Settings\Damien\Application Data\m\shared"
Found ! [17/12/2008 18:11] - "C:\Documents and Settings\Damien\Application Data\m"
Found ! [17/12/2008 18:07] - "C:\Documents and Settings\Damien\Application Data\drivers"
Found ! [17/12/2008 19:43] - "C:\Documents and Settings\Damien\Application Data\drivers\srosa.sys"
Found ! [17/12/2008 19:43] - "C:\Documents and Settings\Damien\Application Data\drivers\srosa2.sys"
Found ! [06/07/2004 01:01] - "C:\Documents and Settings\Damien\Application Data\drivers\winupgro.exe"
Found ! [17/12/2008 19:43] - "C:\Documents and Settings\Damien\Application Data\drivers\downld"
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\157437.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\162984.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\169937.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\179250.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\181109.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\182000.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\190484.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\192421.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\192859.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\297937.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\321328.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\325265.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\335953.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\337359.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\337781.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\346296.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\355031.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\355468.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\376703.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\400843.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\402265.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\402593.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\420468.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\432140.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\432156.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\448796.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\450109.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\450546.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\451453.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\452218.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\452718.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\470968.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\506781.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\524703.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\526843.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\527328.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\591296.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\592812.exe
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Application Data\drivers\downld\593125.exe

»»»» Presence des fichiers dans C:\DOCUME~1\Damien\LOCALS~1\Temp

Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\CAPS
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\config.xml
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\InstallerResults.dll
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\manifest.xml
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\RollbackManifest.xml
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\RTPatch
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\StagingArea
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\ZippedStagingArea
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\CAPS\adobe_caps.dll
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalizedStrings.zip
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ar_AE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\bg_BG
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\cs_CZ
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\da_DK
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\de_DE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\el_GR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\en_US
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\es_ES
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\et_EE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\fi_FI
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\fr_FR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\he_IL
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\hr_HR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\hu_HU
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\it_IT
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ja_JP
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ko_KR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\lt_LT
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\lv_LV
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\nb_NO
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\nl_NL
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\pl_PL
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\pt_BR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ro_RO
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ru_RU
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\sk_SK
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\sl_SI
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\sv_SE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\tr_TR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\uk_UA
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\zh_CN
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\zh_TW
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ar_AE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\bg_BG\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\cs_CZ\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\da_DK\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\de_DE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\el_GR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\en_US\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\es_ES\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\et_EE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\fi_FI\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\fr_FR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\he_IL\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\hr_HR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\hu_HU\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\it_IT\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ja_JP\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ko_KR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\lt_LT\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\lv_LV\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\nb_NO\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\nl_NL\PBS.ZDCT
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\pl_PL\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\pt_BR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ro_RO\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\ru_RU\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\sk_SK\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\sl_SI\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\sv_SE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\tr_TR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\uk_UA\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\zh_CN\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\PBSLocalizedStrings\PBSLocalization\zh_TW\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\RTPatch\patch.exe
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\RTPatch\patchw32.dll
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\StagingArea\1001
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\StagingArea\1001.8bi
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\StagingArea\1003
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher248\ZippedStagingArea\PatchFiles.zip
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\CAPS
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\config.xml
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\InstallerResults.dll
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\CAPS\adobe_caps.dll
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalizedStrings.zip
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ar_AE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\bg_BG
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\cs_CZ
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\da_DK
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\de_DE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\el_GR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\en_US
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\es_ES
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\et_EE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\fi_FI
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\fr_FR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\he_IL
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\hr_HR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\hu_HU
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\it_IT
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ja_JP
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ko_KR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\lt_LT
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\lv_LV
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\nb_NO
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\nl_NL
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\pl_PL
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\pt_BR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ro_RO
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ru_RU
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\sk_SK
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\sl_SI
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\sv_SE
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\tr_TR
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\uk_UA
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\zh_CN
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\zh_TW
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ar_AE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\bg_BG\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\cs_CZ\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\da_DK\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\de_DE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\el_GR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\en_US\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\es_ES\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\et_EE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\fi_FI\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\fr_FR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\he_IL\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\hr_HR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\hu_HU\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\it_IT\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ja_JP\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ko_KR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\lt_LT\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\lv_LV\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\nb_NO\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\nl_NL\PBS.ZDCT
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\pl_PL\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\pt_BR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ro_RO\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\ru_RU\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\sk_SK\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\sl_SI\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\sv_SE\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\tr_TR\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\uk_UA\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\zh_CN\PBS.zdct
Found ! - C:\DOCUME~1\Damien\LOCALS~1\Temp\Patcher\Patcher5888\PBSLocalizedStrings\PBSLocalization\zh_TW\PBS.zdct

»»»» Presence des fichiers dans C:\Documents and Settings\Damien\Local Settings\Temporary Internet Files\Content.IE5

Found ! [24/10/2008 09:39] - C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Local Cache\D3987B641C134048B815DB578D607F42_more.jpg
Found ! [17/12/2008 18:11] - C:\Documents and Settings\Damien\Local Settings\Temporary Internet Files\Content.IE5\2E2QGAT7\b64[1].jpg
Found ! [17/12/2008 18:10] - C:\Documents and Settings\Damien\Local Settings\Temporary Internet Files\Content.IE5\2E2QGAT7\b64_3[1].jpg
Found ! [17/12/2008 18:14] - C:\Documents and Settings\Damien\Local Settings\Temporary Internet Files\Content.IE5\KZNZASAA\b64_2[1].jpg
Found ! [17/12/2008 18:13] - C:\Documents and Settings\Damien\Local Settings\Temporary Internet Files\Content.IE5\OQ38IG0L\b64_1[1].jpg
Found ! [17/12/2008 19:43] - C:\Documents and Settings\Damien\Local Settings\Temporary Internet Files\Content.IE5\T5EH5ELI\b64_3[1].jpg

--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
PlaxoUpdate=C:\Program Files\Plaxo\vs.a01012\PlaxoHelper_fr.exe -a
LogitechSoftwareUpdate="C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
eyeBeam SIP Client=
SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PlaxoSysTray=C:\Program Files\Plaxo\vs.a01012\PlaxoSysTray.exe
Google Update="C:\Documents and Settings\Damien\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
Picasa Media Detector=C:\Program Files\Picasa2\PicasaMediaDetector.exe
googletalk="C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=
<NO NAME>=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz=nwiz.exe /install
GrooveMonitor="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
Acrobat Assistant 8.0="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
Adobe_ID0EYTHM=C:\PROGRA~1\FICHIE~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
AVP="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
LVCOMSX=C:\WINDOWS\system32\LVCOMSX.EXE
LogitechVideoRepair=C:\Program Files\Logitech\Video\ISStart.exe
LogitechVideoTray=C:\Program Files\Logitech\Video\LogiTray.exe
QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
AppleSyncNotifier=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"

[HKEY_CURRENT_USER\software\local appwizard-generated applications\HViewer]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\install_crack]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\MsnMsgr]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]

--------------- [ Registre / Clés infectieuses ] ----------------


Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\Local AppWizard-Generated Applications\install_crack
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\Local AppWizard-Generated Applications\MsnMsgr
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-1645522239-1965331169-725345543-1003\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\install_crack
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\MsnMsgr
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s

--------------- [ Etat / Services ] ----------------

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

- sans echec non fonctionnel !!



+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

/!\ Ndisuio - Type de démarrage = 4

EapHost - Type de démarrage = 3

/!\ Ip6Fw - Type de démarrage = 4

/!\ SharedAccess - Type de démarrage = 4

/!\ wuauserv - Type de démarrage = 4

/!\ wscsvc - Type de démarrage = 4



--------------- [ Recherche dans supports amovibles] ----------------


+- Informations :

C: - Lecteur fixe

D: - Lecteur fixe


+- presence des fichiers :



--------------- [ Registre / Mountpoint2 ] ----------------


-> Not found !


------------------- ! Fin du rapport ! --------------------

7 réponses

g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
18 déc. 2008 à 09:56
salut,

passe l´option 2 de findykill et post le rapport

@+
0
g.chinal Messages postés 1151 Date d'inscription lundi 11 février 2008 Statut Membre Dernière intervention 2 octobre 2014 76
18 déc. 2008 à 10:12
0
daboon Messages postés 6 Date d'inscription jeudi 18 décembre 2008 Statut Membre Dernière intervention 18 décembre 2008
18 déc. 2008 à 11:14
2 fois que je lance la suppression de FindyKill sans qu'il ne me sorte de rapport ?!?
il est bien censé être derrière C:\ ?!

sinon winupgro.exe tourne toujours dans mes process ...

des idées ?
0
daboon Messages postés 6 Date d'inscription jeudi 18 décembre 2008 Statut Membre Dernière intervention 18 décembre 2008
18 déc. 2008 à 11:27
N'y a-t-il que FindyKill pour supprimer ce winupgro.exe et tous les tracas qu'il occasionne ?
merci!
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
daboon Messages postés 6 Date d'inscription jeudi 18 décembre 2008 Statut Membre Dernière intervention 18 décembre 2008
18 déc. 2008 à 11:44
une troisième fois...

en fait, au redémarrage, il me met un message d'erreur :
"windows ne trouve pas C:\Program. vérifiez que vous avez entré le nom correctement"

par la suite je trouve un fichier sur le bureau : $Filetokill dans lequel sont affichées juste deux lignes

C:\Documents and Settings\Damien\Application Data\drivers\winupgro.exe
C:\Documents and Settings\Damien\Application Data\drivers\winupgro.exe



... et winupgro.exe tourne toujours ...

n'importe quelle idée est la bienvenue, merci!
0
daboon Messages postés 6 Date d'inscription jeudi 18 décembre 2008 Statut Membre Dernière intervention 18 décembre 2008
18 déc. 2008 à 19:56
bon, en fait combofix m'a sauvé!
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
19 déc. 2008 à 04:10
salut daboon,

desolé j´ai du m´absenter...

peux tu poster le rapport de combofix stp

@+
0