Bonjour et merci d'avance...
Mon pc est infecté par un win 32 SillyFDC depuis plusieurs jours cela a rendu mon norton inactif, de ce fait je l'ai désinstallé pour mieux le réinstallé et pas de chance il ne s'installe plus et aucun autre anti virus gratuit ne fonctionne: comme quoi ce n'est pas une application win32 valide...
j'ai fait scanner mon pc en ligne et c'est là que je me suis rendu cpte que j'avais deux virus: le w32 + hacktool rootkit
Je ne sais pas quoi faire, (symantec ne peut rien pour moi alors que je paye un abonnement
) si quelqu'un peut m'aider car là, je suis perdue...^^
A très bientôt je l'espère
Je viens de télécharger HijackThis et, apparament, ce n'est pas non plus une application Win32 valide...Ca va être difficile de m'aider je pense...
Message édité par alpha0 le 26-05-2008 à 18:51:14
bonsoir et
~Télécharge Elibagla sur cette page :
http://www.zonavirus.com/datos/des [...] ibagla.asp
Tu trouveras le programme à télécharger tout en bas de la page :,
clique sur escargar Elibagla11.33
Enregistre ce fichier sur le bureau
Va sur ton bureau et double-clic sur Elibagla.exe
La case "eliminar ficheros automaticamente" doit être cochée
Clique sur"explorar" et laisse-le travailler
~Poste le rapport final qui sera dans c:\infosat.txt
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Tout d'abord merci beaucoup pour votre aide voici le rapport:
Thu May 08 19:39:20 2008
EliBagle v11.33 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado.
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.
Thu May 08 19:40:32 2008
EliBagle v11.33 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\Program Files\Google\GoogleToolbarNotifier\GOOGLETOOLBARNOTIFIER.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP432\A0144411.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP432\A0144417.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP432\A0144424.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP432\A0144428.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP432\A0144429.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP432\A0144441.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144558.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144562.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144563.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144570.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144575.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144576.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0144625.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145232.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145235.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145237.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145243.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145244.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145247.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145248.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145249.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145641.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145841.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145842.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145843.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145844.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145858.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145859.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145908.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145909.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145910.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145921.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145923.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145931.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145932.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP433\A0145933.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146133.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146134.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146146.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146147.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146148.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146156.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146157.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146158.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146160.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146161.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146167.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146168.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146170.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146171.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146172.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146218.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146219.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146221.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146222.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146223.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146230.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146231.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0146233.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0147021.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0147022.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP434\A0147024.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147089.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147090.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147091.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147136.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147141.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147142.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147149.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147151.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147152.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147155.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147199.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147210.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147215.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147224.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147369.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147374.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147379.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147388.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147392.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147433.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147438.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147488.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147493.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147497.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147506.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147510.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147561.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147565.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147573.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147577.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147586.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147599.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147611.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147627.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147632.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147637.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147646.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147651.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147676.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147677.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP435\A0147678.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147684.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147685.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147686.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147749.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147754.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147755.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147762.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147764.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147765.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147768.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147812.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147823.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147828.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147837.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147982.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147987.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0147992.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148001.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148005.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148046.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148051.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148101.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148106.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148110.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148119.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148123.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148174.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148178.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148186.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148190.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148199.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148212.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148224.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148240.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148245.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148250.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148259.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP436\A0148264.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148293.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148294.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148295.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148358.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148363.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148364.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148371.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148373.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148374.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148377.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148421.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148432.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148437.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148446.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148591.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148596.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148601.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148610.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148614.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148655.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148660.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148710.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148715.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148719.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148728.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148732.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148783.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148787.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148795.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148799.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148808.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148821.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148833.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148849.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148854.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148859.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148868.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148873.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148898.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148899.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148900.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148902.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148903.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148922.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148923.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148925.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148947.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0148948.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0149063.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0149071.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP437\A0149072.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP438\A0149083.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP438\A0149084.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP438\A0149085.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP438\A0149096.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP438\A0149107.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP439\A0149115.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP439\A0149116.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP439\A0149117.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP439\A0149122.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP439\A0149124.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP439\A0149126.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP440\A0149129.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP440\A0149130.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP440\A0149131.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP440\A0149132.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP440\A0149133.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149142.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149145.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149146.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149147.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149148.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149159.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149160.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149162.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149163.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP441\A0149164.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149204.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149205.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149206.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149207.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149208.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149221.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149223.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149225.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149261.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149262.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149274.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149276.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149277.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149279.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149280.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149286.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149294.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149296.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149297.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149299.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149300.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149362.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149368.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149394.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149395.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149402.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149403.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149410.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149411.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149412.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0149413.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150409.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150410.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150412.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150413.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150414.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150421.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150422.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150425.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150426.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150427.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP442\A0150445.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150458.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150459.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150461.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150462.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150474.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150475.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150477.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150675.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150677.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150684.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150685.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP443\A0150686.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150688.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150689.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150690.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150691.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150693.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150819.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150823.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150824.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150825.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP444\A0150826.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP445\A0150829.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP445\A0150830.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP445\A0150831.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP445\A0150833.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP445\A0150834.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP446\A0150843.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP446\A0150849.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP446\A0150857.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP446\A0150858.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP446\A0150859.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150862.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150863.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150864.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150866.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150867.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150868.EXE --> Eliminado Bagle.dldr
Nº Total de Directorios: 7006
Nº Total de Ficheros: 89487
Nº de Ficheros Analizados: 13560
Nº de Ficheros Infectados: 299
Nº de Ficheros Limpiados: 299
Thu May 08 19:46:01 2008
EliBagle v11.33 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad D:\
Nº Total de Directorios: 3809
Nº Total de Ficheros: 38902
Nº de Ficheros Analizados: 11651
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Encore merci, mon pc est plus rapide, je viens de parcourir votre dossier prévention et protection (que je vais diffuser) très instructif.. je vais appliquer les recommandations que j'ignorais...cpte administrateur..mises à jour...pieces jointes etc..
Mauvaise nouvelle je viens d'allumer mon pc et elibagla demande à se lancer, nouvelle analyse détecte tjrs bagle et à nouveau l'ordi est au ralenti : je ne peux tjrs pas lancer les autres anti virus pour le w32 si quelqu'un peut m'aider merci beaucoup
Fri May 09 07:04:15 2008
EliBagle v11.33 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado.
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.
Fri May 09 07:11:18 2008
EliBagle v11.33 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\Program Files\Google\GoogleToolbarNotifier\GOOGLETOOLBARNOTIFIER.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150926.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150927.EXE --> Eliminado Bagle.dldr
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150928.SYS --> Eliminado Bagle (rootkit)
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150929.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150930.EXE --> Eliminado Bagle
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP447\A0150943.EXE --> Eliminado Bagle.dldr
Nº Total de Directorios: 6993
Nº Total de Ficheros: 89178
Message édité par alpha0 le 09-05-2008 à 10:04:31
bonsoir
on va s'en occuper autrement:
1
Télécharge ComboFix de sUBs :
ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
mais attention, vu que c'est bagle, il faut feinter pour que tu puisses lancer l'outil donc:
renomme Combofix en Combo-Fix avant de lancer le téléchargement comme suit:
http://forum.pcastuces.com/sujet.asp?f=25&s=37315
Double-clic sur ComboFix, Il va te poser une question, réponds en appuyant sur la touche1 puis attends que combofix ait terminé, il est possible que ton PC reboot, c’est normal, un rapport sera créé.Poste le rapport
\Combofix.txt
clique dessus pour l'ouvrir, puis édition "sélectionner tout", édition "copier"
viens sur le forum et édition "coller"
2
il me faut aussi un rapport de scan en ligne, parfois bagle se régénère à partir d'un crack présent sur ton pc.
~Fais une analyse antivirus en ligne sur le site de Kaspersky
http://webscanner.kaspersky.fr/
~ Clique sur Online Scanner.
~Accepte l'installation du contrôle ActiveX en cliquant sur le bouton Install.
~Sélectionne le poste de travail comme analyse.
~Enregistre le rapport en cliquant sur le bouton "Enregistrer rapport sous". Nomme-le, tu feras un copier/coller dans ta prochaine réponse.
Tuto du scan en ligne
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Avec un peu de retard je vous envoie le rapport de combofix
merci pour l'aide
ComboFix 08-05-11.1 - Benjamin Boscher 2008-05-12 0:07:15.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1557 [GMT 2:00]
Endroit: D:\Documents and Settings\Benjamin Boscher\Bureau\Combo-Fix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-11 to 2008-05-11 ))))))))))))))))))))))))))))))))))))
.
2008-05-11 10:50 . 2008-05-11 22:57 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Symantec
2008-05-11 10:50 . 2008-05-11 22:57 <REP> d-------- C:\Program Files\Symantec
2008-05-11 10:34 . 2008-05-11 10:34 <REP> d-------- C:\Program Files\Windows Sidebar
2008-05-11 10:31 . 2008-05-11 10:31 <REP> d-------- C:\Nouveau dossier (2)
2008-05-11 10:30 . 2008-05-11 14:14 <REP> d-------- C:\SymKBFix
2008-05-10 15:23 . 2008-05-10 15:23 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-05-10 15:20 . 2008-03-01 14:58 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-05-10 15:20 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-05-10 15:20 . 2007-03-08 07:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-05-10 15:20 . 2008-03-01 14:58 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-05-10 15:20 . 2008-03-01 14:58 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-05-10 15:20 . 2008-03-01 14:58 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-05-10 15:20 . 2008-03-01 14:58 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-05-10 15:20 . 2008-03-01 14:58 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-05-10 15:20 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-05-10 15:11 . 2008-05-10 15:11 12,598 --a------ C:\WINDOWS\system32\wpa.bak
2008-05-10 14:34 . 2004-08-05 14:00 10,096,640 --a--c--- C:\WINDOWS\system32\dllcache\hwxcht.dll
2008-05-10 14:33 . 2004-08-05 14:00 563,712 --a--c--- C:\WINDOWS\system32\dllcache\fxsst.dll
2008-05-10 14:32 . 2008-05-10 14:32 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-05-10 14:32 . 2008-05-10 14:32 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-05-10 14:32 . 2008-05-10 14:32 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-05-10 14:32 . 2008-05-10 14:32 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-05-10 14:32 . 2008-05-10 14:32 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-05-10 14:31 . 2004-08-05 14:00 16,384 --a--c--- C:\WINDOWS\system32\dllcache\isignup.exe
2008-05-10 14:30 . 2004-08-05 14:00 86,016 --a--c--- C:\WINDOWS\system32\dllcache\icwconn2.exe
2008-05-10 14:30 . 2004-08-05 14:00 32,768 --a--c--- C:\WINDOWS\system32\dllcache\icwdl.dll
2008-05-10 14:30 . 2004-08-05 14:00 20,480 --a--c--- C:\WINDOWS\system32\dllcache\inetwiz.exe
2008-05-10 12:51 . 2004-08-05 14:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-05-10 12:51 . 2004-08-05 14:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-05-10 12:51 . 2004-08-05 14:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-05-10 12:51 . 2004-08-05 14:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-05-10 11:41 . 2004-08-05 14:00 218,624 --a--c--- C:\WINDOWS\system32\dllcache\icwconn1.exe
2008-05-10 11:19 . 2004-08-05 14:00 1,086,058 -ra------ C:\WINDOWS\SET51.tmp
2008-05-10 11:19 . 2004-08-05 14:00 1,014,836 -ra------ C:\WINDOWS\SET4E.tmp
2008-05-10 11:19 . 2004-08-05 14:00 14,043 -ra------ C:\WINDOWS\SET5D.tmp
2008-05-10 09:51 . 2008-05-10 09:51 34 --a------ C:\WINDOWS\system\oeminfo.ini
2008-05-10 09:50 . 2004-08-05 14:00 1,086,058 -ra------ C:\WINDOWS\SETF4.tmp
2008-05-10 09:50 . 2004-08-05 14:00 14,043 -ra------ C:\WINDOWS\SET100.tmp
2008-05-10 09:50 . 2004-08-05 14:00 7,334 --a--c--- C:\WINDOWS\system32\dllcache\wmerrenu.cat
2008-05-10 09:49 . 2004-08-05 14:00 1,014,836 -ra------ C:\WINDOWS\SETF1.tmp
2008-05-10 09:24 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-09 18:56 . 2008-05-09 18:56 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-05-09 18:56 . 2001-08-28 13:00 499,200 --a------ C:\WINDOWS\system32\gpedit.dll
2008-05-09 18:56 . 2002-08-29 10:44 284,160 --a------ C:\WINDOWS\system32\appmgr.dll
2008-05-09 18:56 . 2002-08-29 10:44 185,856 --a------ C:\WINDOWS\system32\gptext.dll
2008-05-09 18:56 . 2002-08-29 10:44 165,376 --a------ C:\WINDOWS\system32\appmgmts.dll
2008-05-09 18:56 . 2001-08-28 13:00 119,296 --a------ C:\WINDOWS\system32\fde.dll
2008-05-09 18:56 . 2002-08-29 10:44 70,144 --a------ C:\WINDOWS\system32\fdeploy.dll
2008-05-09 18:56 . 2001-08-28 13:00 34,352 --a------ C:\WINDOWS\system32\gpedit.msc
2008-05-06 17:18 . 2008-05-06 17:18 <REP> d-------- C:\Program Files\Alwil Software
2008-05-05 14:14 . 2008-05-05 14:29 1,518,094 --a------ D:\Documents and Settings\All Users\Application Data\LuInstall.LiveUpdate
2008-05-05 12:16 . 2008-05-05 12:27 <REP> d-------- C:\Program Files\Old-Symantec
2008-05-03 20:13 . 2008-05-03 20:13 <REP> d-------- C:\OEMCUST
2008-05-03 20:13 . 2008-05-03 20:15 <REP> d-------- C:\FACTONLY
2008-05-03 20:13 . 2008-05-03 20:17 <REP> d-------- C:\CABS
2008-04-30 19:25 . 2008-05-11 23:16 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-30 19:25 . 2008-04-30 19:25 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 20:59 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-05-11 20:50 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-11 12:29 --------- d---a-w C:\Program Files\OFFICE One6.5
2008-05-10 14:52 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-05-10 07:24 --------- d-----w C:\Program Files\Java
2008-05-09 16:17 --------- d-----w C:\Program Files\Yahoo!
2008-05-05 13:00 --------- d-----w D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec
2008-05-01 15:51 --------- d-----w C:\Program Files\AVS4YOU
2008-04-30 17:30 --------- d-----w C:\Program Files\Warcraft III
2008-04-21 17:38 --------- d-----w D:\Documents and Settings\All Users\Application Data\UDL
2008-04-21 17:35 --------- d-----w C:\Program Files\epson
2008-04-16 10:26 --------- d-----w C:\Program Files\Apple Software Update
2008-04-05 13:06 --------- d-----w C:\Program Files\iTunes
2008-04-05 13:06 --------- d-----w C:\Program Files\iPod
2008-04-05 13:05 --------- d-----w C:\Program Files\QuickTime
2008-03-19 16:44 --------- d-----w D:\Documents and Settings\Benjamin Boscher\Application Data\Apple Computer
2008-03-12 14:28 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-29 16:30 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2006-12-30 20:57 5,037,072 -c--a-w D:\Documents and Settings\Benjamin Boscher\spybotsd14.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4B857FD8-EE58-4AFE-8975-A72BBB90E11B}]
C:\WINDOWS\system32\mllmj.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"copy bind"="D:\DOCUME~1\BENJAM~1\APPLIC~1\REMOTE~1\support mfcd.exe" [ ]
"Configuration de la C-BOX"="C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe" [ ]
"EPSON Stylus DX8400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.exe" [2007-04-12 08:00 182272]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ulead AutoDetector v2"="C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2008-05-07 16:50 90112]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-11-03 12:53 180269]
"Skipwmaadmin16"="D:\Documents and Settings\All Users\Application Data\PROCNURBSKIPWMA\THAT CASH.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [ ]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [ ]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 14:48 127118]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-12 16:59 77824]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-12 16:57 188416]
"Lexmark X6100 Series"="C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 15:00 208952]
"Doom 3 NO CD Crack"="D:\Documents and Settings\Benjamin Boscher\Shared\Doom 3 NO CD Crack.exe" [ ]
"BOOT"="C:\Program Files\ISSENDIS\ISSENDIS WebUpdate v6\issendiswebupdatev6.exe" [2002-08-16 15:14 476160]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-05 14:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Battlefield 1942 no cd crack"="D:\Documents and Settings\Benjamin Boscher\Shared\Battlefield 1942 no cd crack.exe" [ ]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 22:05 344064]
"Age Of Mythology - The Titans no cd crack"="D:\Documents and Settings\Benjamin Boscher\Shared\Age Of Mythology - The Titans no cd crack.exe" [ ]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31 24576]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2005-05-17 19:48 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"IS CfgWiz"="C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cfgwiz.exe" [ ]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [ ]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [ ]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe" [2006-09-08 15:46 100032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SymLnch"="D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" [2007-08-26 18:04 687976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 22:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccProxy"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Symantec RemoteAssist"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Sierra\\Homeworld2\\Bin\\Release\\Homeworld2.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"D:\\Divers\\jeux\\Age of Empire II\\EMPIRES2.ICD"=
"D:\\Divers\\jeux\\Age of Empire II\\age2_x1\\age2_x1.icd"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
"D:\\Divers\\jeux\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"D:\\Divers\\jeux\\Dawn Of War & Winter Assault\\W40k.exe"=
"D:\\Divers\\jeux\\Dawn Of War & Winter Assault\\W40kWA.exe"=
"D:\\Divers\\jeux\\supreme Commander\\Supreme Commander\\bin\\SupremeCommander.exe"=
"D:\\Divers\\jeux\\supreme Commander\\GPGNet\\GPG.Multiplayer.Client.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"D:\\Program Files\\lphant\\eLePhantClient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:HTTP
"27900:TCP"= 27900:TCP:Master Server UDP Heartbeat
"28900:TCP"= 28900:TCP:Master Server List Request
"29900:TCP"= 29900:TCP:GP Connection Manager
"29901:TCP"= 29901:TCP:GP Search Manager
"13139:TCP"= 13139:TCP:Custom UDP Prings
"6500:TCP"= 6500:TCP:entrant, UDP, port de requête de salle par défaut
"4662:TCP"= 4662:TCP:Elphant 1
"4672:UDP"= 4672:UDP:Elphant 2
R0 sonypvl2;sonypvl2;C:\WINDOWS\system32\drivers\sonypvl2.sys [2003-07-25 15:02]
R1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2005-11-09 17:07]
R1 sonypvf2;sonypvf2;C:\WINDOWS\system32\drivers\sonypvf2.sys [2004-04-08 11:04]
R1 sonypvt2;sonypvt2;C:\WINDOWS\system32\drivers\sonypvt2.sys [2003-08-20 10:44]
S3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-27 13:51]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
S3 e54c1f43-d91d-4efd-a3c0-b217f515a874;e54c1f43-d91d-4efd-a3c0-b217f515a874;E:\Player\cds300.dll []
S3 kbeepm;kbeepm;D:\DOCUME~1\BENJAM~1\LOCALS~1\Temp\kbeepm.sys []
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-11 22:00:00 C:\WINDOWS\Tasks\A46DDFA591AE5A81.job"
- d:\docume~1\benjam~1\applic~1\remote~1\SetupDefyThunk.exe
"2008-05-06 15:49:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-05-11 17:30:00 C:\WINDOWS\Tasks\Configurer mon PC.job"
- C:\Apps\SMP\PCSETUP.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 00:07:59
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MysqlInventime]
"ImagePath"="C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime"
.
Temps d'accomplissement: 2008-05-12 0:08:22
ComboFix-quarantined-files.txt 2008-05-11 22:08:20
ComboFix2.txt 2008-05-11 21:19:05
Pre-Run: 14,055,583,744 octets libres
Post-Run: 14,043,631,616 octets libres
226 --- E O F --- 2008-05-11 19:20:46
voila le rapport kaspersky:
KASPERSKY ON-LINE SCANNER REPORT
Monday, May 12, 2008 11:16:16 AM
Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.83.0
Dernière mise à jour de la base antivirus Kaspersky : 12/05/2008
Enregistrements dans la base antivirus Kaspersky : 680760
Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie vrai
Cible de l'analyse Poste de travail
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Statistiques de l'analyse
Total d'objets analysés 123174
Nombre de virus trouvés 4
Nombre d'objets infectés 114 / 0
Nombre d'objets suspects 0
Durée de l'analyse 01:00:24
Nom de l'objet infecté Nom du virus Dernière action
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_AGENT_LOG1.txt L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_AUDIO\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_AUDIO\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_BINARY\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_BLOB\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_BLOB\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_GLOBAL\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_GLOBAL\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_IMAGE\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_IMAGE\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_MAIN\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_MAIN\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_TV\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_TV\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_VIDEO\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_VIDEO\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcrst.dll L'objet est verrouillé ignoré
C:\QooBox\Quarantine\Registry_backups\Legacy_SROSA.reg.dat Infecté : Trojan-Downloader.Win32.Bagle.hp ignoré
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP7\change.log L'objet est verrouillé ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000043.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000047.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000063.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000073.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000081.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000091.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000096.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000106.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000111.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000124.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000127.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000142.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000147.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000151.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000153.exe Infecté : Email-Worm.Win32.Bagle.of ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000154.exe Infecté : Email-Worm.Win32.Bagle.vr ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000162.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000168.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000173.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000183.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000188.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000197.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000203.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000207.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000222.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000234.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000239.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000254.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000265.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000269.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000279.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000285.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000291.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000301.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000306.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000311.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000323.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000333.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000338.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000373.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000383.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000388.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000396.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000402.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000407.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000421.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000422.exe Infecté : Email-Worm.Win32.Bagle.vr ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000426.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000430.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000436.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000441.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000447.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000453.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000457.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000466.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000470.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000480.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000484.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000486.exe Infecté : Email-Worm.Win32.Bagle.vr ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000492.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000497.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000507.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000509.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000522.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000535.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000569.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000583.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000589.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000602.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000609.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000611.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000629.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000645.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000660.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000668.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000681.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000691.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000714.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000726.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000730.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000740.exe Infecté : Email-Worm.Win32.Bagle.vr ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000742.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000746.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000764.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000765.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000773.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000774.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000784.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000800.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000804.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000814.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000821.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000826.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000840.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000850.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000860.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000870.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000886.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000913.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000917.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000923.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000930.exe Infecté : Email-Worm.Win32.Bagle.of ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000933.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000938.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000951.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000956.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000969.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000974.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000980.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000990.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000997.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0000999.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\System Volume Information\_restore{8FBB22D8-4871-424E-9C94-00D6FF923C77}\RP1\A0001003.exe Infecté : Trojan-Downloader.Win32.Bagle.ij ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\EventCache\{EE0315DC-C195-4B20-8123-5799629858C9}.bin L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edbtmp.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-05-12_Log.ALUSchedulerSvc.LiveUpdate L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Cookies\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Logs\Dfsr00005.log L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\pending.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\dfsr.db L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\fsr.log L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\fsrtmp.log L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\tmp.edb L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows Live Contacts\anthonyboscher@hotmail.fr\real\members.stg L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows Live Contacts\anthonyboscher@hotmail.fr\shadow\members.stg L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Historique\History.IE5\MSHist012008051220080513\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\temp\~DF97F7.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\temp\~DF980B.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\temp\~DFD74E.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\temp\~DFD75B.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\NTUSER.DAT L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\ntuser.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\UserData\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
D:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
D:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP7\change.log L'objet est verrouillé ignoré
Analyse terminée.
Quelqu'un peut m'aider ? ? je voudrais me débarrasser définitivement de bagle dois je lancer hijackthis ?? merci
bonjour
j'ai une vie.
tu as eu bagle, mais comme tu as passé Combofix plusieurs fois, je ne le vois pas dans le rapport.
rien dans le rapport de Kasperky, bagle est dans le backup de combofix et dans la restauration de xp. Il est donc inoffensif maintenant
réinstalle un antivirus (si ce n'est pas déjà fait)
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
- Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
- Afin de lancer la recherche, clic sur"Rechercher".
- Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.
AIDE : Tuto en images sur MBAM
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
c'était un peu long (+ de 6 h...), mais , ça y est, voici le rapport de malware:
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 742
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 158623
Temps écoulé: 6 hour(s), 26 minute(s), 14 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\ClickToFindandFixErrors_Intl.ico (Malware.Trace) -> No action taken.
je suis contente d'apprendre que mon bagle est inoffensif, merci beaucoup d'avoir pris le temps de m'aider, j'étais un peu perdu...
je vais réinstaller norton et spybot, je pense que je dois supprimer tous les outils utilisés...merciiii à sham_rock sans oublier aussi angeldark
re
tu as oublié clic sur "Afficher les résultats" puis sur "[]Supprimer la sélection[/]"
supprime manuellement:
C:\WINDOWS\system32\ClickToFindandFixErrors_Intl.ico
poste un log hijackthis quand même, qu'on puisse tout vérifier
Télécharge puis installe Hijackthis (Trend Micro)
Poste ensuite un rapport dans ta prochaine réponse.
AIDE : Comment utiliser Hijackthis v2.0.2
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Re coucou,
voici le rapport de hijackthis mais je n'ai pas trouvé le fichier que je dois supprimer manuellement ( pour moi supprimer manuellement c'est click droit; supprimer...c'est bien ça...? )
Entre temps j'ai installé kaspersky pour un mois à l'essai,
quand pensez-vous ? Car, avec norton, j'ai tous les problèmes du monde pour le réinstaller.
RE merci
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:52:40, on 14/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\rundll32.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ctfmon.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4B857FD8-EE58-4AFE-8975-A72BBB90E11B} - C:\WINDOWS\system32\mllmj.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Skipwmaadmin16] D:\Documents and Settings\All Users\Application Data\PROCNURBSKIPWMA\THAT CASH.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [BOOT] C:\Program Files\ISSENDIS\ISSENDIS WebUpdate v6\issendiswebupdatev6.exe /BOOT
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [Doom 3 NO CD Crack] D:\Documents and Settings\Benjamin Boscher\Shared\Doom 3 NO CD Crack.exe
O4 - HKLM\..\Run: [Battlefield 1942 no cd crack] D:\Documents and Settings\Benjamin Boscher\Shared\Battlefield 1942 no cd crack.exe
O4 - HKLM\..\Run: [Age Of Mythology - The Titans no cd crack] D:\Documents and Settings\Benjamin Boscher\Shared\Age Of Mythology - The Titans no cd crack.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\RunOnce: [SymLnch] "D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [copy bind] D:\DOCUME~1\BENJAM~1\APPLIC~1\REMOTE~1\support mfcd.exe
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_S118.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.happyfile.net
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6 [...] vSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader4.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://c.voila.fr/V3/Icons/voila.gif
--
End of file - 11711 bytes
Suite
Je viens de trouver le system32 dans Qoobox\quarantine\C\windows\System32 et dedans 10 fichiers VIR
ex: de nom :bqhdrcck.ini.vir en effet quand j'ai lancé kaspersky il a trouvé bagle + un fichier volume restore ? ? j'ai fait supprimé mais ils sont en quarantaine.... ? ? c'est des cours d'informatique qu'il me faudrait hi hi
je suis moins stressée maintenant désolée pour la pression... Bonne soirée
re
pas de panique
il reste une infection (pas bagle) mais lop: ça génère des pages de pubs intempestives. On s'en occupe:
Télécharge Lop S&D.exe sur ton bureau
- Double-clique dessus pour lancer l'installation
- Puis double-clique sur le raccourci Lop S&D présent sur ton bureau
- Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
- Patiente jusqu'à la fin du scan
- Poste le rapport généré ( C:\lopR.txt )
( Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
J'ai téléchargé Lop S&D avec votre lien, je l'ai installé, mais lorsque que je double-click sur le raccourci qui s'est créé sur mon bureau, le message suivant s'affiche: "le lecteur ou la conexion réseau désigné par le raccourci Lop s&D.Ink n'est pas disponible, vérifier que...etc...etc...". De plus le raccourci a l'allure d'un fichier windows (le dessin d'une petite fenètre sur un fond blanc), le genre de fichier que l'on ne peut pas ouvrir sans un programme adapté...
Que faire ?
bonjour
supprime ce que tu as téléchargé et recommence la manipulation en désactivant ton antivirus
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
bonsoir Sham_Rock,
je viens de refaire la manipulation en désactivant mon anti-virus, et, la seule chose qui change est le message d'erreur.
Maintenant, ça donne:"c:\lopSD\LopSD.cmd Le chemin d'accès spécifié n'éxiste pas. Vérifiez que le chemin est correct puis essayez à nouveau."
bonjour
possible que ça soit lié à tes deux partitions. (et que tu ais téléchargé sur D)
supprime ce que tu as et fais le téléchargement sur C:\
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Bonsoir,
Je viens de faire comme vous me l'avez demandé et ça marche
Ci joint le rapport
Sinon mon ordi fonctionne bien, je n'ai pas réinstallé norton mais kaspersky à l'essai pour un mois qu'en pensez vous ?
Merci pour vos conseils
-----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 3 ]
[ USER : Benjamin Boscher ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 19/05/2008 | 19:36:30,84 ] [ PC : 111239660313 ]
[ MAJ : 16-05-2008 | 23:35 ]
-------------[ Listing des dossiers dans Application Data ]------------
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[19/05/2008 19:30][--a------] C:\WINDOWS\tasks\Configurer mon PC.job
[19/05/2008 19:00][--ah-----] C:\WINDOWS\tasks\A46DDFA591AE5A81.job
[13/05/2008 17:49][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[19/05/2008 19:34][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 15:00][---h-----] C:\WINDOWS\tasks\desktop.ini
A46DDFA591AE5A81.job <--> d:\docume~1\benjam~1\applic~1\remote~1\SetupDefyThunk.exe
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[12/05/2006|19:23] C:\Program Files\ABBYY FineReader 6.0
[23/02/2008|18:45] C:\Program Files\ABBYY FineReader 6.0 Sprint
[18/02/2008|21:23] C:\Program Files\Adobe
[24/11/2005|20:34] C:\Program Files\AMD
[09/03/2007|20:40] C:\Program Files\AOL 9.0
[24/11/2005|20:35] C:\Program Files\AOL Compagnon
[16/04/2008|12:26] C:\Program Files\Apple Software Update
[14/01/2008|20:54] C:\Program Files\AviSynth 2.5
[01/05/2008|17:51] C:\Program Files\AVS4YOU
[13/05/2006|20:31] C:\Program Files\Ciel
[24/11/2005|20:34] C:\Program Files\ComPlus Applications
[14/05/2008|15:30] C:\Program Files\Conduit
[24/11/2005|20:34] C:\Program Files\CyberLink
[15/11/2007|19:40] C:\Program Files\DigimaxReader Eng
[07/05/2006|11:47] C:\Program Files\directx
[21/04/2008|19:35] C:\Program Files\epson
[13/05/2008|17:46] C:\Program Files\Fichiers communs
[24/11/2005|20:34] C:\Program Files\GMixon
[29/02/2008|20:03] C:\Program Files\InstallShield Installation Information
[10/05/2008|16:48] C:\Program Files\Internet Explorer
[18/08/2007|10:58] C:\Program Files\Inventel
[05/04/2008|15:06] C:\Program Files\iPod
[13/05/2006|20:32] C:\Program Files\ISSENDIS
[05/04/2008|15:06] C:\Program Files\iTunes
[10/05/2008|09:24] C:\Program Files\Java
[13/05/2008|19:45] C:\Program Files\Kaspersky Lab
[24/11/2005|20:34] C:\Program Files\Learn2.com
[31/05/2006|17:02] C:\Program Files\Logitech
[14/05/2008|15:30] C:\Program Files\LphantBar
[01/05/2006|20:22] C:\Program Files\Maxis
[18/05/2008|12:57] C:\Program Files\Messenger
[16/07/2007|15:40] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[07/12/2007|19:56] C:\Program Files\microsoft frontpage
[07/12/2007|19:58] C:\Program Files\Microsoft Office
[30/05/2007|15:08] C:\Program Files\Microsoft Picture It! PhotoPub
[07/12/2007|19:26] C:\Program Files\Microsoft Visual Studio
[18/05/2008|12:57] C:\Program Files\Movie Maker
[07/06/2006|19:07] C:\Program Files\MSN
[24/11/2005|20:34] C:\Program Files\MSN Gaming Zone
[17/11/2006|08:05] C:\Program Files\MSXML 4.0
[11/08/2007|10:16] C:\Program Files\N1busMetronome
[18/05/2008|12:55] C:\Program Files\NetMeeting
[11/05/2008|14:29] C:\Program Files\OFFICE One6.5
[05/05/2008|12:27] C:\Program Files\Old-Symantec
[18/05/2008|12:55] C:\Program Files\Outlook Express
[29/12/2006|20:17] C:\Program Files\overnet
[05/04/2008|15:05] C:\Program Files\QuickTime
[20/05/2006|10:36] C:\Program Files\Readiris Pro 8
[24/11/2005|20:34] C:\Program Files\Real
[15/11/2007|19:37] C:\Program Files\Samsung
[24/11/2005|20:37] C:\Program Files\Services en ligne
[26/07/2006|19:59] C:\Program Files\Sierra
[07/12/2007|19:57] C:\Program Files\Snapshot Viewer
[18/07/2006|15:19] C:\Program Files\SoftEx Company
[24/11/2005|20:34] C:\Program Files\Sonic
[14/05/2008|19:52] C:\Program Files\Trend Micro
[24/11/2005|20:34] C:\Program Files\Ulead Systems
[24/11/2005|20:34] C:\Program Files\Uninstall Information
[24/11/2005|20:34] C:\Program Files\Viewpoint
[18/08/2007|11:04] C:\Program Files\Wanadoo
[17/05/2008|15:46] C:\Program Files\Warcraft III
[31/12/2006|12:49] C:\Program Files\Warez P2P Client
[09/03/2008|18:16] C:\Program Files\Windows Live
[10/05/2008|16:52] C:\Program Files\Windows Live Toolbar
[24/11/2005|20:34] C:\Program Files\Windows Media Components
[28/12/2006|15:51] C:\Program Files\Windows Media Connect 2
[18/05/2008|18:07] C:\Program Files\Windows Media Player
[18/05/2008|12:55] C:\Program Files\Windows NT
[24/11/2005|20:34] C:\Program Files\WindowsUpdate
[09/01/2008|18:50] C:\Program Files\WinRAR
[25/11/2006|15:22] C:\Program Files\WinZip
[24/11/2005|20:34] C:\Program Files\xerox
[09/05/2008|18:17] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[18/02/2008|21:23] C:\Program Files\Fichiers communs\Adobe
[19/07/2006|13:05] C:\Program Files\Fichiers communs\Adobe Systems Shared
[24/11/2005|20:36] C:\Program Files\Fichiers communs\AOL
[24/11/2005|20:36] C:\Program Files\Fichiers communs\aolshare
[08/07/2007|21:15] C:\Program Files\Fichiers communs\Apple
[18/08/2007|23:19] C:\Program Files\Fichiers communs\AVSMedia
[13/05/2006|20:31] C:\Program Files\Fichiers communs\Borland Shared
[07/12/2007|19:26] C:\Program Files\Fichiers communs\Designer
[01/05/2006|13:35] C:\Program Files\Fichiers communs\InstallShield
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Java
[31/05/2006|17:02] C:\Program Files\Fichiers communs\Labtec
[09/03/2008|18:15] C:\Program Files\Fichiers communs\Microsoft Shared
[24/11/2005|20:34] C:\Program Files\Fichiers communs\MSSoap
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Nullsoft
[24/11/2005|20:34] C:\Program Files\Fichiers communs\ODBC
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Real
[10/05/2008|14:31] C:\Program Files\Fichiers communs\Services
[03/11/2006|22:35] C:\Program Files\Fichiers communs\Sonic Shared
[24/11/2005|20:34] C:\Program Files\Fichiers communs\SpeechEngines
[13/04/2007|17:50] C:\Program Files\Fichiers communs\SureThing Shared
[10/02/2007|13:52] C:\Program Files\Fichiers communs\SWF Studio
[13/05/2008|17:57] C:\Program Files\Fichiers communs\Symantec Shared
[18/05/2008|12:55] C:\Program Files\Fichiers communs\System
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Ulead Systems
[09/03/2008|18:15] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[24/11/2005|20:34] C:\Program Files\Fichiers communs\xing shared
---------------------------[ Process ]--------------------------
... 51
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
C:\WINDOWS\Tasks\A46DDFA591AE5A81.job
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SaveRoamBrowse]
"DisplayName"="CiD Help"
"UninstallString"="D:\\DOCUME~1\\BENJAM~1\\APPLIC~1\\REMOTE~1\\support mfcd.exe -uninstall"
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-19 19:37:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
=> D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\AnyDVD v6.1.0.0 + crack.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\BearShare PRO 5 2 5 FULL with CRACK (latest version) - WORKS 100%NBCclan nl zip.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Diskeeper.2007 PRO PREMIERE 11.0.686 Winx86 + CRACK.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Eragon & NoCD Crack.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Google Earh Pro 4 0 incl Crack.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Google Earth Pro v254 incl Crack.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Kaspersky Internetsecurity 6 0 1 411 incl working cracks rar.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Mac Crack Attack 1.0.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\McAfee VirusScan Plus 2007 FULL+CRACK WORKING CRACK zip.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Need For Speed Carbon CRACK.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\nortoninternet security 2007 crack zip.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\PalmCrack 1.1.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\PSP Movie Creator v2 0 And Cracks.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Safe Cracker 2.05.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\SQL Server Backup v6 1 2 1086 WinALL Cracked-NGEN.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Ultimate ZIP Cracker 7.3.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\UltraISO Premium Edition v8 6 0 1936 Cracked-EXPLOSiON NoPassword.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Unreal Tournament 2004 v3369 crack(online play enabled).zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Vista 64 bits Francais Ultimate + Crack.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Vista Crack WORKING! 100% clean.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Windows Media Player 11 Final + WINDOWS VALIDATION CRACK rar.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Windows Media Player 11 Final + WINDOWS VALIDATION CRACK.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\windows vista TiMeBoMb crack BY Digital tech.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Adobe Photoshop CS2 v9 0 FinaL + KeyGeN & Activator=NBCclan nl zip.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\avast! Professional Edition 4 7 827 + KeyGen.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\IDM UltraEdit v12 20b + Keygen.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Need for speed carbon keygen by x4rsz exe.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Nero 7 5 9 0 WoRKING KeYgen.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Tune Up Utilities 2007 Final English+keygen working.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\Windows Vista Keygen Home Professional.zip
=> D:\Documents and Settings\Benjamin Boscher\Complete\WinZip Pro v11 0 7313 with keygen no password exe.zip
[F:1341][D:169]-> D:\DOCUME~1\BENJAM~1\LOCALS~1\Temp
[F:60][D:0]-> D:\DOCUME~1\BENJAM~1\Cookies
[F:897][D:6]-> D:\DOCUME~1\BENJAM~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 19:38:28,84 ]----------------------
je stoppe la désinfection jusqu'à temps que tu vires tous tes cracks pourris,
fais le ménage, sinon, faudra trouver une autre poire quand tu te réinfecteras,
à toi de jouer, supprime:
| Citation : => D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip
|
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Bonsoir,
Pouvez vous me dire comment je fais pour trouver le dossier "complete" car il ne se trouve pas dans "D:\doc & setting\benjamin boscher\
si ce fichier existe, il n'est pas visible...
Désolé pour le malentendu, mon fils, en voulant télecharger un crack pour jouer à un jeux (que je lui avais supprimé) sans le CD: Doom 3.
Il s'est retrouvé avec tout un tas de crack différents pour des jeux qu'il n'a même pas et d'autres applications inconnues.
Et tous ces fichiers là, on ne les trouve pas dans nos dossiers...
Je veux les supprimer, pouvez-vous encore m'aider, svp
re
~Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne TOUS les emplacements en gras ci-dessous :
D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip
D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO.zip
D:\Documents and Settings\Benjamin Boscher\Complete\AnyDVD v6.1.0.0 + crack.zip
D:\Documents and Settings\Benjamin Boscher\Complete\BearShare PRO 5 2 5 FULL with CRACK (latest version) - WORKS 100%NBCclan nl zip.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Diskeeper.2007 PRO PREMIERE 11.0.686 Winx86 + CRACK.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Eragon & NoCD Crack.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Google Earh Pro 4 0 incl Crack.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Google Earth Pro v254 incl Crack.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Kaspersky Internetsecurity 6 0 1 411 incl working cracks rar.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Mac Crack Attack 1.0.zip
D:\Documents and Settings\Benjamin Boscher\Complete\McAfee VirusScan Plus 2007 FULL+CRACK WORKING CRACK zip.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Need For Speed Carbon CRACK.zip
D:\Documents and Settings\Benjamin Boscher\Complete\nortoninternet security 2007 crack zip.zip
D:\Documents and Settings\Benjamin Boscher\Complete\PalmCrack 1.1.zip
D:\Documents and Settings\Benjamin Boscher\Complete\PSP Movie Creator v2 0 And Cracks.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Safe Cracker 2.05.zip
D:\Documents and Settings\Benjamin Boscher\Complete\SQL Server Backup v6 1 2 1086 WinALL Cracked-NGEN.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Ultimate ZIP Cracker 7.3.zip
D:\Documents and Settings\Benjamin Boscher\Complete\UltraISO Premium Edition v8 6 0 1936 Cracked-EXPLOSiON NoPassword.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Unreal Tournament 2004 v3369 crack(online play enabled).zip
D:\Documents and Settings\Benjamin Boscher\Complete\Vista 64 bits Francais Ultimate + Crack.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Vista Crack WORKING! 100% clean.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Windows Media Player 11 Final + WINDOWS VALIDATION CRACK rar.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Windows Media Player 11 Final + WINDOWS VALIDATION CRACK.zip
D:\Documents and Settings\Benjamin Boscher\Complete\windows vista TiMeBoMb crack BY Digital tech.zip
D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip
D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Adobe Photoshop CS2 v9 0 FinaL + KeyGeN & Activator=NBCclan nl zip.zip
D:\Documents and Settings\Benjamin Boscher\Complete\avast! Professional Edition 4 7 827 + KeyGen.zip
D:\Documents and Settings\Benjamin Boscher\Complete\IDM UltraEdit v12 20b + Keygen.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Need for speed carbon keygen by x4rsz exe.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Nero 7 5 9 0 WoRKING KeYgen.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Tune Up Utilities 2007 Final English+keygen working.zip
D:\Documents and Settings\Benjamin Boscher\Complete\Windows Vista Keygen Home Professional.zip
D:\Documents and Settings\Benjamin Boscher\Complete\WinZip Pro v11 0 7313 with keygen no password exe.zip
---> Clique-droit puis Copier (ou Ctrl+C)
Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
Clique maintenant sur MoveIt!
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
merci, voici le rapport:
D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\AnyDVD v6.1.0.0 + crack.zip moved successfully.
< D:\Documents and Settings\Benjamin Boscher\Complete\BearShare PRO 5 2 5 FULL with CRACK (latest version) - WORKS 100%NBCclan nl zip.zip >
D:\Documents and Settings\Benjamin Boscher\Complete\BearShare PRO 5 2 5 FULL with CRACK (latest version) - WORKS 100%NBCclan nl zip.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Diskeeper.2007 PRO PREMIERE 11.0.686 Winx86 + CRACK.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Eragon & NoCD Crack.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Google Earh Pro 4 0 incl Crack.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Google Earth Pro v254 incl Crack.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Kaspersky Internetsecurity 6 0 1 411 incl working cracks rar.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Mac Crack Attack 1.0.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\McAfee VirusScan Plus 2007 FULL+CRACK WORKING CRACK zip.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Need For Speed Carbon CRACK.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\nortoninternet security 2007 crack zip.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\PalmCrack 1.1.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\PSP Movie Creator v2 0 And Cracks.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Safe Cracker 2.05.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\SQL Server Backup v6 1 2 1086 WinALL Cracked-NGEN.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Ultimate ZIP Cracker 7.3.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\UltraISO Premium Edition v8 6 0 1936 Cracked-EXPLOSiON NoPassword.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Unreal Tournament 2004 v3369 crack(online play enabled).zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Vista 64 bits Francais Ultimate + Crack.zip moved successfully.
< D:\Documents and Settings\Benjamin Boscher\Complete\Vista Crack WORKING! 100% clean.zip >
D:\Documents and Settings\Benjamin Boscher\Complete\Vista Crack WORKING! 100% clean.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Windows Media Player 11 Final + WINDOWS VALIDATION CRACK rar.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Windows Media Player 11 Final + WINDOWS VALIDATION CRACK.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\windows vista TiMeBoMb crack BY Digital tech.zip moved successfully.
File/Folder D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO rar.zip not found.
File/Folder D:\Documents and Settings\Benjamin Boscher\Complete\ACDSee 9 0pro WinAll+crack+keygen-NFO.zip not found.
D:\Documents and Settings\Benjamin Boscher\Complete\Adobe Photoshop CS2 v9 0 FinaL + KeyGeN & Activator=NBCclan nl zip.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\avast! Professional Edition 4 7 827 + KeyGen.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\IDM UltraEdit v12 20b + Keygen.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Need for speed carbon keygen by x4rsz exe.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Nero 7 5 9 0 WoRKING KeYgen.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Tune Up Utilities 2007 Final English+keygen working.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\Windows Vista Keygen Home Professional.zip moved successfully.
D:\Documents and Settings\Benjamin Boscher\Complete\WinZip Pro v11 0 7313 with keygen no password exe.zip moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05212008_162119
Pensez_vous que mon infection venait de ces fichiers ?
Merci.
bonjour
oui, la plupart des infections viennent des cracks ou des sites pornos...
Relance Lop S&D
- Choisis cette fois ci l'Option 2 ( Suppression )
- Ne ferme pas la fenêtre lors de la suppression !
- Poste le rapport généré ( C:\lopR.txt )
( Si le Bureau ne réapparaît pas presse Ctrl + Alt + Suppr , Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
ça y est, voici le rapport de lop s&d:
-----------------------[ Lop S&D 4.2.0-9 XP/Vista ]---------------------
[ Windows XP (NT 5.1) Build 2600, Service Pack 3 ]
[ USER : Benjamin Boscher ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 21/05/2008 | 18:07:34,10 ] [ PC : 111239660313 ]
[ MAJ : 16-05-2008 | 23:35 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION /////////////////////////////
Supprimé! - C:\WINDOWS\Tasks\A46DDFA591AE5A81.job
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
Supprimé! - C:\Program Files\Viewpoint
Supprimé! - D:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
-------------[ Listing des dossiers dans Application Data ]------------
----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------
[21/05/2008 18:00][--a------] C:\WINDOWS\tasks\Configurer mon PC.job
[13/05/2008 17:49][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[21/05/2008 09:59][--ah-----] C:\WINDOWS\tasks\SA.DAT
[05/08/2004 15:00][---h-----] C:\WINDOWS\tasks\desktop.ini
---------------[ Listing des dossiers dans C:\Program Files ]--------------
[12/05/2006|19:23] C:\Program Files\ABBYY FineReader 6.0
[23/02/2008|18:45] C:\Program Files\ABBYY FineReader 6.0 Sprint
[18/02/2008|21:23] C:\Program Files\Adobe
[24/11/2005|20:34] C:\Program Files\AMD
[09/03/2007|20:40] C:\Program Files\AOL 9.0
[24/11/2005|20:35] C:\Program Files\AOL Compagnon
[16/04/2008|12:26] C:\Program Files\Apple Software Update
[14/01/2008|20:54] C:\Program Files\AviSynth 2.5
[01/05/2008|17:51] C:\Program Files\AVS4YOU
[13/05/2006|20:31] C:\Program Files\Ciel
[24/11/2005|20:34] C:\Program Files\ComPlus Applications
[14/05/2008|15:30] C:\Program Files\Conduit
[24/11/2005|20:34] C:\Program Files\CyberLink
[15/11/2007|19:40] C:\Program Files\DigimaxReader Eng
[07/05/2006|11:47] C:\Program Files\directx
[21/04/2008|19:35] C:\Program Files\epson
[13/05/2008|17:46] C:\Program Files\Fichiers communs
[24/11/2005|20:34] C:\Program Files\GMixon
[29/02/2008|20:03] C:\Program Files\InstallShield Installation Information
[10/05/2008|16:48] C:\Program Files\Internet Explorer
[18/08/2007|10:58] C:\Program Files\Inventel
[05/04/2008|15:06] C:\Program Files\iPod
[13/05/2006|20:32] C:\Program Files\ISSENDIS
[05/04/2008|15:06] C:\Program Files\iTunes
[10/05/2008|09:24] C:\Program Files\Java
[13/05/2008|19:45] C:\Program Files\Kaspersky Lab
[24/11/2005|20:34] C:\Program Files\Learn2.com
[31/05/2006|17:02] C:\Program Files\Logitech
[14/05/2008|15:30] C:\Program Files\LphantBar
[01/05/2006|20:22] C:\Program Files\Maxis
[18/05/2008|12:57] C:\Program Files\Messenger
[16/07/2007|15:40] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[07/12/2007|19:56] C:\Program Files\microsoft frontpage
[07/12/2007|19:58] C:\Program Files\Microsoft Office
[30/05/2007|15:08] C:\Program Files\Microsoft Picture It! PhotoPub
[07/12/2007|19:26] C:\Program Files\Microsoft Visual Studio
[18/05/2008|12:57] C:\Program Files\Movie Maker
[07/06/2006|19:07] C:\Program Files\MSN
[24/11/2005|20:34] C:\Program Files\MSN Gaming Zone
[17/11/2006|08:05] C:\Program Files\MSXML 4.0
[11/08/2007|10:16] C:\Program Files\N1busMetronome
[18/05/2008|12:55] C:\Program Files\NetMeeting
[11/05/2008|14:29] C:\Program Files\OFFICE One6.5
[05/05/2008|12:27] C:\Program Files\Old-Symantec
[18/05/2008|12:55] C:\Program Files\Outlook Express
[29/12/2006|20:17] C:\Program Files\overnet
[05/04/2008|15:05] C:\Program Files\QuickTime
[20/05/2006|10:36] C:\Program Files\Readiris Pro 8
[24/11/2005|20:34] C:\Program Files\Real
[15/11/2007|19:37] C:\Program Files\Samsung
[24/11/2005|20:37] C:\Program Files\Services en ligne
[26/07/2006|19:59] C:\Program Files\Sierra
[07/12/2007|19:57] C:\Program Files\Snapshot Viewer
[18/07/2006|15:19] C:\Program Files\SoftEx Company
[24/11/2005|20:34] C:\Program Files\Sonic
[14/05/2008|19:52] C:\Program Files\Trend Micro
[24/11/2005|20:34] C:\Program Files\Ulead Systems
[24/11/2005|20:34] C:\Program Files\Uninstall Information
[18/08/2007|11:04] C:\Program Files\Wanadoo
[21/05/2008|13:43] C:\Program Files\Warcraft III
[31/12/2006|12:49] C:\Program Files\Warez P2P Client
[09/03/2008|18:16] C:\Program Files\Windows Live
[10/05/2008|16:52] C:\Program Files\Windows Live Toolbar
[24/11/2005|20:34] C:\Program Files\Windows Media Components
[28/12/2006|15:51] C:\Program Files\Windows Media Connect 2
[18/05/2008|18:07] C:\Program Files\Windows Media Player
[18/05/2008|12:55] C:\Program Files\Windows NT
[24/11/2005|20:34] C:\Program Files\WindowsUpdate
[09/01/2008|18:50] C:\Program Files\WinRAR
[25/11/2006|15:22] C:\Program Files\WinZip
[24/11/2005|20:34] C:\Program Files\xerox
[09/05/2008|18:17] C:\Program Files\Yahoo!
------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------
[18/02/2008|21:23] C:\Program Files\Fichiers communs\Adobe
[19/07/2006|13:05] C:\Program Files\Fichiers communs\Adobe Systems Shared
[24/11/2005|20:36] C:\Program Files\Fichiers communs\AOL
[24/11/2005|20:36] C:\Program Files\Fichiers communs\aolshare
[08/07/2007|21:15] C:\Program Files\Fichiers communs\Apple
[18/08/2007|23:19] C:\Program Files\Fichiers communs\AVSMedia
[13/05/2006|20:31] C:\Program Files\Fichiers communs\Borland Shared
[07/12/2007|19:26] C:\Program Files\Fichiers communs\Designer
[01/05/2006|13:35] C:\Program Files\Fichiers communs\InstallShield
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Java
[31/05/2006|17:02] C:\Program Files\Fichiers communs\Labtec
[09/03/2008|18:15] C:\Program Files\Fichiers communs\Microsoft Shared
[24/11/2005|20:34] C:\Program Files\Fichiers communs\MSSoap
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Nullsoft
[24/11/2005|20:34] C:\Program Files\Fichiers communs\ODBC
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Real
[10/05/2008|14:31] C:\Program Files\Fichiers communs\Services
[03/11/2006|22:35] C:\Program Files\Fichiers communs\Sonic Shared
[24/11/2005|20:34] C:\Program Files\Fichiers communs\SpeechEngines
[13/04/2007|17:50] C:\Program Files\Fichiers communs\SureThing Shared
[10/02/2007|13:52] C:\Program Files\Fichiers communs\SWF Studio
[13/05/2008|17:57] C:\Program Files\Fichiers communs\Symantec Shared
[18/05/2008|12:55] C:\Program Files\Fichiers communs\System
[24/11/2005|20:34] C:\Program Files\Fichiers communs\Ulead Systems
[09/03/2008|18:15] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[24/11/2005|20:34] C:\Program Files\Fichiers communs\xing shared
---------------------------[ Process ]--------------------------
... 52
... OK !
----------------------[ Recherche avec S_Lop ]---------------------
Aucun fichier / dossier Lop trouvé !
-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------
Aucun fichier / dossier Lop trouvé !
----------------------[ Verification du Registre ]----------------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SaveRoamBrowse]
"DisplayName"="CiD Help"
"UninstallString"="D:\\DOCUME~1\\BENJAM~1\\APPLIC~1\\REMOTE~1\\support mfcd.exe -uninstall"
--------------------[ Verification du fichier Hosts ]---------------------
Fichier Hosts PROPRE
----------------[ Recherche de fichiers avec Catchme ]-----------------
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-21 18:10:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------[ Recherche d'autres infections ]---------------------
Aucune autre infection trouvée !
[F:1362][D:170]-> D:\DOCUME~1\BENJAM~1\LOCALS~1\Temp
[F:12][D:0]-> D:\DOCUME~1\BENJAM~1\Cookies
[F:260][D:5]-> D:\DOCUME~1\BENJAM~1\LOCALS~1\TEMPOR~1\content.IE5
--------------------[ Fin du rapport a 18:11:32,29 ]----------------------
re
reposte un log hijackthis stp
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
re !
voici le log hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:37:57, on 22/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\rundll32.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4B857FD8-EE58-4AFE-8975-A72BBB90E11B} - C:\WINDOWS\system32\mllmj.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Skipwmaadmin16] D:\Documents and Settings\All Users\Application Data\PROCNURBSKIPWMA\THAT CASH.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [BOOT] C:\Program Files\ISSENDIS\ISSENDIS WebUpdate v6\issendiswebupdatev6.exe /BOOT
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [Doom 3 NO CD Crack] D:\Documents and Settings\Benjamin Boscher\Shared\Doom 3 NO CD Crack.exe
O4 - HKLM\..\Run: [Battlefield 1942 no cd crack] D:\Documents and Settings\Benjamin Boscher\Shared\Battlefield 1942 no cd crack.exe
O4 - HKLM\..\Run: [Age Of Mythology - The Titans no cd crack] D:\Documents and Settings\Benjamin Boscher\Shared\Age Of Mythology - The Titans no cd crack.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\RunOnce: [SymLnch] "D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [copy bind] D:\DOCUME~1\BENJAM~1\APPLIC~1\REMOTE~1\support mfcd.exe
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_S118.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.happyfile.net
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6 [...] vSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader4.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://c.voila.fr/V3/Icons/voila.gif
--
End of file - 11997 bytes
Je viens de voir qu'il me reste 3 cracks en parcourant le rapport hijackthis, et j'ai remarqué qu'ils sont présents dans l'utilitaire de configuration système, dans l'onglet "démarrage"(démarrer\éxécuter\msconfig).
Ces cracks là ne se sont visiblement pas supprimés, comment en venir à bout ?
re
franchement, vu ta pratique du p2p, je me demande si un format du disque D ne t'aurait pas été plus bénéfique...
quand on ne veut pas dépenser d'argent pour les jeux comme les tiens, on joue à Wolfenstein Enemy Territory
1
~Lance Hijackthis “Do a system scan only”.
Coche les lignes qui suivent si encore présentes et uniquement celles-là.
R3 - URLSearchHook: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O2 - BHO: (no name) - {4B857FD8-EE58-4AFE-8975-A72BBB90E11B} - C:\WINDOWS\system32\mllmj.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLpha.dll
O4 - HKLM\..\Run: [Skipwmaadmin16] D:\Documents and Settings\All Users\Application Data\PROCNURBSKIPWMA\THAT CASH.exe
O4 - HKLM\..\Run: [Doom 3 NO CD Crack] D:\Documents and Settings\Benjamin Boscher\Shared\Doom 3 NO CD Crack.exe
O4 - HKLM\..\Run: [Battlefield 1942 no cd crack] D:\Documents and Settings\Benjamin Boscher\Shared\Battlefield 1942 no cd crack.exe
O4 - HKLM\..\Run: [Age Of Mythology - The Titans no cd crack] D:\Documents and Settings\Benjamin Boscher\Shared\Age Of Mythology - The Titans no cd crack.exe
O4 - HKLM\..\RunOnce: [SymLnch] "D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" "D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup.exe" "/REALUPREBOOT /temp /patched"
O4 - HKCU\..\Run: [copy bind] D:\DOCUME~1\BENJAM~1\APPLIC~1\REMOTE~1\support mfcd.exe
Clique sur Fix checked (en bas à gauche)
2
Sélectionne TOUS les emplacements en gras ci-dessous :
D:\DOCUME~1\BENJAM~1\APPLIC~1\REMOTE~1
D:\Documents and Settings\Benjamin Boscher\Shared
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec
D:\Documents and Settings\Benjamin Boscher\Shared
D:\Documents and Settings\All Users\Application Data\PROCNURBSKIPWMA
C:\Program Files\LphantBar
---> Clique-droit puis Copier (ou Ctrl+C)
Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
Clique maintenant sur MoveIt!
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
3
~télécharge ce fichier http://downloads.malwareremoval.com/Nel/FixP.zip
sur le bureau.
Extraie et double clique sur Fix_Protocol_zones_ranges.reg.
Accepte lorsqu'il te demande de fusionner avec le registre. poste ensuite un nouveau rapport hijackthis.
Message édité par Sham_Rock le 22-05-2008 à 22:29:40
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Bonsoir,
Ci joint le rapport de hijackthis:
D:\DOCUME~1\BENJAM~1\APPLIC~1\REMOTE~1 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Shared moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\NPMDataStore moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\VCRedist moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\SYMTHM moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\SYMHTML moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\SPManfst moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\NPC\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\NPC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\Manifest moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\Gadget\frames moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\Gadget\buttons moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\Gadget\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\Gadget moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\APP\SUPPSOFT moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC\APP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC\uiNPC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\uiNPC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymNet\SymNet\Manifest moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymNet\SymNet\Drivers moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymNet\SymNet moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymNet moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymMCEAI\SymMCEAI\SYMSHARE\XP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymMCEAI\SymMCEAI\SYMSHARE\Vista moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymMCEAI\SymMCEAI\SYMSHARE\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymMCEAI\SymMCEAI\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymMCEAI\SymMCEAI moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymMCEAI moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP\SRTSP\System32\Drivers moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP\SRTSP\System32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP\SRTSP\SYMSHARE\SRTSP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP\SRTSP\SYMSHARE\Manifest moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP\SRTSP\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP\SRTSP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SRTSP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC\SPBBC32\SYMSHARE\SPBBC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC\SPBBC32\SYMSHARE\MANIFEST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC\SPBBC32\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC\SPBBC32\LUpdate\LUMfests moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC\SPBBC32\LUpdate moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC\SPBBC32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SPBBC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SEVINST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\Reporter\0c\01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\Reporter\0c moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\Reporter moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\Remover moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\PreScan\0c\01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\PreScan\0c moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\PreScan moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\NISTools moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\MSI moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\LUpdate\WLUEX\SYSTEM32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\LUpdate\WLUEX\SPMANI~1 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\LUpdate\WLUEX\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\LUpdate\WLUEX moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\LUpdate moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\HelpMSI\External\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\HelpMSI\External moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\HelpMSI moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\CF\cfCore\MANIFEST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\CF\cfCore\CFMan moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\CF\cfCore moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\CF moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\ccCommon\ccCommon\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\ccCommon\ccCommon moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\ccCommon moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\AppCore\AppCore moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\AppCore moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC\uiNPC64\NPC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC\uiNPC64\Gadget\frames moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC\uiNPC64\Gadget\buttons moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC\uiNPC64\Gadget\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC\uiNPC64\Gadget moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC\uiNPC64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\uiNPC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SymNet\SND_x64\Drivers moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SymNet\SND_x64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SymNet moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP\SRTSPx64\System32\Drivers moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP\SRTSPx64\System32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP\SRTSPx64\SYMSHARE\SRTSP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP\SRTSPx64\SYMSHARE\Manifest moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP\SRTSPx64\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP\SRTSPx64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SRTSP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SPBBC\SPBBC64\SYMSHARE\SPBBC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SPBBC\SPBBC64\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SPBBC\SPBBC64\LUpdate\LUMfests moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SPBBC\SPBBC64\LUpdate moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SPBBC\SPBBC64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SPBBC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\SEVINST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\ccCommon\ccCmn64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64\ccCommon moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Suport64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\VAData\Dict moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\VAData moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\VASCAN64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\VASCAN\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\VASCAN moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\SPBBC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\SecHist moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\Options moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\ncwHyPEX moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\MANIFEST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\IDS moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\CF\CFMan moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\CF moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\CCPD-LC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\PIF_96E2\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\PIF_96E2 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\OPC\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\OPC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\HTEC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\Dist moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\CF moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\App\IDSDefs moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\App moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup\Setup moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Setup moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\SYMSHARE\MANIFEST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\SYMSHARE\COL moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\Symantec\LUREGMAN moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\Symantec moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\InitDefs moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\drivers moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\APP\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO\APP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO\NCO moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NCO moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\VirusDef moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\VirusD64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\System32\COH64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\System32\COH32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\System32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\Symantec\NORTON\Tasks moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\Symantec\NORTON moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\Symantec moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\NORTON\MUI\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\NORTON\MUI moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\NORTON\APP moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\NORTON\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\NORTON moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\SYMSHARE\SPBBC moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\SYMSHARE\MANIFEST moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\SYMSHARE\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\SYMSHARE moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\COH64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\COH32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi\0c01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\CommonFi moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\COH64 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External\COH32 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV\External moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\NAV moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Lang\0c\01 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Lang\0c moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Lang moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security\15.0 moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts\Norton Internet Security moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec\Layouts moved successfully.
D:\Documents and Settings\Benjamin Boscher\Application Data\Symantec moved successfully.
File/Folder D:\Documents and Settings\Benjamin Boscher\Shared not found.
D:\Documents and Settings\All Users\Application Data\PROCNURBSKIPWMA moved successfully.
C:\Program Files\LphantBar moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05232008_194611
maintenant je vais télécharger malware...encore merci
re..
Deuxième rapport d'hijackthis...j'espère que tout va être OK...
Super, les 3 cracks ne sont plus dans l'utilitaire de configuration système
MERCIIII !!!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:54:43, on 23/05/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Apps\Powercinema\PCMService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://orange.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [BOOT] C:\Program Files\ISSENDIS\ISSENDIS WebUpdate v6\issendiswebupdatev6.exe /BOOT
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ATIPTA] "C:\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [EPSON Stylus DX8400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\WINDOWS\TEMP\E_S118.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6 [...] vSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6 [...] /cabsa.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader4.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://c.voila.fr/V3/Icons/voila.gif
--
End of file - 9855 bytes
Message édité par alpha0 le 23-05-2008 à 20:04:02
re
refais un scan en ligne stp
~Fais une analyse antivirus en ligne sur le site de Kaspersky
http://webscanner.kaspersky.fr/
~ Clique sur Online Scanner.
~Accepte l'installation du contrôle ActiveX en cliquant sur le bouton Install.
~Sélectionne le poste de travail comme analyse.
~Enregistre le rapport en cliquant sur le bouton "Enregistrer rapport sous". Nomme-le, tu feras un copier/coller dans ta prochaine réponse.
Tuto du scan en ligne
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Bonjour,
Je viens de faire l'analyse avec kaspersky, voici le rapport
KASPERSKY ON-LINE SCANNER REPORT
Saturday, May 24, 2008 2:40:12 PM
Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
Kaspersky On-line Scanner version : 5.0.83.0
Dernière mise à jour de la base antivirus Kaspersky : 24/05/2008
Enregistrements dans la base antivirus Kaspersky : 712737
Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie vrai
Cible de l'analyse Poste de travail
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Statistiques de l'analyse
Total d'objets analysés 141998
Nombre de virus trouvés 0
Nombre d'objets infectés 0 / 0
Nombre d'objets suspects 0
Durée de l'analyse 01:15:09
Nom de l'objet infecté Nom du virus Dernière action
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_AGENT_LOG1.txt L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_AUDIO\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_AUDIO\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_BINARY\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_BLOB\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_BLOB\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_GLOBAL\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_GLOBAL\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_IMAGE\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_IMAGE\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_MAIN\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_MAIN\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_TV\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_TV\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_VIDEO\CLML.db L'objet est verrouillé ignoré
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLML_VIDEO\CLML.db-journal L'objet est verrouillé ignoré
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcrst.dll L'objet est verrouillé ignoré
C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP39\change.log L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\EventCache\{091187CD-B36A-4F06-B591-71CE1C489316}.bin L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\drivers\fidbox.dat L'objet est verrouillé ignoré
C:\WINDOWS\system32\drivers\fidbox.idx L'objet est verrouillé ignoré
C:\WINDOWS\system32\drivers\fidbox2.dat L'objet est verrouillé ignoré
C:\WINDOWS\system32\drivers\fidbox2.idx L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0324_AdBlocker_eventcritlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0324_AdBlocker_eventlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0328_popupchk_eventcritlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0328_popupchk_eventlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0331_File_Monitoring_eventlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0334_Web_Monitoring_eventlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0336_pdm_eventcritlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\0336_pdm_eventlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.idx L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\detected.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\eventlog.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP7\Report\report.rpt L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Cookies\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Logs\Dfsr00005.log L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\pending.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\dfsr.db L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\fsr.log L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\fsrtmp.log L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Messenger\anthonyboscher@hotmail.fr\SharingMetadata\Working\database_8EB8_8CE1_B88C_C963\tmp.edb L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows Live Contacts\anthonyboscher@hotmail.fr\real\members.stg L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Application Data\Microsoft\Windows Live Contacts\anthonyboscher@hotmail.fr\shadow\members.stg L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Historique\History.IE5\MSHist012008052420080525\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temp\fla3E35.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temp\~DF84E7.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temp\~DF879E.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temp\~DF8A1E.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temp\~DF8A66.tmp L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temporary Internet Files\Content.IE5\AU0728XO\get_video[1] L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\ntuser.dat L'objet est verrouillé ignoré
D:\Documents and Settings\Benjamin Boscher\ntuser.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\Cookies\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\NTUSER.DAT L'objet est verrouillé ignoré
D:\Documents and Settings\LocalService.AUTORITE NT\ntuser.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\Cookies\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\NTUSER.DAT L'objet est verrouillé ignoré
D:\Documents and Settings\NetworkService.AUTORITE NT\ntuser.dat.LOG L'objet est verrouillé ignoré
D:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
D:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP39\change.log L'objet est verrouillé ignoré
Analyse terminée.
bonjour
d'autres soucis?
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Rebonjour Sham_Rock
Alors j'en conclus que tout est ok, c'est super, merci beaucoup
Je souhaite prendre kaspersky comme anti virus à la place de norton, qu'en pensez vous ??
Merciii beaucoup,
avant ce problème je ne savais pas que l'on pouvait trouver de l'aide en ligne c'est superrr
Je peux écrire RESOLU sur mon message ?
re
kaspersky est performant... mais SI tu l'achètes, si c'est un crack, tu vas te réinfecter.
Supprime tous les programmes installés pour la désinfection.
Merci de consulter ce dossier (en pdf) pour en connaître davantage sur les risques du Net.
Si tu trouves ce document intéressant, n'hésite pas à le transmettre à tes contacts.
~Edite ton premier message (en cliquant sur la gomme) et marque [résolu] dans le titre.
/!\Marre de la pub: Firefox sécurisé/!\
Répondre à Sham_Rock
Il y a 1233 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
