|
|
|
|
Bonjour,
merci de me dire si mon pc est encore infecter apres nettoyage par findykill suite a infection bagle
----------------- FindyKill V4.711 ------------------
* User : HP_Propri‚taire - ANNICK
* executed from : C:\Program Files\FindyKill
* Update on 05/01/09 par Chiquitine29
* Start at 22:42:53 the 11/01/2009
* Windows XP - Internet Explorer 7.0.5730.11
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in C:
Deleted ! - "C:\Muestras"
Deleted ! - C:\InfoSat.txt
»»»» Supression files in C:\WINDOWS
»»»» Supression files in C:\WINDOWS\Prefetch
Deleted ! - C:\WINDOWS\prefetch\143593.EXE-15E4DE8F.pf
Deleted ! - C:\WINDOWS\prefetch\MDELK.EXE-0EF461CE.pf
Deleted ! - C:\WINDOWS\prefetch\WINTEMS.EXE-377E42D4.pf
Deleted ! - C:\WINDOWS\prefetch\WINUPGRO.EXE-2E16D772.pf
»»»» Supression files in C:\WINDOWS\system32
Deleted ! - C:\WINDOWS\system32\mdelk.exe
Deleted ! - C:\WINDOWS\system32\wintems.exe
»»»» Supression files in C:\WINDOWS\system32\drivers
»»»» Supression files in C:\Documents and Settings\HP_Propri‚taire\Application Data
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\m\flec006.exe"
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\m\data.oct"
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\m\srvlist.oct"
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\.Net VisualPaseo Freeware 6.1.0.9.0.68.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\2001
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\@PROMT French-Russian Express Translator 7.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ABC Amber Text Converter 5.06.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Absolute Video Converter 3.30.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Active NTFS Reader for DOS 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Add Bookmark Here 2 3.0.20081031.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Alea Address Book 2.5.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Amazon MP3 Search 1.0.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Arabs Radio Toolbar 1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ASP Calendar 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ATCalc 3.1.8.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Auslogics System Information 1.2.16.230.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Auto Monitor 1.1.3.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Automated Domain Inspiration 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Avast.Antivirus.4.6.Profesional.spanish-espaÇñol.+.keygen.por.TuNeM.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Beautiful Snow Demo Screensaver 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Best MP3 WAV Converter 1.00.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Bid-n-Invoice Basic Invoice 2.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Biorhythm Expert 1.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Black 1.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\BMP EMF Grapher 1.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Box Option Spread Calculator 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\BW-Plus 1.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Chameleon Flash 1.10.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ClickFix Lite for Adobe Audition 3.02a.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Comic Hi-FI 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Convert PSD to JPG Software 7.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\CRACK NORTON ANTIVIRUS 2005(1).zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Crimson Skies Screensaver 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Cubic Ruler 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Customized Windows Logon 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\CyberLink MediaShow 4.0.1617.6618.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Daniusoft WMA MP3 Converter 2.3.0.23.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Data Tracker for Figurines 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\dedupeIT 1.06.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Dipstick 3.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Disney Movies Screensaver.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Domain Finder Tools 2.07626.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\DSSF Calculator 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\EarMuffs 0.2.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\EMCO OS License Modifier 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Enchanted Toolbar 2.00.0003.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\EZ WebShow 2.0.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\EzMagnifier 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Fast Email Verifier Pro 2.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Firesizer 0.54.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Harmony In My Ears toolbar for Firefox 1.5.0.4.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\HaroldSearchNetworks for IE 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Haxial Calculator 1.2 Beta 1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\HDOB 1.01.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Healthy Life Cookbook 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Hixus Scrollbar Designer 1.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Homemade Facial Moisturizers 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\iOrgSoft WAV Converter 1.6.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Kalimages Basic 1.0.17.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Kaspersky.Internet.Security.6.0.1.402.all.Windows.and.Server2K3.version.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\KeyState 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Label Flow - Label Maker Software 3.4.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\LingvoSoft Suite 2008 English - Albanian 2.1.28.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Log Paper 1.04.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Lokad Safety Stock Calculator 1.5.1171.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\LucidLink Wireless LAN Security 2.22.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Mail Server Pro 3.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Mailing List Studio 3.13.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ManageEngine ServiceDesk Plus 7.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\McAfee.Total.Protection.2007.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\MediaJoin 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Micron iPod Data Recovery 4.8.3.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\MONOGRAM Frame Grabber 1.0.0.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\MP3 CD Burn Magic 7.4.0.10.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\MPI.NET Runtime 1.0.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\n80 n72 6600 Ngage.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\NetFloor Live! 2.0.0.5.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Nod32.v2.12.3.Win.95.98.Me.Espa‡û¸Ol.Spanish.Comercial.Profesional.Monousuario.By.Freeman.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\nod32_2_70_final.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\OGS Notifier 0.18.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\One-Click Opener 0.4.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Oxygen Plan Library 1.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Oxygen SimpleUp 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\PANDA_TITANIUM_2005.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\PCLoupe 1.0.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Photonizer 2005 1.13.0.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\PopScan 4.63.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Print Expander 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\PSTCompactor (Professional Edition) 2.5.5.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Quick Recovery for Microsoft Access 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Rapla 1.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\RealMedia Muxer 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Report Forge 3.0.11.5.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ResumeGrabber Standard 2008 5.0.0.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\SavantFTP 2.1.2.28.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Schedule Password Recovery Key 8.0 build 2514.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ServiceUtility 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Simple Unit Tab Editor 1.4.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Snipperoo 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\SocketWatch 3.5b.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Spring Dream 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Sprintometer 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\StartupPlus WOL 2.0 Build 118.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Surf Icons.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Swift POS 5.3.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Symantec.AntiVirus.Corporate.v9.0.1.1000.FULL.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\symantec.pcanywhere.11.0_german_retail_win_all_[ccb].zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\TheDatabaser 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Time Gain 1.5.0720.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Totwise 2.0.2.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\txt2pdf 9.7.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\UniversalHDTV 1.2.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\UniView 1.65.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Vista Caller-ID 1.0.7 Beta.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\ViviClip Pre-Wash DV Basic 1.00.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\VTC Player 1.11.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\W32.Welchia.Worm Removal Tool 1.06.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\WBIAS 0.81.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Widget World Cup 1.6.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Win Mp3 Merge App 1.2.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Win PC Adress Book 3.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\WinContig 0.80.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\WinKiller 3 3.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\WMon 1.0.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\WordBanker English-Swedish 6.4.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\XenoCrawler Beta 1.0 Build 3223.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\xTang 1.5.1.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\Yahoo Satellite Maps Downloader 4.18.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\YIPI 2.0 beta.zip
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared\_Lizenzschlussel.zip
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\m\shared"
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\m"
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\drivers\srosa.sys"
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\drivers\downld"
Deleted ! - "C:\Documents and Settings\HP_Propri‚taire\Application Data\drivers"
»»»» Supression files in C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\bisoft
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\DateTime4
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\FFC
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\FirtR
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\MuleAppData
Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
»»»» Supression files in C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\0465HI7K\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\0Y9KF0PT\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\3M6P072I\b64[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\3M6P072I\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\4M2ERXRA\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\6I3BFS2J\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\7XPSD1FS\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\945CPJY7\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\945CPJY7\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\95O6V1G3\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\B9B0WKXT\b64[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\B9B0WKXT\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\DMQ07ARH\b64[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\DMQ07ARH\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\EBGEAG4X\b64[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\EBGEAG4X\b64[2].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\EBGEAG4X\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\EBGEAG4X\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\F7EVWZ0M\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SJ0WJRYH\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\HP_Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\VWB2DRJJ\file[1].txt
--------------- [ Registry / Infected keys ] ----------------
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Deleted ! - HKEY_CURRENT_USER\Software\bisoft
Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
Deleted ! - HKEY_CURRENT_USER\Software\FirtR
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flec006.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hldrrr.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfilse.exe
Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupgro.exe
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\FFC
Deleted ! - HKEY_USERS\S-1-5-21-881167365-900127857-875764690-1007\Software\MuleAppData
--------------- [ States / Restarting of services ] ----------------
+- Safe boot mode restored !
+- Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - Type of startup = 3
Ip6Fw - Type of startup = 2
SharedAccess - Type of startup = 2
wuauserv - Type of startup = 2
wscsvc - Type of startup = 2
--------------- [ Cleaning removable drives ] ----------------
+- Informations :
C: - Lecteur fixeD: - Lecteur fixe
+- deleting files :
Deleted ! - D:\autorun.inf
Deleted ! - D:\info.exe
--------------- [ Registry / Mountpoint2 ] ----------------
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e117e0b-6de7-11dc-9fe6-00112f76ba3d}\Shell\AutoRun\command
Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a534d0a2-a272-11dd-9c8e-00112f76ba3d}\Shell\AutoRun\command
--------------- [ Searching Other Infections ] ----------------
Références de comparaison Bagle MD5 :
113ac36b77630a2f67dd6cb7844406a4 C:\WINDOWS\system32\mdelk.exe
113ac36b77630a2f67dd6cb7844406a4 C:\WINDOWS\system32\wintems.exe
Suspect ! - ebe38e2fcd97bfaf184cd5386100b529 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Suspect ! - f5a3e4b4bcf683ebfd3948acfdee3ed2 C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1353\A0262699.exe
Suspect ! - a8440f007fb29127b649917f55a7defe C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1379\A0265052.exe
Suspect ! - 64f497dace34ea0c38569c4c0549fe03 C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1409\A0266625.exe
Suspect ! - ebe38e2fcd97bfaf184cd5386100b529 C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1437\A0269232.exe
Suspect ! - ebe38e2fcd97bfaf184cd5386100b529 C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273437.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273488.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273489.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273497.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273499.exe
Suspect ! - 9c498d9305a5014caf113709499e093a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273501.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273521.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP1439\A0273547.exe
--------------- [ Searching Cracks / Keygen ] ----------------
C:\Documents and Settings\HP_Propri‚taire\Bureau\int‚grales artistes\Jacques Dutronc\Crack Boum Hue.MP3
C:\Documents and Settings\HP_Propri‚taire\Local Settings\Application Data\IM\Animation\firecracker.ima
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert.zip
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Sony.Sound.Forge.7.0 + KeyGen + MP3.Plugin.2.0 + Patch.FR.zip
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Easy Cd-Da Extractor Professional v10.0.2.1 Multilangages Incl-Crack.rar
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack\Armadillo.dll
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack\Consignes.txt
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack\ezcddax.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert\OFFICE XP 2005 SP3 ( word excel access powerpoint frontpage ) FRENCH FRANCAIS no fake cracked by FRELON VERT
C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert\OFFICE XP 2005 SP3 ( word excel access powerpoint frontpage ) FRENCH FRANCAIS no fake cracked by FRELON VERT.ISO
C:\Documents and Settings\HP_Propri‚taire\Mes documents\soundforge70\KeyGen
C:\Documents and Settings\HP_Propri‚taire\Mes documents\soundforge70\KeyGen\keygen.exe
---------------- ! End of report ! ------------------
Configuration: Windows XP Internet Explorer 7.0
Télécharge le fichier d'installation d'HijackThis.
|
Bonjour
|
Bonjour à vous tous, oui tu est bien infectés tu peux faire l'option 2 de findykill et puis mettre un hijackthis comme demander et aussi faire comme dit marie virer tes cracks et keygens si tu ne sais pas ou les trouver je te mets la liste
--------------- [ Searching Cracks / Keygen ] ---------------- C:\Documents and Settings\HP_Propri‚taire\Bureau\int‚grales artistes\Jacques Dutronc\Crack Boum Hue.MP3 C:\Documents and Settings\HP_Propri‚taire\Local Settings\Application Data\IM\Animation\firecracker.ima C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert.zip C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Sony.Sound.Forge.7.0 + KeyGen + MP3.Plugin.2.0 + Patch.FR.zip C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Easy Cd-Da Extractor Professional v10.0.2.1 Multilangages Incl-Crack.rar C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack\Armadillo.dll C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack\Consignes.txt C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Easy Cd-Da Extractor\Crack\ezcddax.exe C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert\OFFICE XP 2005 SP3 ( word excel access powerpoint frontpage ) FRENCH FRANCAIS no fake cracked by FRELON VERT C:\Documents and Settings\HP_Propri‚taire\Mes documents\programmes t‚l‚charg‚s\Office Xp 2005 Sp3 (Word Excel Access Powerpoint Frontpage) French Francais No Fake Cracked By Frelon Vert\OFFICE XP 2005 SP3 ( word excel access powerpoint frontpage ) FRENCH FRANCAIS no fake cracked by FRELON VERT.ISO C:\Documents and Settings\HP_Propri‚taire\Mes documents\soundforge70\KeyGen C:\Documents and Settings\HP_Propri‚taire\Mes documents\soundforge70\KeyGen\keygen.exe ---------------- ! End of report ! ------------------Attention !! la surmultiplication de logiciels de sécurité ne protège pas mieux voire peut engendrer des conflits et des plantages. " mais chacun reste maître de son PC " |
Bonsoir
|