Bonjour,
j'ai copié le rapport et le colle ici,maintenant svp qu'est ce que je dois faire?est-ce cela signifie que le virus est supprimé après avoir suivi cette démarche?Merci pour vos réponses suis dans le besoin
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:16:42, on 14/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\documents and settings\babacar\local settings\application data\mcigkqg.exe
C:\WINDOWS\system32\drivers\Memoire Jeff EYEGHE.exe
C:\WINDOWS\system32\drivers\Memoire Jeff EYEGHE.exe
C:\WINDOWS\system32\drivers\Raila Odinga.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://fr.search.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\SCVVHSOT.exe
O4 - HKCU\..\Run: [mcigkqg] "c:\documents and settings\babacar\local settings\application data\mcigkqg.exe" mcigkqg
O4 - HKCU\..\Run: [] C:\WINDOWS\system32\drivers\Memoire Jeff EYEGHE
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Memoire Jeff EYEGHE.lnk = ?
O4 - Startup: Raila Odinga.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: RealGuide - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/OnlineScanner.cab
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/babacar/LOCALS~1/Temp/msohtml1/01/clip_image002.gif
O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/babacar/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

-------------- UsbFix V2.413.4 ---------------
* User : babacar - BOX1
* Outils mis a jours le 11/12/2008 par Chiquitine29 et Chimay8
* Recherche effectuée à 16:00:59 le 14/12/2008
* Windows Xp - Internet Explorer 6.0.2900.5512
--------------- [ Processus actifs ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\DOCUME~1\babacar\LOCALS~1\Temp\1.tmp\b2e.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
--------------- [ Informations lecteurs ] ----------------
C: - Lecteur fixe
E: - Lecteur amovible
+- Contenu de l'autorun : C:\autorun.inf
;8K2SJ4jfjKd69wwswckAiAk4lKw5dpaae0sfKi3
[AutoRun]
;rrwkLsDs4DJDdw2da5kZdiDww2kOao
open=ph.com
;edJadfflL1wew43KelkikKsLDksr5C28qkDj
shell\open\Command=ph.com
;9a44qj0Kra3cwsI3aww3sjLlo1oipC5Lr8J0ks74ndkAlHwaa36Ki5qZiqSeqKoi4ldrws2w33j90f03KdSAqp54wDwZwi
shell\open\Default=1
;7a3l1jirLfkijaaq3Kqdklwmak3iei1w30wf3q1090sdDliCjSSj37SKLw2K74es39aL4aJcd2w
shell\explore\Command=ph.com
;wiwdSiasja1L7k5k4Jw1o10KkrkdiiaDqkdDwes5lk0aws3Jo3deKkaLa7r3sAA41D0JL28s2wrplep89L0L34Zl0kofkidwd3sqpDlSf
+- Contenu de l'autorun : E:\autorun.inf
;8K2SJ4jfjKd69wwswckAiAk4lKw5dpaae0sfKi3
[AutoRun]
;rrwkLsDs4DJDdw2da5kZdiDww2kOao
open=ph.com
;edJadfflL1wew43KelkikKsLDksr5C28qkDj
shell\open\Command=ph.com
;9a44qj0Kra3cwsI3aww3sjLlo1oipC5Lr8J0ks74ndkAlHwaa36Ki5qZiqSeqKoi4ldrws2w33j90f03KdSAqp54wDwZwi
shell\open\Default=1
;7a3l1jirLfkijaaq3Kqdklwmak3iei1w30wf3q1090sdDliCjSSj37SKLw2K74es39aL4aJcd2w
shell\explore\Command=ph.com
;wiwdSiasja1L7k5k4Jw1o10KkrkdiiaDqkdDwes5lk0aws3Jo3deKkaLa7r3sAA41D0JL28s2wrplep89L0L34Zl0kofkidwd3sqpDlSf
--------------- [ Lecteur C ] ----------------
C: - Lecteur fixe
+- Listing des fichiers présents :
[09/05/2008 00:41][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38][-rahs----] C:\NTDETECT.COM
[03/08/2004 22:38][-rahs----] C:\ph.com
[30/08/2008 12:08][-r-hs----] C:\rs.cmd
[09/05/2008 00:28][---hs----] C:\boot.ini
[14/12/2008 15:46][-r-hs----] C:\autorun.inf
[28/10/2008 15:01][--a------] C:\fixnavi.txt
[28/10/2008 15:01][--a------] C:\cleannavi.txt
[28/10/2008 15:01][--a------] C:\YServer.txt
[28/10/2008 15:01][--a------] C:\UsbFix.txt
[][] C:\pagefile.sys
[][] C:\CONFIG.SYS
[][] C:\IO.SYS
[][] C:\MSDOS.SYS
[][] C:\hiberfil.sys
--------------- [ Lecteur E ] ----------------
E: - Lecteur amovible
+- Listing des fichiers présents :
[27/08/2008 16:05][-r-hs----] E:\ph.com
[27/08/2008 16:05][-r-hs----] E:\2fiji.com
[04/12/2008 22:00][-r-hs----] E:\iplt.pif
[13/08/2008 11:58][-rahs----] E:\log.exe
[13/08/2008 11:58][-rahs----] E:\STDBSTR.exe
[13/08/2008 11:58][-rahs----] E:\STDBDATA.exe
[13/08/2008 11:58][-rahs----] E:\RAMLIST.exe
[13/08/2008 11:58][-rahs----] E:\playqueue.exe
[13/08/2008 11:58][-rahs----] E:\cm0.exe
[13/08/2008 11:58][-rahs----] E:\SETSTOR.exe
[13/08/2008 11:58][-rahs----] E:\Business Plan[1].exe
[13/08/2008 11:58][-rahs----] E:\ph.exe
[13/08/2008 11:58][-rahs----] E:\la reforme du titolo v.exe
[13/08/2008 11:58][-rahs----] E:\CRIM0009.exe
[13/08/2008 11:58][-rahs----] E:\CRIM0005.exe
[13/08/2008 11:58][-rahs----] E:\Photo002.exe
[13/08/2008 11:58][-rahs----] E:\CRIM0004.exe
[13/08/2008 11:58][-rahs----] E:\CRIM0040.exe
[13/08/2008 11:58][-rahs----] E:\autorun.exe
[13/08/2008 11:58][-rahs----] E:\CRIM0010.exe
[13/08/2008 11:58][-rahs----] E:\iplt.exe
[13/08/2008 11:58][-rahs----] E:\jobscvlio.exe
[13/08/2008 11:58][-rahs----] E:\CV AL.exe
[13/08/2008 11:58][-rahs----] E:\CRIM0011.exe
[13/08/2008 11:58][-rahs----] E:\~WRL0001.exe
[13/08/2008 11:58][-rahs----] E:\2fiji.exe
[13/08/2008 11:58][-rahs----] E:\~WRL0005.exe
[13/08/2008 11:58][-rahs----] E:\02 Piste.exe
[13/08/2008 11:58][-rahs----] E:\smss.exe
[13/08/2008 11:58][-rahs----] E:\S‚minaire M‚thodologie.exe
[13/08/2008 11:58][-rahs----] E:\politique de d‚centralisation italienne 1900-2003.exe
[13/08/2008 11:58][-rahs----] E:\La politique de d‚centralisation en Italie.exe
[13/08/2008 11:58][-rahs----] E:\La politique de d‚centralisation en Italie. Td.exe
[13/08/2008 11:58][-rahs----] E:\FISCALITE DES ENTREPRISES.exe
[13/08/2008 11:58][-rahs----] E:\Management Definition et Concepts.exe
[13/08/2008 11:58][-rahs----] E:\Th‚orie Management Taylor & Fayol.exe
[13/08/2008 11:58][-rahs----] E:\puisregard.exe
[13/08/2008 11:58][-rahs----] E:\Management - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\TD de politique de d‚centralisation en Italie.exe
[13/08/2008 11:58][-rahs----] E:\COURS%20COM%20MASTER%20ESUP[1].exe
[13/08/2008 11:58][-rahs----] E:\VOCABULAIRE DE RECHERCHE.exe
[13/08/2008 11:58][-rahs----] E:\‚cole des rh et de la motivation.exe
[13/08/2008 11:58][-rahs----] E:\corrig‚ management.exe
[13/08/2008 11:58][-rahs----] E:\Projet - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\La Motivation.exe
[13/08/2008 11:58][-rahs----] E:\06 Piste 6.exe
[13/08/2008 11:58][-rahs----] E:\Marketing - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES PLAN GENERAL.exe
[13/08/2008 11:58][-rahs----] E:\Gestion des ressources humaines - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - I-VII.exe
[13/08/2008 11:58][-rahs----] E:\Droit fiscal - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - II-VII.exe
[13/08/2008 11:58][-rahs----] E:\Gestion de projet - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - III-VII.exe
[13/08/2008 11:58][-rahs----] E:\Financement de projet - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - IV-VII.exe
[13/08/2008 11:58][-rahs----] E:\Analyse financiŠre - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES V-VII.exe
[13/08/2008 11:58][-rahs----] E:\Concurrence ‚conomique - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\02 Piste (4).exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES DROIT DES ASSURANCES - REGLEMENT DU SINISTRE - VI-VII.exe
[13/08/2008 11:58][-rahs----] E:\Droit de la concurrence - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - VII-VII.exe
[13/08/2008 11:58][-rahs----] E:\Plaquette_IJF2-_Technique_contractuelle.exe
[13/08/2008 11:58][-rahs----] E:\comptaetfiscalitedentreprise.exe
[13/08/2008 11:58][-rahs----] E:\Droit fiscal en France - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\tude de march‚ - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\Droit du travail - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\50 cent ft justin timberlake - she wants it (ayo technology).exe
[13/08/2008 11:58][-rahs----] E:\11 Confessions Nocturnes (feat. Vitaa).exe
[13/08/2008 11:58][-rahs----] E:\05 Piste 5.exe
[13/08/2008 11:58][-rahs----] E:\11 Piste 11.exe
[13/08/2008 11:58][-rahs----] E:\13 Piste 13.exe
[13/08/2008 11:58][-rahs----] E:\15 Piste 15.exe
[13/08/2008 11:58][-rahs----] E:\01 Piste 1.exe
[13/08/2008 11:58][-rahs----] E:\02 Piste 2.exe
[13/08/2008 11:58][-rahs----] E:\03 Piste 3.exe
[13/08/2008 11:58][-rahs----] E:\06 Piste 6_New1.exe
[13/08/2008 11:58][-rahs----] E:\05 Piste 5_New1.exe
[13/08/2008 11:58][-rahs----] E:\12 Piste 12.exe
[13/08/2008 11:58][-rahs----] E:\01 Piste 1_New1.exe
[13/08/2008 11:58][-rahs----] E:\02 Piste 2_New1.exe
[13/08/2008 11:58][-rahs----] E:\03 Piste 3_New1.exe
[13/08/2008 11:58][-rahs----] E:\04 Piste 4.exe
[13/08/2008 11:58][-rahs----] E:\09 Piste 9.exe
[13/08/2008 11:58][-rahs----] E:\14 Piste 14.exe
[13/08/2008 11:58][-rahs----] E:\19 Piste 19.exe
[13/08/2008 11:58][-rahs----] E:\03 Piste 3_New2.exe
[13/08/2008 11:58][-rahs----] E:\04 Piste 4_New1.exe
[13/08/2008 11:58][-rahs----] E:\08 Piste 8.exe
[13/08/2008 11:58][-rahs----] E:\14 Piste 14_New1.exe
[13/08/2008 11:58][-rahs----] E:\Akon - Keep On Calling.exe
[13/08/2008 11:58][-rahs----] E:\Akon~Sorry, blame it on me..exe
[13/08/2008 11:58][-rahs----] E:\akon_feat_snoop_dogg_-_i_wanna.exe
[13/08/2008 11:58][-rahs----] E:\Shaggy_-_Angel.exe
[13/08/2008 11:58][-rahs----] E:\BUSTA RHYMES - Together.exe
[13/08/2008 11:58][-rahs----] E:\Baro Fod‚.exe
[13/08/2008 11:58][-rahs----] E:\Finance d'entreprise - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\Droit p‚nal - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\Ragga - String color(1).exe
[13/08/2008 11:58][-rahs----] E:\Alicia Keys - Karma (Reggaeton Remix).exe
[13/08/2008 11:58][-rahs----] E:\nina sky & noreaga - untitled - 06-07-04 - oye me canto.exe
[13/08/2008 11:58][-rahs----] E:\somme excel.exe
[13/08/2008 11:58][-rahs----] E:\Sla‹ - 04 - FlorilŠge - La DerniŠre Danse (Ne Rentre Pas Che.exe
[13/08/2008 11:58][-rahs----] E:\Contr“le de gestion - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\Concurrence d‚loyale - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\Proc‚dure p‚nale - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\Strat‚gie d'entreprise - Wikip‚dia.exe
[13/08/2008 11:58][-rahs----] E:\FISCALITE DES ENTREPRISES[1].exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Amortissement d‚gressif.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Calculs non r‚f‚renc‚s.exe
[13/08/2008 11:58][-rahs----] E:\Mbaye Diene Faye - Blocass.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Amortissement lin‚aire (2Šme m‚thode).exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Copier - Coller.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Fonctions complexes.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Les donn‚es num‚riques.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Longueur de texte.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Qu'est-ce que c'est.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Somme … capitaliser.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Poign‚e de Recopie.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Selon une liste.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - PremiŠres formules.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - NB_SI.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - Les libell‚s.exe
[13/08/2008 11:58][-rahs----] E:\Excel Exercice et cours - L'environnement de travail.exe
[13/08/2008 11:58][-rahs----] E:\HijackThis.exe
[14/12/2008 15:46][-r-h-----] E:\autorun.inf
[10/11/2008 20:14][--a------] E:\FISCALITE DES ENTREPRISES[1].txt
--------------- [ Registre / Startup ] ----------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.google.com"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
SuperCopier2.exe=C:\Program Files\SuperCopier2\SuperCopier2.exe
MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
Yahoo! Pager="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
ares="C:\Program Files\Ares\Ares.exe" -h
mcigkqg="c:\documents and settings\babacar\local settings\application data\mcigkqg.exe" mcigkqg
<NO NAME>=C:\WINDOWS\system32\drivers\Memoire Jeff EYEGHE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
Installed=1
NoChange=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=
--------------- [ Registre / Mountpoint2 ] ----------------
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b507be0-3e2b-11dd-8720-0010b5a01a02}\Shell\AutoRun\command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b507be0-3e2b-11dd-8720-0010b5a01a02}\Shell\explore\Command
Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b507be0-3e2b-11dd-8720-0010b5a01a02}\Shell\open\Command
--------------- [ Nettoyage des disques ] ----------------
Supprimé ! - [27/08/2008 16:05][-r-hs----] C:\WINDOWS\system32\ckvo.exe
Supprimé ! - [14/12/2008 09:33][---------] C:\WINDOWS\system32\ckvo0.dll
Supprimé ! - [14/12/2008 09:43][-r-hs----] C:\WINDOWS\system32\ckvo1.dll
Supprimé ! - [05/07/2008 16:35][--a------] "C:\WINDOWS\system32\drivers\Raila Odinga.exe"
Supprimé ! - [14/12/2008 09:34][--a------] "C:\DOCUME~1\babacar\LOCALS~1\Temp\help.exe"
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
E:\autorun.inf moved successfully.
E:\iplt.pif moved successfully.
E:\log.exe moved successfully.
E:\STDBSTR.exe moved successfully.
E:\STDBDATA.exe moved successfully.
E:\RAMLIST.exe moved successfully.
E:\playqueue.exe moved successfully.
E:\cm0.exe moved successfully.
E:\SETSTOR.exe moved successfully.
E:\Business Plan[1].exe moved successfully.
E:\ph.exe moved successfully.
E:\la reforme du titolo v.exe moved successfully.
E:\CRIM0009.exe moved successfully.
E:\CRIM0005.exe moved successfully.
E:\Photo002.exe moved successfully.
E:\CRIM0004.exe moved successfully.
E:\CRIM0040.exe moved successfully.
E:\CRIM0010.exe moved successfully.
E:\iplt.exe moved successfully.
E:\jobscvlio.exe moved successfully.
E:\CV AL.exe moved successfully.
E:\CRIM0011.exe moved successfully.
E:\~WRL0001.exe moved successfully.
E:\2fiji.exe moved successfully.
E:\~WRL0005.exe moved successfully.
E:\02 Piste.exe moved successfully.
File/Folder E:\S‚minaire M‚thodologie.exe not found.
File/Folder E:\politique de d‚centralisation italienne 1900-2003.exe not found.
File/Folder E:\La politique de d‚centralisation en Italie.exe not found.
File/Folder E:\La politique de d‚centralisation en Italie. Td.exe not found.
E:\FISCALITE DES ENTREPRISES.exe moved successfully.
E:\Management Definition et Concepts.exe moved successfully.
File/Folder E:\Th‚orie Management Taylor & Fayol.exe not found.
E:\puisregard.exe moved successfully.
File/Folder E:\Management - Wikip‚dia.exe not found.
File/Folder E:\TD de politique de d‚centralisation en Italie.exe not found.
E:\COURS%20COM%20MASTER%20ESUP[1].exe moved successfully.
E:\VOCABULAIRE DE RECHERCHE.exe moved successfully.
File/Folder E:\‚cole des rh et de la motivation.exe not found.
File/Folder E:\corrig‚ management.exe not found.
File/Folder E:\Projet - Wikip‚dia.exe not found.
E:\La Motivation.exe moved successfully.
E:\06 Piste 6.exe moved successfully.
File/Folder E:\Marketing - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES PLAN GENERAL.exe not found.
File/Folder E:\Gestion des ressources humaines - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - I-VII.exe not found.
File/Folder E:\Droit fiscal - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - II-VII.exe not found.
File/Folder E:\Gestion de projet - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - III-VII.exe not found.
File/Folder E:\Financement de projet - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - IV-VII.exe not found.
File/Folder E:\Analyse financiŠre - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES V-VII.exe not found.
File/Folder E:\Concurrence ‚conomique - Wikip‚dia.exe not found.
E:\02 Piste (4).exe moved successfully.
File/Folder E:\JURISQUES DROIT DES ASSURANCES - REGLEMENT DU SINISTRE - VI-VII.exe not found.
File/Folder E:\Droit de la concurrence - Wikip‚dia.exe not found.
File/Folder E:\JURISQUES SUPPORT DE COURS DE DROIT DES ASSURANCES - VII-VII.exe not found.
E:\Plaquette_IJF2-_Technique_contractuelle.exe moved successfully.
E:\comptaetfiscalitedentreprise.exe moved successfully.
File/Folder E:\Droit fiscal en France - Wikip‚dia.exe not found.
File/Folder E:\tude de march‚ - Wikip‚dia.exe not found.
File/Folder E:\Droit du travail - Wikip‚dia.exe not found.
E:\50 cent ft justin timberlake - she wants it (ayo technology).exe moved successfully.
E:\11 Confessions Nocturnes (feat. Vitaa).exe moved successfully.
E:\05 Piste 5.exe moved successfully.
E:\Raila Odinga.exe moved successfully.
E:\11 Piste 11.exe moved successfully.
E:\13 Piste 13.exe moved successfully.
E:\15 Piste 15.exe moved successfully.
E:\01 Piste 1.exe moved successfully.
E:\02 Piste 2.exe moved successfully.
E:\03 Piste 3.exe moved successfully.
E:\06 Piste 6_New1.exe moved successfully.
E:\05 Piste 5_New1.exe moved successfully.
E:\12 Piste 12.exe moved successfully.
E:\01 Piste 1_New1.exe moved successfully.
E:\02 Piste 2_New1.exe moved successfully.
E:\03 Piste 3_New1.exe moved successfully.
E:\04 Piste 4.exe moved successfully.
E:\09 Piste 9.exe moved successfully.
E:\14 Piste 14.exe moved successfully.
E:\19 Piste 19.exe moved successfully.
E:\03 Piste 3_New2.exe moved successfully.
E:\04 Piste 4_New1.exe moved successfully.
E:\08 Piste 8.exe moved successfully.
E:\14 Piste 14_New1.exe moved successfully.
E:\Akon - Keep On Calling.exe moved successfully.
E:\Akon~Sorry, blame it on me..exe moved successfully.
E:\akon_feat_snoop_dogg_-_i_wanna.exe moved successfully.
E:\Shaggy_-_Angel.exe moved successfully.
E:\BUSTA RHYMES - Together.exe moved successfully.
File/Folder E:\Baro Fod‚.exe not found.
File/Folder E:\Finance d'entreprise - Wikip‚dia.exe not found.
File/Folder E:\Droit p‚nal - Wikip‚dia.exe not found.
File/Folder E:\Ragga - String color(1).exe not found.
E:\Alicia Keys - Karma (Reggaeton Remix).exe moved successfully.
E:\nina sky & noreaga - untitled - 06-07-04 - oye me canto.exe moved successfully.
E:\somme excel.exe moved successfully.
File/Folder E:\Sla‹ - 04 - FlorilŠge - La DerniŠre Danse (Ne Rentre Pas Che.exe not found.
File/Folder E:\Contr“le de gestion - Wikip‚dia.exe not found.
File/Folder E:\Concurrence d‚loyale - Wikip‚dia.exe not found.
File/Folder E:\Proc‚dure p‚nale - Wikip‚dia.exe not found.
File/Folder E:\Strat‚gie d'entreprise - Wikip‚dia.exe not found.
E:\FISCALITE DES ENTREPRISES[1].exe moved successfully.
File/Folder E:\Excel Exercice et cours - Amortissement d‚gressif.exe not found.
File/Folder E:\Excel Exercice et cours - Calculs non r‚f‚renc‚s.exe not found.
E:\Mbaye Diene Faye - Blocass.exe moved successfully.
File/Folder E:\Excel Exercice et cours - Amortissement lin‚aire (2Šme m‚thode).exe not found.
E:\Excel Exercice et cours - Copier - Coller.exe moved successfully.
E:\Excel Exercice et cours - Fonctions complexes.exe moved successfully.
File/Folder E:\Excel Exercice et cours - Les donn‚es num‚riques.exe not found.
E:\Excel Exercice et cours - Longueur de texte.exe moved successfully.
E:\Excel Exercice et cours - Qu'est-ce que c'est.exe moved successfully.
File/Folder E:\Excel Exercice et cours - Somme … capitaliser.exe not found.
File/Folder E:\Excel Exercice et cours - Poign‚e de Recopie.exe not found.
E:\Excel Exercice et cours - Selon une liste.exe moved successfully.
File/Folder E:\Excel Exercice et cours - PremiŠres formules.exe not found.
E:\Excel Exercice et cours - NB_SI.exe moved successfully.
File/Folder E:\Excel Exercice et cours - Les libell‚s.exe not found.
E:\Excel Exercice et cours - L'environnement de travail.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\babacar\LOCALS~1\Temp\nsw4.tmp\System.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\babacar\LOCALS~1\Temp\nsn2.tmp\System.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\babacar\LOCALS~1\Temp\etilqs_cbsAN0tI3F6LWZyUD0Wp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\babacar\LOCALS~1\Temp\Perflib_Perfdata_960.dat scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_79c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12142008_191311
Files moved on Reboot...
DllUnregisterServer procedure not found in C:\DOCUME~1\babacar\LOCALS~1\Temp\nsw4.tmp\System.dll
C:\DOCUME~1\babacar\LOCALS~1\Temp\nsw4.tmp\System.dll NOT unregistered.
C:\DOCUME~1\babacar\LOCALS~1\Temp\nsw4.tmp\System.dll moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\babacar\LOCALS~1\Temp\nsn2.tmp\System.dll
C:\DOCUME~1\babacar\LOCALS~1\Temp\nsn2.tmp\System.dll NOT unregistered.
C:\DOCUME~1\babacar\LOCALS~1\Temp\nsn2.tmp\System.dll moved successfully.
File C:\DOCUME~1\babacar\LOCALS~1\Temp\etilqs_cbsAN0tI3F6LWZyUD0Wp not found!
File C:\DOCUME~1\babacar\LOCALS~1\Temp\Perflib_Perfdata_960.dat not found!
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_79c.dat not found!
C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\babacar\Local Settings\Application Data\Mozilla\Firefox\Profiles\ko7u3osl.default\urlclassifier3.sqlite moved successfully.
je vous ai envoyé le rapport du contenu log.txt hier soir,et je suis toujours à votre attente,vu que le virus y est toujours
merci