voila les rapports:
otl.txt:
- Code: Tout sélectionner
All processes killed
========== FILES ==========
C:\Documents and Settings\Chouchou\Application Data\pdfforge\res folder moved successfully.
C:\Documents and Settings\Chouchou\Application Data\pdfforge\temp folder moved successfully.
C:\Documents and Settings\Chouchou\Application Data\pdfforge folder moved successfully.
C:\Documents and Settings\Chouchou\Application Data\Search Settings\kb130\temp folder moved successfully.
C:\Documents and Settings\Chouchou\Application Data\Search Settings\kb130 folder moved successfully.
C:\Documents and Settings\Chouchou\Application Data\Search Settings folder moved successfully.
========== OTL ==========
Service HidServ stopped successfully!
Service HidServ deleted successfully!
File C:\WINDOWS\System32\hidserv.dll File not found not found.
Service s24trans stopped successfully!
Service s24trans deleted successfully!
File C:\WINDOWS\System32\DRIVERS\s24trans.sys File not found not found.
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\DOCUME~1\Chouchou\LOCALS~1\Temp\catchme.sys File not found not found.
Registry key HKEY_USERS\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel\ not found.
Registry key HKEY_USERS\S-1-5-21-3478786516-1028448895-2109670324-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3478786516-1028448895-2109670324-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDrives deleted successfully.
Folder C:\Documents and Settings\Chouchou\Application Data\pdfforge\ not found.
Folder C:\Documents and Settings\Chouchou\Application Data\Search Settings\ not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: All Users
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: LocalService
->Temp folder emptied: 65748 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: Chouchou
->Temp folder emptied: 234252 bytes
->Temporary Internet Files folder emptied: 70620670 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 2357 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32768 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 68,00 mb
[EMPTYFLASH]
User: Default User
User: All Users
User: NetworkService
User: LocalService
User: Chouchou
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0,00 mb
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.10.0 log created on 08292010_092852
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
scanxp.txt:
- Code: Tout sélectionner
Bootkit Remover
(c) 2009 eSage Lab
www.esagelab.com
Program version: 1.1.0.0
OS Version: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
System volume is \\.\C:
\\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`f98b7a00
Boot sector MD5 is: 7c47d39b31ef9830828d5f8aa4780dfd
Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 Unknown boot code
Unknown boot code has been found on some of your physical disks.
To inspect the boot code manually, dump the master boot sector:
remover.exe dump <device_name> [output_file]
To disinfect the master boot sector, use the following command:
remover.exe fix <device_name>
Done;
Merci
+