OnlyInhuman
Participant
Nombre d'articles : 15

EDIT : Les deux liens m’amènent à télécharger un même logiciel : ZHPDiag2 et non le ZHPdiag de Nicolas…
Voici le résultat de la suppression. Juste, à la fin de la supression, en affichant les résultats j’ai aussi cette fenêtre qui est apparue : Erreur des dossiers compressés : Fichier introuvable ou lecture non autorisée.

Je vais faire les deux autres manip…

Spoiler for n0aqd6y9

############################## | UsbFix V 7.152 | [Suppression]

Utilisateur: CleCle (Administrateur) # CLECLE-PC
Mis à jour le 20/11/2013 par El Desaparecido – Team SosVirus
Lancé à 11:39:03 | 07/12/2013

Site Web : http://www.usbfix.net” onclick=”window.open(this.href);return false;
Forum : https://www.sosvirus.net/” onclick=”window.open(this.href);return false;
Upload Malware : upload_malware.php
Contact : http://www.usbfix.net/contact/” onclick=”window.open(this.href);return false;

PC: ASUSTeK Computer Inc. (K52Je)
CPU: Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz
RAM -> [Total : 3949 | Free : 1733]
Bios: American Megatrends Inc.
Boot: Normal boot

OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16736
WB: Google Chrome : 31.0.1650.63

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Avira Desktop [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
AS: Malwarebytes' Anti-Malware : 1.51.0.1074
FW: Windows FireWall Service [Enabled]

C: (%systemdrive%) -> Disque fixe # 149 Go (60 Go libre(s) – 40%) [OS] # NTFS
D: -> Disque fixe # 426 Go (426 Go libre(s) – 100%) [DATA] # NTFS
E: -> CD-ROM
F: -> Disque fixe # 466 Go (258 Go libre(s) – 55%) [TOSHIBA EXT] # NTFS
G: -> Disque amovible # 2 Go (2 Go libre(s) – 96%) [JIN-DEVIL] # FAT

################## | Processus Stoppés |

Stoppé! C:Program Files (x86)AviraAntiVir Desktopsched.exe (ID: 1612 |ParentID: 568)
Stoppé! C:Program Files (x86)AviraAntiVir Desktopavguard.exe (ID: 1852 |ParentID: 568)
Stoppé! C:Program Files (x86)AviraAntiVir Desktopavgnt.exe (ID: 3720 |ParentID: 3308)
Stoppé! C:Program Files (x86)AviraAntiVir Desktopavshadow.exe (ID: 2644 |ParentID: 1852)
Stoppé! C:program files (x86)aviraantivir desktopavcenter.exe (ID: 2552 |ParentID: 3720)
Stoppé! C:Windowsexplorer.exe (ID: 4916 |ParentID: 880)
Stoppé! C:WindowsMicrosoft.NetFramework64v3.0WPFPresentationFontCache.exe (ID: 5928 |ParentID: 568)
Stoppé! C:WindowsSystem32rundll32.exe (ID: 6660 |ParentID: 696)
Stoppé! C:WindowsSystem32WUDFHost.exe (ID: 5936 |ParentID: 968)
Stoppé! C:Windowssystem32SearchIndexer.exe (ID: 6116 |ParentID: 568)
Stoppé! C:Program Files (x86)IntelIntel(R) Management Engine ComponentsLMSLMS.exe (ID: 4844 |ParentID: 568)
Stoppé! C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE (ID: 3536 |ParentID: 568)
Stoppé! C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe (ID: 4544 |ParentID: 3536)
Stoppé! C:Program FilesWindows Media Playerwmpnetwk.exe (ID: 5424 |ParentID: 568)
Stoppé! C:WindowsSystem32spoolsv.exe (ID: 856 |ParentID: 568)
Stoppé! C:Program Files (x86)Common FilesAppleMobile Device SupportAppleMobileDeviceService.exe (ID: 1184 |ParentID: 568)
Stoppé! C:Program Files (x86)AdobeReader 10.0ReaderAcroRd32.exe (ID: 3656 |ParentID: 4916)
Stoppé! C:Program Files (x86)AdobeReader 10.0ReaderAcroRd32.exe (ID: 3188 |ParentID: 3656)
Stoppé! C:Windowssystem32DllHost.exe (ID: 3640 |ParentID: 696)
Stoppé! C:WindowsSysWOW64NOTEPAD.EXE (ID: 6308 |ParentID: 4664)
Stoppé! C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 6592 |ParentID: 4916)
Stoppé! C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 6908 |ParentID: 6592)
Stoppé! C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 4860 |ParentID: 6592)
Stoppé! C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 4176 |ParentID: 6592)
Stoppé! C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 3084 |ParentID: 6592)
Stoppé! C:Program Files (x86)GoogleChromeApplicationchrome.exe (ID: 2736 |ParentID: 6592)
Stoppé! C:Program FilesMicrosoft OfficeOffice15WINWORD.EXE (ID: 4320 |ParentID: 4916)

################## | Regedit Run |

04 – HKLMSOFTWARE | Run : [UpdateLBPShortCut] – “C:Program Files (x86)CyberLinkLabelPrintMUITransferMUIStartMenu.exe” “C:Program Files (x86)CyberLinkLabelPrint” UpdateWithCreateOnce “SoftwareCyberLinkLabelPrint2.5”
04 – HKLMSOFTWARE | Run : [UpdateP2GoShortCut] – “C:Program Files (x86)CyberLinkPower2GoMUITransferMUIStartMenu.exe” “C:Program Files (x86)CyberLinkPower2Go” UpdateWithCreateOnce “SOFTWARECyberLinkPower2Go6.0”
04 – HKLMSOFTWARE | Run : [Boingo Wi-Fi] – “C:Program Files (x86)BoingoBoingo Wi-FiBoingo.lnk”
04 – HKLMSOFTWARE | Run : [StartCCC] – “C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe” MSRun
04 – HKLMSOFTWARE | Run : [ATKOSD2] – C:Program Files (x86)ASUSATK PackageATKOSD2ATKOSD2.exe
04 – HKLMSOFTWARE | Run : [ATKMEDIA] – C:Program Files (x86)ASUSATK PackageATK MediaDMedia.exe
04 – HKLMSOFTWARE | Run : [HControlUser] – C:Program Files (x86)ASUSATK PackageATK HotkeyHControlUser.exe
04 – HKLMSOFTWARE | Run : [Wireless Console 3] – C:Program Files (x86)ASUSWireless Console 3wcourier.exe
04 – HKLMSOFTWARE | Run : [SwitchBoard] – C:Program Files (x86)Common FilesAdobeSwitchBoardSwitchBoard.exe
04 – HKLMSOFTWARE | Run : [AdobeCS5ServiceManager] – “C:Program Files (x86)Common FilesAdobeCS5ServiceManagerCS5ServiceManager.exe” -launchedbylogin
04 – HKLMSOFTWARE | Run : [NPSStartup] –
04 – HKLMSOFTWARE | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
04 – HKLMSOFTWARE | Run : [APSDaemon] – “C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLMSOFTWARE | Run : [avgnt] – “C:Program Files (x86)AviraAntiVir Desktopavgnt.exe” /min
04 – HKLMSOFTWARE | Run : [QuickTime Task] – “C:Program Files (x86)QuickTimeQTTask.exe” -atboottime
04 – HKLMSOFTWARE | Run : [SunJavaUpdateSched] – “C:Program Files (x86)Common FilesJavaJava Updatejusched.exe”
04 – HKLMSOFTWARE | Run : [iTunesHelper] – “C:Program Files (x86)iTunesiTunesHelper.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [UpdateLBPShortCut] – “C:Program Files (x86)CyberLinkLabelPrintMUITransferMUIStartMenu.exe” “C:Program Files (x86)CyberLinkLabelPrint” UpdateWithCreateOnce “SoftwareCyberLinkLabelPrint2.5”
04 – HKLMSOFTWAREwow6432Node | Run : [UpdateP2GoShortCut] – “C:Program Files (x86)CyberLinkPower2GoMUITransferMUIStartMenu.exe” “C:Program Files (x86)CyberLinkPower2Go” UpdateWithCreateOnce “SOFTWARECyberLinkPower2Go6.0”
04 – HKLMSOFTWAREwow6432Node | Run : [Boingo Wi-Fi] – “C:Program Files (x86)BoingoBoingo Wi-FiBoingo.lnk”
04 – HKLMSOFTWAREwow6432Node | Run : [StartCCC] – “C:Program Files (x86)ATI TechnologiesATI.ACECore-StaticCLIStart.exe” MSRun
04 – HKLMSOFTWAREwow6432Node | Run : [ATKOSD2] – C:Program Files (x86)ASUSATK PackageATKOSD2ATKOSD2.exe
04 – HKLMSOFTWAREwow6432Node | Run : [ATKMEDIA] – C:Program Files (x86)ASUSATK PackageATK MediaDMedia.exe
04 – HKLMSOFTWAREwow6432Node | Run : [HControlUser] – C:Program Files (x86)ASUSATK PackageATK HotkeyHControlUser.exe
04 – HKLMSOFTWAREwow6432Node | Run : [Wireless Console 3] – C:Program Files (x86)ASUSWireless Console 3wcourier.exe
04 – HKLMSOFTWAREwow6432Node | Run : [SwitchBoard] – C:Program Files (x86)Common FilesAdobeSwitchBoardSwitchBoard.exe
04 – HKLMSOFTWAREwow6432Node | Run : [AdobeCS5ServiceManager] – “C:Program Files (x86)Common FilesAdobeCS5ServiceManagerCS5ServiceManager.exe” -launchedbylogin
04 – HKLMSOFTWAREwow6432Node | Run : [NPSStartup] –
04 – HKLMSOFTWAREwow6432Node | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [APSDaemon] – “C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [avgnt] – “C:Program Files (x86)AviraAntiVir Desktopavgnt.exe” /min
04 – HKLMSOFTWAREwow6432Node | Run : [QuickTime Task] – “C:Program Files (x86)QuickTimeQTTask.exe” -atboottime
04 – HKLMSOFTWAREwow6432Node | Run : [SunJavaUpdateSched] – “C:Program Files (x86)Common FilesJavaJava Updatejusched.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [iTunesHelper] – “C:Program Files (x86)iTunesiTunesHelper.exe”
04 – HKLMSOFTWARE | RunOnce : [] –
04 – HKLMSOFTWAREwow6432Node | RunOnce : [] –
04 – HKUS-1-5-19SOFTWARE | Run : [Sidebar] – %ProgramFiles%Windows SidebarSidebar.exe /autoRun
04 – HKUS-1-5-20SOFTWARE | Run : [Sidebar] – %ProgramFiles%Windows SidebarSidebar.exe /autoRun
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [msnmsgr] – “C:Program Files (x86)Windows LiveMessengermsnmsgr.exe” /background
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [EA Core] – “C:Program Files (x86)Electronic ArtsEADMCore.exe” -silent
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [AdobeBridge] –
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [Skype] – “C:Program Files (x86)SkypePhoneSkype.exe” /minimized /regrun
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [cacaoweb] – “C:UsersCleCleAppDataRoamingcacaowebcacaoweb.exe” -noplayer
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [wqknxfwfzv] – wscript.exe //B “C:UsersCleCleAppDataLocalTempwqknxfwfzv..vbs”
04 – HKUS-1-5-21-1501487328-2378481731-598642488-1001SOFTWARE | Run : [Sidebar] – C:Program FilesWindows Sidebarsidebar.exe /autoRun
04 – HKUS-1-5-19SOFTWARE | RunOnce : [mctadmin] – C:WindowsSystem32mctadmin.exe
04 – HKUS-1-5-20SOFTWARE | RunOnce : [mctadmin] – C:WindowsSystem32mctadmin.exe

################## | Recherche générique |

Supprimé! C:UsersCleCleAppDataLocalTempwqknxfwfzv..vbs
Supprimé! C:UsersCleCleAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupwqknxfwfzv..vbs
Non supprimé ! G:wqknxfwfzv..vbs
Supprimé! G:Maths TD2.lnk
Supprimé! G:Chap 1 maths.lnk
Supprimé! G:Chap 2 maths.lnk
Supprimé! G:Maths TD1.lnk
Supprimé! G:2_Histologie_2013.lnk
Supprimé! G:1_Cytologie_2013.lnk
Supprimé! G:Séjour à Najac PowerPoint.lnk
Supprimé! G:Ecole.lnk
Supprimé! G:CHAPITRE I.lnk
Supprimé! G:ChapIII-2013.lnk
Supprimé! G:Exposé.lnk
Supprimé! G:Article El Pais Musica.lnk
Supprimé! G:Méiose et crossing over.lnk
Supprimé! G:donde-la-familia-real.lnk
Supprimé! G:Présentation.lnk
Supprimé! G:arbol-genealogico-de-la-familia-del-rey.lnk
Supprimé! G:Premier travail – Redes sociales.lnk
Supprimé! G:20131121 152743.lnk
Supprimé! G:Compta.lnk
Supprimé! G:A imprimer.lnk
Supprimé! G:Info.lnk
Supprimé! G:Nouveau dossier.lnk
Supprimé! C:UsersCleCleAppDataRoaminginstall
Supprimé! C:UsersCleCleAppDataLocalTempCleCle7
Supprimé! C:UsersCleCleAppDataLocalTempCleCle8
Supprimé! C:UsersCleCleAppDataLocalTempavgnt.exe
Non supprimé ! F:autorun.inf

(!) Fichiers temporaires supprimés.

################## | Référence de comparaison MD5 |

Md5 : 0F01571A3E4C71EB4313175AAE86488E -> C:UsersCleCleAppDataRoaminginstallserver.exe
Md5 : D41D8CD98F00B204E9800998ECF8427E -> C:UsersCleCleAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupwqknxfwfzv..vbs
Md5 : D41D8CD98F00B204E9800998ECF8427E -> C:UsersCleCleAppDataLocalTempwqknxfwfzv..vbs
Md5 : D41D8CD98F00B204E9800998ECF8427E -> G:wqknxfwfzv..vbs
Md5 : D41D8CD98F00B204E9800998ECF8427E -> C:UsersCleCleAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupwqknxfwfzv..vbs

################## | Comparaison MD5 |

Supprimé! Md5 : 0F01571A3E4C71EB4313175AAE86488E -> C:WindowsMicrosoft.NETFrameworkv2.0.50727AppLaunch.exe
Non supprimé ! Md5 : D41D8CD98F00B204E9800998ECF8427E -> G:wqknxfwfzv..vbs

################## | Registre |

Réparé ! HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer|NoActiveDesktop -> 0
Réparé ! HKLMSOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer|NoActiveDesktopChanges -> 0
Supprimé! HKUS-1-5-21-1501487328-2378481731-598642488-1001SoftwareMicrosoftWindowsCurrentVersionRun|wqknxfwfzv

################## | Listing |

[22/08/2012 – 09:52:59 | SHD ] C:$Recycle.Bin
[05/07/2011 – 21:57:25 | D ] C:ASUS.DAT
[10/07/2011 – 13:52:32 | SHD ] C:Boot
[20/11/2010 – 13:40:07 | RASH | 383786] C:bootmgr
[29/07/2009 – 07:03:37 | RASH | 8192] C:BOOTSECT.BAK
[08/12/2010 – 21:29:56 | N | 15398] C:devlist.txt
[14/07/2009 – 06:08:56 | SHD ] C:Documents and Settings
[07/07/2011 – 17:27:39 | N | 20] C:dpi.txt
[08/12/2010 – 21:17:21 | D ] C:eSupport
[08/12/2010 – 21:29:55 | N | 9] C:Finish.log
[26/08/2012 – 13:25:38 | D ] C:found.000
[12/11/2013 – 18:09:12 | D ] C:found.001
[20/11/2013 – 17:48:22 | D ] C:found.002
[07/12/2013 – 10:37:34 | ASH | 3105259520] C:hiberfil.sys
[08/12/2010 – 21:01:55 | D ] C:Intel
[13/07/2010 – 09:57:31 | N | 2097152] C:K52Je.BIN
[02/06/2010 – 03:42:23 | N | 2097152] C:K52Jr.BIN
[05/08/2010 – 14:07:29 | N | 19] C:K52JR_K62JR_K52JE_WIN7.70
[12/05/2010 – 12:00:23 | N | 2097152] C:K62Jr.BIN
[18/09/2011 – 14:43:02 | RHD ] C:MSOCache
[07/12/2013 – 10:37:36 | ASH | 4140347392] C:pagefile.sys
[08/12/2010 – 06:52:28 | N | 233] C:Pass.txt
[14/07/2009 – 04:20:08 | D ] C:PerfLogs
[03/12/2013 – 19:09:54 | D ] C:Program Files
[29/11/2013 – 18:10:43 | D ] C:Program Files (x86)
[03/12/2013 – 19:09:54 | HD ] C:ProgramData
[05/07/2011 – 21:53:24 | SHD ] C:Recovery
[05/08/2010 – 14:07:29 | N | 21] C:RECOVERY.DAT
[08/12/2010 – 21:17:17 | N | 90] C:setup.log
[13/05/2006 – 17:22:24 | N | 5] C:store.log
[07/12/2013 – 10:50:13 | SHD ] C:System Volume Information
[08/07/2011 – 18:59:01 | D ] C:temp
[07/12/2013 – 11:44:15 | D ] C:UsbFix
[07/12/2013 – 11:44:33 | A | 13744] C:UsbFix [Clean 1] CLECLE-PC.txt
[07/12/2013 – 11:20:04 | N | 18737] C:UsbFix [Scan 1] CLECLE-PC.txt
[05/07/2011 – 21:54:59 | RD ] C:Users
[20/10/2013 – 07:39:22 | D ] C:Windows
[05/07/2011 – 21:56:08 | SHDC ] D:$RECYCLE.BIN
[21/02/2013 – 21:52:40 | SHDC ] D:System Volume Information
[19/09/2012 – 18:49:24 | SHD ] F:$RECYCLE.BIN
[15/09/2011 – 05:12:14 | N | 80] F:autorun.inf
[01/12/2013 – 22:45:54 | D ] F:CLECLE-PC
[19/09/2012 – 18:49:07 | D ] F:Cours
[22/12/2012 – 19:24:10 | D ] F:images
[01/05/2013 – 14:20:06 | N | 347509] F:img033.jpg
[24/03/2012 – 01:00:14 | D ] F:lang
[12/10/2013 – 13:30:00 | D ] F:Maxime
[09/09/2012 – 16:22:42 | N | 528] F:MediaID.bin
[22/12/2012 – 19:26:46 | D ] F:Musique
[08/09/2013 – 13:17:01 | D ] F:Photos
[26/09/2013 – 18:51:00 | D ] F:Photos portable
[12/10/2013 – 13:29:41 | D ] F:Purpan
[01/05/2013 – 09:14:05 | SHD ] F:RECYCLER
[12/10/2013 – 13:29:53 | D ] F:Saliège
[22/12/2012 – 19:24:11 | D ] F:Sample Pictures
[12/10/2013 – 13:29:57 | D ] F:Sciences Po
[27/01/2012 – 07:28:54 | N | 16022] F:Software Offer.hta
[01/12/2013 – 23:46:29 | SHD ] F:System Volume Information
[22/12/2012 – 19:24:12 | RASH | 5120] F:Thumbs.db
[16/05/2011 – 07:40:50 | N | 9518] F:TMP.ico
[16/05/2011 – 07:40:50 | N | 1244] F:Toshiba Places.html
[15/09/2011 – 03:20:04 | N | 5599808] F:TOSHIBA STOR.E BASICS.pdf
[09/09/2012 – 16:47:07 | D ] F:WindowsImageBackup
[14/09/2013 – 09:26:04 | N | 241771] G:Maths TD2.pdf
[14/09/2013 – 09:24:00 | N | 6545062] G:Chap 1 maths.pdf
[14/09/2013 – 09:24:46 | N | 5323562] G:Chap 2 maths.pdf
[14/09/2013 – 09:26:00 | N | 237693] G:Maths TD1.pdf
[02/10/2013 – 09:56:46 | N | 8484461] G:2_Histologie_2013.pdf
[02/10/2013 – 09:56:20 | N | 5199157] G:1_Cytologie_2013.pdf
[19/09/2013 – 23:19:54 | N | 31604899] G:Séjour à Najac PowerPoint.odp
[22/09/2013 – 17:49:44 | N | 73242] G:wqknxfwfzv..vbs
[03/10/2013 – 15:38:26 | D ] G:Compta
[22/09/2013 – 21:20:26 | D ] G:A imprimer
[15/11/2013 – 15:17:18 | N | 301517] G:Ecole.docx
[22/10/2013 – 15:18:36 | D ] G:Info
[11/11/2013 – 11:10:16 | N | 36109] G:CHAPITRE I.docx
[12/11/2013 – 15:25:30 | N | 869486] G:Méiose et crossing over.pdf
[12/11/2013 – 15:26:32 | N | 4741397] G:ChapIII-2013.pdf
[15/11/2013 – 15:17:44 | N | 1611] G:Ecole – Raccourci.lnk
[02/12/2013 – 23:02:22 | D ] G:Nouveau dossier
[30/11/2013 – 14:58:06 | N | 132717] G:arbol-genealogico-de-la-familia-del-rey.jpg
[28/11/2013 – 17:35:00 | N | 17680] G:Article El Pais Musica.docx
[30/11/2013 – 14:58:36 | N | 85327] G:donde-la-familia-real.jpg
[30/11/2013 – 15:23:08 | N | 13948] G:Exposé.docx
[07/11/2013 – 17:14:06 | N | 12541] G:Premier travail – Redes sociales.docx
[30/11/2013 – 14:47:32 | N | 14502] G:Présentation.docx
[21/11/2013 – 15:35:24 | N | 3672293] G:20131121 152743.m4a

################## | UsbFix – Information |

UsbFix a détecté sur votre ordinateur, une infection qui dispose d'une fonction de Keylogger.
Après désinfection par UsbFix, veuillez modifier tous vos mots de passe.
Si vous avez effectué des achats sur internet,
veuillez contacter votre banque afin d'envisager une opposition sur votre carte bancaire.

################## | Vaccin |

G:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | http://www.usbfix.net” onclick=”window.open(this.href);return false; – https://www.sosvirus.net” onclick=”window.open(this.href);return false; |[/spoiler:n0aqd6y9]