Logiciel qui s'installe tout seul !
Fermé
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
-
23 déc. 2008 à 19:58
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 30 déc. 2008 à 14:33
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 30 déc. 2008 à 14:33
A voir également:
- Logiciel qui s'installe tout seul !
- Money logiciel - Télécharger - Comptabilité & Facturation
- Logiciel montage vidéo gratuit windows 10 - Guide
- Logiciel de sauvegarde gratuit - Guide
- Logiciel spss - Télécharger - Outils professionnels
- Logiciel benchmark - Accueil - Utilitaires
67 réponses
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
24 déc. 2008 à 18:23
24 déc. 2008 à 18:23
Infection Vundo.
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
23 déc. 2008 à 19:59
23 déc. 2008 à 19:59
Salut,
- Télécharge HijackThis v2.0.2 sur ton Bureau.
- Double-clique sur HJTInstall afin de lancer l'installation.
- Clique sur Install ensuite sur I Accept.
- Clique sur Do a system scan and save a logfile.
- Le bloc-notes s'ouvrira, fais un copier/coller de tout son contenu ici dans ton prochain message.
- Télécharge HijackThis v2.0.2 sur ton Bureau.
- Double-clique sur HJTInstall afin de lancer l'installation.
- Clique sur Install ensuite sur I Accept.
- Clique sur Do a system scan and save a logfile.
- Le bloc-notes s'ouvrira, fais un copier/coller de tout son contenu ici dans ton prochain message.
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
23 déc. 2008 à 20:02
23 déc. 2008 à 20:02
Merci mais j'ai un probleme car je ne peut pas installer d'autre logiciel car je n'ai pas assez de place :\
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
23 déc. 2008 à 20:03
23 déc. 2008 à 20:03
Fais du tri ^^
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
23 déc. 2008 à 20:05
23 déc. 2008 à 20:05
Ok mais comment on fait pour savoir la mémoire qui nous reste dans notre ordi jme souvien plus kommen on fait !
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
23 déc. 2008 à 20:06
23 déc. 2008 à 20:06
On va essayer quelque chose.
---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).
---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
23 déc. 2008 à 20:08
23 déc. 2008 à 20:08
je dois partir on se vera demain je le ferais
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
23 déc. 2008 à 20:09
23 déc. 2008 à 20:09
Si tu me laisses tomber, je préfère que tu me le dises.
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 12:28
24 déc. 2008 à 12:28
Dsl mais je ne te laisse pas tomber c'est que je dois brancher l'autre unité central c'est sur l'autre que le probleme de spyware est là ! Ne te vexe pas pour ça
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
24 déc. 2008 à 15:13
24 déc. 2008 à 15:13
Je ne me vexe pas mais un trop grand pourcentage de personnes disparaissent sans donner de nouvelle.
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 18:21
24 déc. 2008 à 18:21
Ok Mais Moi je revien ;)
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 18:22
24 déc. 2008 à 18:22
Voici le Blog note :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:21:58, on 24/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\WINDOWS\fxstaller.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
O4 - HKLM\..\Run: [a8e27778] rundll32.exe "C:\WINDOWS\system32\krboaocj.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - AppInit_DLLs: irpjuo.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:21:58, on 24/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Creative\Shared Files\CamTray.exe
C:\WINDOWS\fxstaller.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
O4 - HKLM\..\Run: [a8e27778] rundll32.exe "C:\WINDOWS\system32\krboaocj.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O20 - AppInit_DLLs: irpjuo.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 18:34
24 déc. 2008 à 18:34
Ok merci je vais suivre tout cela
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 19:17
24 déc. 2008 à 19:17
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1541
Windows 5.1.2600 Service Pack 3
24/12/2008 19:06:28
mbam-log-2008-12-24 (19-06-28).txt
Type de recherche: Examen rapide
Eléments examinés: 74187
Temps écoulé: 21 minute(s), 30 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 8
Clé(s) du Registre infectée(s): 17
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 90
Processus mémoire infecté(s):
C:\WINDOWS\fxstaller.exe (Backdoor.Bot) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\krboaocj.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qoMgEUnl.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pmnmlliF.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\opnmNGWq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ssqronnM.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\rqRIyVlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\sfqitjjb.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\irpjuo.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmllif (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6e76df63-64fa-489d-aa84-84cd9d0ca9e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6e76df63-64fa-489d-aa84-84cd9d0ca9e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9de487bb-2748-41e7-a42f-f9a56d81b52b} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{9de487bb-2748-41e7-a42f-f9a56d81b52b} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9de487bb-2748-41e7-a42f-f9a56d81b52b} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6e76df63-64fa-489d-aa84-84cd9d0ca9e6} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a8e27778 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows UDP Control Center (Backdoor.Bot) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomgeunl -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\qomgeunl -> Delete on reboot.
Dossier(s) infecté(s):
C:\Program Files\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\quarantine (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS\system32\pmnmlliF.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\irpjuo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qoMgEUnl.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lnUEgMoq.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lnUEgMoq.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\krboaocj.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jcoaobrk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mhcpvkib.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bikvpchm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnmNGWq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ssqronnM.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\rqRIyVlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\sfqitjjb.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\sysrest32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ftsicgff.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\geBtRlJd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\byXOfedC.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnmMFyv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSScfub.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSnrsr.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSofxh.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vtUlJdCs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcYpmnk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRIxwVO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRKCtrP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccaYpOI.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccbAQgg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGwWNde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGxUOHB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGxWQhh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hnhnnh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\khfEUOgh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\khfFVMGw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mlJYpNhe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqNggEU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqPgHxV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqRKBTk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnlIYqp.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winscenter.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awturOFu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXnlMcd(2).dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXOIbcy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXRKCUl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvUKcde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvUOFWo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvVLdeb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urqNEWNf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urqPfEtT.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMcaabb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMdARIA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMdCrpm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJBrRhg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJcCrsP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iifecccb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayXQJde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayxxwvV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayxyyaY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkHYPjH.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\TDSSpaxt.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\reps.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\1BF1HI1Q\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\UP5R7EL1\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\WB81WPYF\file[1].exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\conf.cfg (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\mbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\quarantine.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\queue.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\uninstall.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\vbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temp\BN4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\fxstaller.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtuRhEX.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\byXRhGXq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\spoolsystem.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\vmreg.dll (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\svhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Protect\svhost.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Internet Explorer\DLLs\zledymppda.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSfxmp.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> Quarantined and deleted successfully.
Version de la base de données: 1541
Windows 5.1.2600 Service Pack 3
24/12/2008 19:06:28
mbam-log-2008-12-24 (19-06-28).txt
Type de recherche: Examen rapide
Eléments examinés: 74187
Temps écoulé: 21 minute(s), 30 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 8
Clé(s) du Registre infectée(s): 17
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 90
Processus mémoire infecté(s):
C:\WINDOWS\fxstaller.exe (Backdoor.Bot) -> Unloaded process successfully.
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\krboaocj.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qoMgEUnl.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\pmnmlliF.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\opnmNGWq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ssqronnM.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\rqRIyVlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\sfqitjjb.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\irpjuo.dll (Trojan.Vundo) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmllif (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6e76df63-64fa-489d-aa84-84cd9d0ca9e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6e76df63-64fa-489d-aa84-84cd9d0ca9e6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9de487bb-2748-41e7-a42f-f9a56d81b52b} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{9de487bb-2748-41e7-a42f-f9a56d81b52b} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9de487bb-2748-41e7-a42f-f9a56d81b52b} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6e76df63-64fa-489d-aa84-84cd9d0ca9e6} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a8e27778 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows UDP Control Center (Backdoor.Bot) -> Quarantined and deleted successfully.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\qomgeunl -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\qomgeunl -> Delete on reboot.
Dossier(s) infecté(s):
C:\Program Files\Spyware Guard 2008 (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\quarantine (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
C:\WINDOWS\system32\pmnmlliF.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\irpjuo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qoMgEUnl.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lnUEgMoq.ini (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\lnUEgMoq.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\krboaocj.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\jcoaobrk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mhcpvkib.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bikvpchm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnmNGWq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ssqronnM.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\rqRIyVlj.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\sfqitjjb.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\sysrest32.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ftsicgff.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\geBtRlJd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\byXOfedC.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnmMFyv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSScfub.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSnrsr.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSofxh.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\vtUlJdCs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ddcYpmnk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRIxwVO.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRKCtrP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccaYpOI.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccbAQgg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGwWNde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGxUOHB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hgGxWQhh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hnhnnh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\khfEUOgh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\khfFVMGw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mlJYpNhe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqNggEU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqPgHxV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqRKBTk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\opnlIYqp.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winscenter.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awturOFu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXnlMcd(2).dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXOIbcy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cbXRKCUl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvUKcde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvUOFWo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tuvVLdeb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urqNEWNf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\urqPfEtT.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMcaabb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMdARIA.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qoMdCrpm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJBrRhg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ljJcCrsP.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\iifecccb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayXQJde.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayxxwvV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yayxyyaY.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkHYPjH.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\TDSSpaxt.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\reps.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\1BF1HI1Q\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\UP5R7EL1\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\WB81WPYF\file[1].exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\conf.cfg (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\mbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\quarantine.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\queue.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\spywareguard.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\uninstall.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Program Files\Spyware Guard 2008\vbase.vdb (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\admin\Local Settings\Temp\BN4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\fxstaller.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\awtuRhEX.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\byXRhGXq.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\sysexplorer.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\reged.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\spoolsystem.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\sys.com (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\syscert.exe (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\WINDOWS\vmreg.dll (Rogue.SpywareGuard) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\svhost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Protect\svhost.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Protect\track.sys (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Internet Explorer\DLLs\zledymppda.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Internet Explorer\DLLs\moduleie.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSSfxmp.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> Quarantined and deleted successfully.
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 19:18
24 déc. 2008 à 19:18
Ece que c'est Bon signe ??
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
24 déc. 2008 à 19:27
24 déc. 2008 à 19:27
---> Redémarre ton PC.
---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\
---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"
---> Je te conseille vivement d'installer la Console de récupération.
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\Combofix.txt
Tutoriel officiel :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\
---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"
---> Je te conseille vivement d'installer la Console de récupération.
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\Combofix.txt
Tutoriel officiel :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 19:29
24 déc. 2008 à 19:29
ok ! Est-tu informaticien ??
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
24 déc. 2008 à 19:31
24 déc. 2008 à 19:31
MBAM a supprimé pas mal d'infection mais à mon avis, il doit en rester.
Je ne suis pas informaticien.
Je ne suis pas informaticien.
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 20:10
24 déc. 2008 à 20:10
Ok en tout cas tu es très cultivé dans ce domaine a ce que je vois
Pwiincesse-224
Messages postés
75
Date d'inscription
mardi 23 décembre 2008
Statut
Membre
Dernière intervention
17 mai 2009
24 déc. 2008 à 20:18
24 déc. 2008 à 20:18
"admin" - 2008-12-24 20:12:39 Service Pack 3
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\admin\Bureau\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
"C:\DOCUME~1\admin\Bureau\internet.lnk"
((((((((((((((((((((((((((((((( Files Created from 2008-11-24 to 2008-12-24 ))))))))))))))))))))))))))))))))))
2008-12-24 20:10 401,408 --a------ C:\WINDOWS\system32\CF11354.exe
2008-12-24 18:35 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-12-24 18:35 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-12-24 18:35 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-24 18:35 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Malwarebytes
2008-12-24 18:35 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\Malwarebytes
2008-12-24 18:21 <REP> d-------- C:\Program Files\Trend Micro
2008-12-24 18:12 <REP> d-------- C:\Program Files\Combined Community Codec Pack
2008-12-24 14:46 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-12-24 14:46 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-12-24 14:42 221,216 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-12-24 14:42 2,182,688 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-12-24 14:42 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-12-24 14:42 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Kaspersky Lab
2008-12-20 18:38 <REP> d-------- C:\Program Files\Enigma Software Group
2008-12-19 20:41 69,632 --a------ C:\oskie.exe
2008-12-19 20:35 91,648 --a------ C:\hehe.exe
2008-12-19 18:19 441 --a------ C:\WINDOWS\system32\TDSSosvd.dat
2008-12-16 19:47 <REP> d-------- C:\Program Files\MSNFix
2008-12-14 19:35 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\MSNInstaller
2008-12-14 19:32 1,490,944 --a------ C:\Documents and Settings\admin\ntuser.dat
2008-12-14 19:32 1,490,944 --a------ C:\DOCUME~1\admin\ntuser.dat
2008-12-09 11:53 <REP> d-------- C:\Program Files\MSXML 4.0
2008-12-07 15:00 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\Samsung
2008-12-07 14:11 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-12-07 14:10 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-12-07 14:09 94,000 --a------ C:\WINDOWS\system32\drivers\ssm_mdm.sys
2008-12-07 14:09 8,336 --a------ C:\WINDOWS\system32\drivers\ssm_mdfl.sys
2008-12-07 14:09 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cmnt.sys
2008-12-07 14:09 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cm.sys
2008-12-07 14:09 58,320 --a------ C:\WINDOWS\system32\drivers\ssm_bus.sys
2008-12-07 14:09 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_whnt.sys
2008-12-07 14:09 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_wh.sys
2008-12-07 14:08 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-12-07 14:08 <REP> d-------- C:\Program Files\Samsung
2008-12-07 11:14 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-12-06 21:11 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\U3
2008-12-06 19:27 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\LimeWire
2008-12-06 19:26 410,984 --a------ C:\WINDOWS\system32\deploytk.dll
2008-12-03 16:53 <REP> d-------- C:\Program Files\Apple Software Update
2008-12-03 16:53 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple Computer
2008-12-03 16:53 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple
2008-12-03 16:50 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-12-03 16:50 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-12-03 16:41 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\Creative
2008-12-03 16:37 86,016 -ra------ C:\WINDOWS\CtDrvIns.exe
2008-12-03 16:37 85,248 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-12-03 16:37 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-12-03 16:37 20,480 -ra------ C:\WINDOWS\P0620Cfg.exe
2008-12-03 16:37 19,200 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2008-12-03 16:37 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2008-12-03 16:37 15,232 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-12-03 16:37 126,976 -ra------ C:\WINDOWS\system32\P0620Vfw.dll
2008-12-03 16:37 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-12-03 16:37 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-12-03 16:36 91,864 -ra------ C:\WINDOWS\system32\drivers\P0620Vid.sys
2008-12-03 16:36 57,344 -ra------ C:\WINDOWS\system32\P0620Hwx.dll
2008-12-03 16:36 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-12-03 16:36 36,864 -ra------ C:\WINDOWS\system32\P0620Pin.dll
2008-12-03 16:36 36,864 -ra------ C:\WINDOWS\system32\CtRegApp.dll
2008-12-03 16:36 32,768 -ra------ C:\WINDOWS\system32\p0620sti.dll
2008-12-03 16:36 24,576 -ra------ C:\WINDOWS\system32\P0620Aor.dll
2008-12-03 16:36 20,480 -ra------ C:\WINDOWS\system32\P0620Srv.exe
2008-12-03 16:34 308,224 --a------ C:\WINDOWS\IsUn040c.exe
2008-12-03 16:32 36,864 -ra------ C:\WINDOWS\system32\CtCamMgr.dll
2008-12-03 16:32 24,576 --------- C:\WINDOWS\system32\CTWEBFUN.DLL
2008-12-03 14:49 0 --a------ C:\WINDOWS\nsreg.dat
2008-12-03 13:18 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2008-12-03 11:46 268,648 --a------ C:\WINDOWS\system32\mucltui.dll
2008-12-03 11:46 208,744 --a------ C:\WINDOWS\system32\muweb.dll
2008-12-03 11:45 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Messenger Plus!
2008-12-02 20:46 <REP> d-------- C:\Program Files\PhotoFiltre
2008-12-02 20:00 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\WLInstaller
2008-12-02 19:53 <REP> d---s---- C:\Documents and Settings\admin\UserData
2008-12-02 19:53 <REP> d---s---- C:\DOCUME~1\admin\UserData
2008-12-02 19:38 <REP> d-------- C:\Documents and Settings\admin\Tracing
2008-12-02 19:38 <REP> d-------- C:\DOCUME~1\admin\Tracing
2008-12-02 19:34 <REP> d-------- C:\Program Files\Fichiers communs\Windows Live
2008-12-02 19:26 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-12-02 19:21 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-12-02 14:46 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-12-02 13:54 <REP> d-------- C:\Documents and Settings\admin\Contacts
2008-12-02 13:54 <REP> d-------- C:\DOCUME~1\admin\Contacts
2008-12-02 13:01 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-12-02 13:00 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-12-02 12:55 83,072 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-12-02 12:55 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-12-02 12:55 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-12-02 12:55 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-12-02 12:55 56,576 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-12-02 12:55 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-12-02 12:55 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-12-02 12:55 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-12-02 12:55 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-12-02 12:55 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-12-02 12:55 142,592 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-12-02 12:54 58,752 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-12-02 12:54 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-12-02 12:53 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll
2008-12-02 12:53 701,440 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-12-02 12:53 60,160 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-12-02 12:53 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll
2008-12-02 12:53 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-12-02 12:53 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll
2008-12-02 12:53 201,728 --a------ C:\WINDOWS\system32\ati2dvag.dll
2008-12-02 12:53 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys
2008-12-02 12:53 146,048 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-12-02 12:53 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-12-02 12:52 88,192 --a------ C:\WINDOWS\system32\drivers\irda.sys
2008-12-02 12:52 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-12-02 12:52 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-12-02 12:52 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS
2008-12-02 12:52 32,768 --a------ C:\WINDOWS\system32\drivers\sisnic.sys
2008-12-02 12:52 29,184 --a------ C:\WINDOWS\system32\irmon.dll
2008-12-02 12:52 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys
2008-12-02 12:52 18,688 --a------ C:\WINDOWS\system32\drivers\irsir.sys
2008-12-02 12:52 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2008-12-02 12:52 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2008-12-02 12:49 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2008-12-02 12:49 9,104 --a------ C:\WINDOWS\system\VER.DLL
2008-12-02 12:49 86,044 --a------ C:\WINDOWS\system32\dgsetup.dll
2008-12-02 12:49 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL
2008-12-02 12:49 8,704 --a------ C:\WINDOWS\system32\batt.dll
2008-12-02 12:49 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2008-12-02 12:49 76,800 --a------ C:\WINDOWS\system32\storprop.dll
2008-12-02 12:49 70,688 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2008-12-02 12:49 70,656 --a------ C:\WINDOWS\NOTEPAD.EXE
2008-12-02 12:49 70,352 --a------ C:\WINDOWS\system\AVICAP.DLL
2008-12-02 12:49 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2008-12-02 12:49 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2008-12-02 12:49 33,904 --a------ C:\WINDOWS\system\COMMDLG.DLL
2008-12-02 12:49 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-12-02 12:49 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2008-12-02 12:49 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2008-12-02 12:49 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2008-12-02 12:49 15,872 --a------ C:\WINDOWS\TASKMAN.EXE
2008-12-02 12:49 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-12-02 12:49 127,168 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2008-12-02 12:49 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2008-12-02 12:49 109,568 --a------ C:\WINDOWS\system\AVIFILE.DLL
2008-12-02 12:49 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2008-12-02 12:49 <REP> dr------- C:\DOCUME~1\DEFAUL~1.WIN\Menu D‚marrer
2008-12-02 12:49 <REP> dr------- C:\DOCUME~1\ALLUSE~1.WIN\Menu D‚marrer
2008-12-02 12:49 <REP> dr------- C:\DOCUME~1\ALLUSE~1.WIN\Documents
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\DEFAUL~1.WIN\Voisinage r‚seau
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\DEFAUL~1.WIN\Voisinage d'impression
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\DEFAUL~1.WIN\ModŠles
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\ALLUSE~1.WIN\ModŠles
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\DEFAUL~1.WIN\Mes documents
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\DEFAUL~1.WIN\Favoris
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\DEFAUL~1.WIN\Bureau
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Favoris
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Bureau
2008-12-02 12:48 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-12-02 12:48 111,184 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-12-02 12:45 97,480 --a------ C:\WINDOWS\system32\AVASTSS.scr
2008-12-02 12:45 94,032 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-12-02 12:45 93,296 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-12-02 12:45 50,864 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-12-02 12:45 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-12-02 12:45 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-12-02 12:45 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-12-02 12:45 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-12-02 12:45 1,236,208 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-12-02 12:45 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-12-02 12:45 <REP> d-------- C:\Program Files\Alwil Software
2008-12-02 12:40 4,108,992 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-12-02 12:32 <REP> dr------- C:\Documents and Settings\admin\Mes documents
2008-12-02 12:32 <REP> dr------- C:\Documents and Settings\admin\Menu D‚marrer
2008-12-02 12:32 <REP> dr------- C:\Documents and Settings\admin\Favoris
2008-12-02 12:32 <REP> dr------- C:\DOCUME~1\admin\Mes documents
2008-12-02 12:32 <REP> dr------- C:\DOCUME~1\admin\Menu D‚marrer
2008-12-02 12:32 <REP> dr------- C:\DOCUME~1\admin\Favoris
2008-12-02 12:32 <REP> d--h----- C:\Documents and Settings\admin\Voisinage r‚seau
2008-12-02 12:32 <REP> d--h----- C:\Documents and Settings\admin\Voisinage d'impression
2008-12-02 12:32 <REP> d--h----- C:\Documents and Settings\admin\ModŠles
2008-12-02 12:32 <REP> d--h----- C:\DOCUME~1\admin\Voisinage r‚seau
2008-12-02 12:32 <REP> d--h----- C:\DOCUME~1\admin\Voisinage d'impression
2008-12-02 12:32 <REP> d--h----- C:\DOCUME~1\admin\ModŠles
2008-12-02 12:32 <REP> d-------- C:\Documents and Settings\admin\Bureau
2008-12-02 12:32 <REP> d-------- C:\DOCUME~1\admin\Bureau
2008-12-02 12:20 241,664 --a------ C:\DOCUME~1\NETWOR~1.AUT\NTUSER.DAT
2008-12-02 12:20 241,664 --a------ C:\DOCUME~1\LOCALS~1.AUT\NTUSER.DAT
2008-12-02 12:13 241,664 ---h----- C:\DOCUME~1\DEFAUL~1.WIN\NTUSER.DAT
2008-12-02 12:13 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2008-12-02 12:11 <REP> d--hs---- C:\DOCUME~1\ALLUSE~1.WIN\DRM
2008-12-02 12:09 86,016 --a------ C:\WINDOWS\system32\isign32.dll
2008-12-02 12:09 81,920 --a------ C:\WINDOWS\system32\ils.dll
2008-12-02 12:09 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2008-12-02 12:09 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2008-12-02 12:09 73,600 --a------ C:\WINDOWS\system32\drivers\sr.sys
2008-12-02 12:09 72,192 --a------ C:\WINDOWS\system32\acctres.dll
2008-12-02 12:09 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-12-02 12:09 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2008-12-02 12:09 691,712 --a------ C:\WINDOWS\system32\inetcomm.dll
2008-12-02 12:09 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2008-12-02 12:09 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2008-12-02 12:09 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2008-12-02 12:09 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2008-12-02 12:09 561,688 --a------ C:\WINDOWS\system32\wuapi.dll
2008-12-02 12:09 51,224 --a------ C:\WINDOWS\system32\wuauclt.exe
2008-12-02 12:09 50,688 --a------ C:\WINDOWS\system32\inetres.dll
2008-12-02 12:09 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2008-12-02 12:09 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2008-12-02 12:09 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2008-12-02 12:09 409,088 --a------ C:\WINDOWS\system32\qmgr.dll
2008-12-02 12:09 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2008-12-02 12:09 34,328 --a------ C:\WINDOWS\system32\wups.dll
2008-12-02 12:09 323,608 --a------ C:\WINDOWS\system32\wucltui.dll
2008-12-02 12:09 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2008-12-02 12:09 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2008-12-02 12:09 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2008-12-02 12:09 282,624 --a------ C:\WINDOWS\system32\inetcfg.dll
2008-12-02 12:09 281,600 --a------ C:\WINDOWS\system32\mstask.dll
2008-12-02 12:09 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2008-12-02 12:09 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2008-12-02 12:09 241,664 --a------ C:\WINDOWS\system32\srrstr.dll
2008-12-02 12:09 23,040 --a------ C:\WINDOWS\system32\fltMc.exe
2008-12-02 12:09 202,776 --a------ C:\WINDOWS\system32\wuweb.dll
2008-12-02 12:09 194,560 --a------ C:\WINDOWS\system32\schedsvc.dll
2008-12-02 12:09 184,320 --a------ C:\WINDOWS\system32\wuaueng1.dll
2008-12-02 12:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-12-02 12:09 171,520 --a------ C:\WINDOWS\system32\srsvc.dll
2008-12-02 12:09 168,960 --a------ C:\WINDOWS\system32\wuauclt1.exe
2008-12-02 12:09 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2008-12-02 12:09 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2008-12-02 12:09 129,792 --a------ C:\WINDOWS\system32\drivers\fltMgr.sys
2008-12-02 12:09 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2008-12-02 12:09 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2008-12-02 12:09 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2008-12-02 12:09 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2008-12-02 12:09 1,809,944 --a------ C:\WINDOWS\system32\wuaueng.dll
2008-12-02 12:08 21,892 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-12-02 12:07 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2008-12-02 12:07 5,632 --a------ C:\WINDOWS\system32\write.exe
2008-12-02 12:07 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2008-12-02 12:07 232,960 --a------ C:\WINDOWS\system32\avtapi.dll
2008-12-02 12:07 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2008-12-02 12:07 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe
2008-12-02 12:06 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2008-12-02 12:06 956,928 --a------ C:\WINDOWS\system32\msdtctm.dll
2008-12-02 12:06 94,208 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2008-12-02 12:06 91,648 --a------ C:\WINDOWS\system32\mtxoci.dll
2008-12-02 12:06 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2008-12-02 12:06 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2008-12-02 12:06 80,896 --a------ C:\WINDOWS\system32\charmap.exe
2008-12-02 12:06 677,888 --a------ C:\WINDOWS\system32\mstsc.exe
2008-12-02 12:06 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2008-12-02 12:06 634,880 --a------ C:\WINDOWS\system32\getuname.dll
2008-12-02 12:06 625,664 --a------ C:\WINDOWS\system32\catsrvut.dll
2008-12-02 12:06 62,976 --a------ C:\WINDOWS\system32\rdpclip.exe
2008-12-02 12:06 61,952 --a------ C:\WINDOWS\system32\remotepg.dll
2008-12-02 12:06 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2008-12-02 12:06 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2008-12-02 12:06 6,144 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2008-12-02 12:06 59,392 --a------ C:\WINDOWS\system32\stclient.dll
2008-12-02 12:06 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2008-12-02 12:06 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2008-12-02 12:06 57,344 --a------ C:\WINDOWS\system32\sol.exe
2008-12-02 12:06 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2008-12-02 12:06 55,808 --a------ C:\WINDOWS\system32\freecell.exe
2008-12-02 12:06 539,648 --a------ C:\WINDOWS\system32\comuid.dll
2008-12-02 12:06 539,136 --a------ C:\WINDOWS\system32\spider.exe
2008-12-02 12:06 53,248 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-12-02 12:06 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2008-12-02 12:06 427,008 --a------ C:\WINDOWS\system32\msdtcprx.dll
2008-12-02 12:06 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2008-12-02 12:06 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2008-12-02 12:06 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2008-12-02 12:06 39,424 --a------ C:\WINDOWS\system32\cfgbkend.dll
2008-12-02 12:06 354,304 --a------ C:\WINDOWS\system32\hypertrm.dll
2008-12-02 12:06 35,840 --a------ C:\WINDOWS\system32\winchat.exe
2008-12-02 12:06 347,648 --a------ C:\WINDOWS\system32\mspaint.exe
2008-12-02 12:06 34,304 --a------ C:\WINDOWS\system32\mtxlegih.dll
2008-12-02 12:06 33,792 --a------ C:\WINDOWS\system32\regini.exe
2008-12-02 12:06 30,720 --a------ C:\WINDOWS\system32\mtxdm.dll
2008-12-02 12:06 297,984 --a------ C:\WINDOWS\system32\termsrv.dll
2008-12-02 12:06 290,304 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-12-02 12:06 28,160 --a------ C:\WINDOWS\system32\comaddin.dll
2008-12-02 12:06 226,304 --a------ C:\WINDOWS\system32\catsrv.dll
2008-12-02 12:06 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe
2008-12-02 12:06 22,528 --a------ C:\WINDOWS\system32\msg.exe
2008-12-02 12:06 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2008-12-02 12:06 20,992 --a------ C:\WINDOWS\system32\qprocess.exe
2008-12-02 12:06 2,061,824 --a------ C:\WINDOWS\system32\mstscax.dll
2008-12-02 12:06 196,224 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-12-02 12:06 191,488 --a------ C:\WINDOWS\system32\cmprops.dll
2008-12-02 12:06 190,464 --a------ C:\WINDOWS\system32\accwiz.exe
2008-12-02 12:06 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2008-12-02 12:06 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll
2008-12-02 12:06 17,408 --a------ C:\WINDOWS\system32\tsshutdn.exe
2008-12-02 12:06 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe
2008-12-02 12:06 167,424 --a------ C:\WINDOWS\system32\comsnap.dll
2008-12-02 12:06 161,792 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2008-12-02 12:06 16,896 --a------ C:\WINDOWS\system32\tskill.exe
2008-12-02 12:06 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe
2008-12-02 12:06 15,872 --a------ C:\WINDOWS\system32\logoff.exe
2008-12-02 12:06 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2008-12-02 12:06 15,360 --a------ C:\WINDOWS\system32\tscon.exe
2008-12-02 12:06 15,360 --a------ C:\WINDOWS\system32\shadow.exe
2008-12-02 12:06 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2008-12-02 12:06 142,848 --a------ C:\WINDOWS\system32\sessmgr.exe
2008-12-02 12:06 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2008-12-02 12:06 139,656 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2008-12-02 12:06 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-12-02 12:06 133,120 --a------ C:\WINDOWS\system32\sndrec32.exe
2008-12-02 12:06 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2008-12-02 12:06 128,000 --a------ C:\WINDOWS\system32\mshearts.exe
2008-12-02 12:06 124,928 --a------ C:\WINDOWS\system32\mplay32.exe
2008-12-02 12:06 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2008-12-02 12:06 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2008-12-02 12:06 115,200 --a------ C:\WINDOWS\system32\calc.exe
2008-12-02 12:06 110,592 --a------ C:\WINDOWS\system32\clbcatex.dll
2008-12-02 12:06 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2008-12-02 12:06 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2008-12-02 12:06 104,448 --a------ C:\WINDOWS\system32\clipbrd.exe
2008-12-02 12:06 10,240 --a------ C:\WINDOWS\system32\reset.exe
2008-12-02 12:06 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2008-12-02 12:06 1,263 --a------ C:\WINDOWS\system32\usrlogon.cmd
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-12-16 14:36:08 -------- d-----w C:\Program Files\Windows Live
2008-12-07 13:09:46 -------- d--h--w C:\Program Files\InstallShield Installation Information
2008-12-06 18:11:21 -------- d-----w C:\Program Files\LimeWire
2008-12-03 15:53:45 -------- d-----w C:\Program Files\QuickTime
2008-12-03 15:49:30 71,248 ----a-w C:\WINDOWS\system32\perfc00C.dat
2008-12-03 15:49:30 458,230 ----a-w C:\WINDOWS\system32\perfh00C.dat
2008-12-02 12:01:00 -------- d-----w C:\Program Files\Realtek AC97
2008-10-24 11:21:09 455,296 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-10-23 12:36:51 286,720 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-10-16 13:09:44 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09:44 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-03 10:03:53 247,326 ----a-w C:\WINDOWS\system32\strmdll.dll
2008-09-30 15:43:34 1,286,152 ----a-w C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-10 05:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 15:24]
{DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-10 05:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 18:18]
"SoundMan"="SOUNDMAN.EXE" []
"Cmaudio"="cmicnfg.cpl" []
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 18:03 C:\WINDOWS\system32\P0620Pin.dll]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 09:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-11-10 05:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 18:34]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-03-29 07:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
%SystemRoot%\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfa7e13e-24eb-11dd-8bbe-0019660cba68}]
AutoRun\command- F:\CDSTART.EXE
Contents of the 'Scheduled Tasks' folder
2008-12-15 15:42:06 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2008-12-24 19:00:00 C:\WINDOWS\tasks\zjckplwb.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-24 20:15:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\JavaQuickStarterService]
"ImagePath"="\"C:\Program Files\Java\jre6\bin\jqs.exe\" -service -config \"C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf\""
Completion time: 2008-12-24 20:16:08
C:\ComboFix-quarantined-files.txt ... 2008-12-24 20:15
--- E O F ---
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\admin\Bureau\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
"C:\DOCUME~1\admin\Bureau\internet.lnk"
((((((((((((((((((((((((((((((( Files Created from 2008-11-24 to 2008-12-24 ))))))))))))))))))))))))))))))))))
2008-12-24 20:10 401,408 --a------ C:\WINDOWS\system32\CF11354.exe
2008-12-24 18:35 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-12-24 18:35 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-12-24 18:35 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-24 18:35 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Malwarebytes
2008-12-24 18:35 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\Malwarebytes
2008-12-24 18:21 <REP> d-------- C:\Program Files\Trend Micro
2008-12-24 18:12 <REP> d-------- C:\Program Files\Combined Community Codec Pack
2008-12-24 14:46 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-12-24 14:46 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-12-24 14:42 221,216 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-12-24 14:42 2,182,688 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-12-24 14:42 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-12-24 14:42 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Kaspersky Lab
2008-12-20 18:38 <REP> d-------- C:\Program Files\Enigma Software Group
2008-12-19 20:41 69,632 --a------ C:\oskie.exe
2008-12-19 20:35 91,648 --a------ C:\hehe.exe
2008-12-19 18:19 441 --a------ C:\WINDOWS\system32\TDSSosvd.dat
2008-12-16 19:47 <REP> d-------- C:\Program Files\MSNFix
2008-12-14 19:35 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\MSNInstaller
2008-12-14 19:32 1,490,944 --a------ C:\Documents and Settings\admin\ntuser.dat
2008-12-14 19:32 1,490,944 --a------ C:\DOCUME~1\admin\ntuser.dat
2008-12-09 11:53 <REP> d-------- C:\Program Files\MSXML 4.0
2008-12-07 15:00 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\Samsung
2008-12-07 14:11 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-12-07 14:10 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-12-07 14:09 94,000 --a------ C:\WINDOWS\system32\drivers\ssm_mdm.sys
2008-12-07 14:09 8,336 --a------ C:\WINDOWS\system32\drivers\ssm_mdfl.sys
2008-12-07 14:09 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cmnt.sys
2008-12-07 14:09 6,176 --a------ C:\WINDOWS\system32\drivers\ssm_cm.sys
2008-12-07 14:09 58,320 --a------ C:\WINDOWS\system32\drivers\ssm_bus.sys
2008-12-07 14:09 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_whnt.sys
2008-12-07 14:09 5,840 --a------ C:\WINDOWS\system32\drivers\ssm_wh.sys
2008-12-07 14:08 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-12-07 14:08 <REP> d-------- C:\Program Files\Samsung
2008-12-07 11:14 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-12-06 21:11 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\U3
2008-12-06 19:27 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\LimeWire
2008-12-06 19:26 410,984 --a------ C:\WINDOWS\system32\deploytk.dll
2008-12-03 16:53 <REP> d-------- C:\Program Files\Apple Software Update
2008-12-03 16:53 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple Computer
2008-12-03 16:53 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple
2008-12-03 16:50 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-12-03 16:50 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-12-03 16:41 <REP> d-------- C:\DOCUME~1\admin\APPLIC~1\Creative
2008-12-03 16:37 86,016 -ra------ C:\WINDOWS\CtDrvIns.exe
2008-12-03 16:37 85,248 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2008-12-03 16:37 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2008-12-03 16:37 20,480 -ra------ C:\WINDOWS\P0620Cfg.exe
2008-12-03 16:37 19,200 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2008-12-03 16:37 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2008-12-03 16:37 15,232 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
2008-12-03 16:37 126,976 -ra------ C:\WINDOWS\system32\P0620Vfw.dll
2008-12-03 16:37 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
2008-12-03 16:37 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
2008-12-03 16:36 91,864 -ra------ C:\WINDOWS\system32\drivers\P0620Vid.sys
2008-12-03 16:36 57,344 -ra------ C:\WINDOWS\system32\P0620Hwx.dll
2008-12-03 16:36 54,784 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-12-03 16:36 36,864 -ra------ C:\WINDOWS\system32\P0620Pin.dll
2008-12-03 16:36 36,864 -ra------ C:\WINDOWS\system32\CtRegApp.dll
2008-12-03 16:36 32,768 -ra------ C:\WINDOWS\system32\p0620sti.dll
2008-12-03 16:36 24,576 -ra------ C:\WINDOWS\system32\P0620Aor.dll
2008-12-03 16:36 20,480 -ra------ C:\WINDOWS\system32\P0620Srv.exe
2008-12-03 16:34 308,224 --a------ C:\WINDOWS\IsUn040c.exe
2008-12-03 16:32 36,864 -ra------ C:\WINDOWS\system32\CtCamMgr.dll
2008-12-03 16:32 24,576 --------- C:\WINDOWS\system32\CTWEBFUN.DLL
2008-12-03 14:49 0 --a------ C:\WINDOWS\nsreg.dat
2008-12-03 13:18 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Windows Genuine Advantage
2008-12-03 11:46 268,648 --a------ C:\WINDOWS\system32\mucltui.dll
2008-12-03 11:46 208,744 --a------ C:\WINDOWS\system32\muweb.dll
2008-12-03 11:45 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Messenger Plus!
2008-12-02 20:46 <REP> d-------- C:\Program Files\PhotoFiltre
2008-12-02 20:00 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\WLInstaller
2008-12-02 19:53 <REP> d---s---- C:\Documents and Settings\admin\UserData
2008-12-02 19:53 <REP> d---s---- C:\DOCUME~1\admin\UserData
2008-12-02 19:38 <REP> d-------- C:\Documents and Settings\admin\Tracing
2008-12-02 19:38 <REP> d-------- C:\DOCUME~1\admin\Tracing
2008-12-02 19:34 <REP> d-------- C:\Program Files\Fichiers communs\Windows Live
2008-12-02 19:26 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-12-02 19:21 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-12-02 14:46 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-12-02 13:54 <REP> d-------- C:\Documents and Settings\admin\Contacts
2008-12-02 13:54 <REP> d-------- C:\DOCUME~1\admin\Contacts
2008-12-02 13:01 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-12-02 13:00 315,392 --a------ C:\WINDOWS\alcupd.exe
2008-12-02 12:55 83,072 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-12-02 12:55 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2008-12-02 12:55 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2008-12-02 12:55 6,272 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-12-02 12:55 56,576 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-12-02 12:55 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-12-02 12:55 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2008-12-02 12:55 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2008-12-02 12:55 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2008-12-02 12:55 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2008-12-02 12:55 142,592 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-12-02 12:54 58,752 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-12-02 12:54 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-12-02 12:53 870,784 --a------ C:\WINDOWS\system32\ati3d1ag.dll
2008-12-02 12:53 701,440 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-12-02 12:53 60,160 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-12-02 12:53 516,768 --a------ C:\WINDOWS\system32\ativvaxx.dll
2008-12-02 12:53 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-12-02 12:53 229,376 --a------ C:\WINDOWS\system32\ati2cqag.dll
2008-12-02 12:53 201,728 --a------ C:\WINDOWS\system32\ati2dvag.dll
2008-12-02 12:53 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys
2008-12-02 12:53 146,048 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-12-02 12:53 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-12-02 12:52 88,192 --a------ C:\WINDOWS\system32\drivers\irda.sys
2008-12-02 12:52 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-12-02 12:52 77,312 --a------ C:\WINDOWS\system32\usbui.dll
2008-12-02 12:52 44,672 --a------ C:\WINDOWS\system32\drivers\UAGP35.SYS
2008-12-02 12:52 32,768 --a------ C:\WINDOWS\system32\drivers\sisnic.sys
2008-12-02 12:52 29,184 --a------ C:\WINDOWS\system32\irmon.dll
2008-12-02 12:52 19,584 --a------ C:\WINDOWS\system32\drivers\rasirda.sys
2008-12-02 12:52 18,688 --a------ C:\WINDOWS\system32\drivers\irsir.sys
2008-12-02 12:52 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2008-12-02 12:52 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2008-12-02 12:49 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2008-12-02 12:49 9,104 --a------ C:\WINDOWS\system\VER.DLL
2008-12-02 12:49 86,044 --a------ C:\WINDOWS\system32\dgsetup.dll
2008-12-02 12:49 83,456 --a------ C:\WINDOWS\system\OLECLI.DLL
2008-12-02 12:49 8,704 --a------ C:\WINDOWS\system32\batt.dll
2008-12-02 12:49 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2008-12-02 12:49 76,800 --a------ C:\WINDOWS\system32\storprop.dll
2008-12-02 12:49 70,688 --a------ C:\WINDOWS\system\MMSYSTEM.DLL
2008-12-02 12:49 70,656 --a------ C:\WINDOWS\NOTEPAD.EXE
2008-12-02 12:49 70,352 --a------ C:\WINDOWS\system\AVICAP.DLL
2008-12-02 12:49 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2008-12-02 12:49 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2008-12-02 12:49 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2008-12-02 12:49 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2008-12-02 12:49 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2008-12-02 12:49 33,904 --a------ C:\WINDOWS\system\COMMDLG.DLL
2008-12-02 12:49 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-12-02 12:49 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2008-12-02 12:49 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2008-12-02 12:49 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2008-12-02 12:49 15,872 --a------ C:\WINDOWS\TASKMAN.EXE
2008-12-02 12:49 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-12-02 12:49 127,168 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2008-12-02 12:49 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2008-12-02 12:49 109,568 --a------ C:\WINDOWS\system\AVIFILE.DLL
2008-12-02 12:49 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2008-12-02 12:49 <REP> dr------- C:\DOCUME~1\DEFAUL~1.WIN\Menu D‚marrer
2008-12-02 12:49 <REP> dr------- C:\DOCUME~1\ALLUSE~1.WIN\Menu D‚marrer
2008-12-02 12:49 <REP> dr------- C:\DOCUME~1\ALLUSE~1.WIN\Documents
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\DEFAUL~1.WIN\Voisinage r‚seau
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\DEFAUL~1.WIN\Voisinage d'impression
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\DEFAUL~1.WIN\ModŠles
2008-12-02 12:49 <REP> d--h----- C:\DOCUME~1\ALLUSE~1.WIN\ModŠles
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\DEFAUL~1.WIN\Mes documents
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\DEFAUL~1.WIN\Favoris
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\DEFAUL~1.WIN\Bureau
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Favoris
2008-12-02 12:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\Bureau
2008-12-02 12:48 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-12-02 12:48 111,184 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-12-02 12:45 97,480 --a------ C:\WINDOWS\system32\AVASTSS.scr
2008-12-02 12:45 94,032 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-12-02 12:45 93,296 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-12-02 12:45 50,864 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-12-02 12:45 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-12-02 12:45 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-12-02 12:45 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-12-02 12:45 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-12-02 12:45 1,236,208 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-12-02 12:45 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-12-02 12:45 <REP> d-------- C:\Program Files\Alwil Software
2008-12-02 12:40 4,108,992 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-12-02 12:32 <REP> dr------- C:\Documents and Settings\admin\Mes documents
2008-12-02 12:32 <REP> dr------- C:\Documents and Settings\admin\Menu D‚marrer
2008-12-02 12:32 <REP> dr------- C:\Documents and Settings\admin\Favoris
2008-12-02 12:32 <REP> dr------- C:\DOCUME~1\admin\Mes documents
2008-12-02 12:32 <REP> dr------- C:\DOCUME~1\admin\Menu D‚marrer
2008-12-02 12:32 <REP> dr------- C:\DOCUME~1\admin\Favoris
2008-12-02 12:32 <REP> d--h----- C:\Documents and Settings\admin\Voisinage r‚seau
2008-12-02 12:32 <REP> d--h----- C:\Documents and Settings\admin\Voisinage d'impression
2008-12-02 12:32 <REP> d--h----- C:\Documents and Settings\admin\ModŠles
2008-12-02 12:32 <REP> d--h----- C:\DOCUME~1\admin\Voisinage r‚seau
2008-12-02 12:32 <REP> d--h----- C:\DOCUME~1\admin\Voisinage d'impression
2008-12-02 12:32 <REP> d--h----- C:\DOCUME~1\admin\ModŠles
2008-12-02 12:32 <REP> d-------- C:\Documents and Settings\admin\Bureau
2008-12-02 12:32 <REP> d-------- C:\DOCUME~1\admin\Bureau
2008-12-02 12:20 241,664 --a------ C:\DOCUME~1\NETWOR~1.AUT\NTUSER.DAT
2008-12-02 12:20 241,664 --a------ C:\DOCUME~1\LOCALS~1.AUT\NTUSER.DAT
2008-12-02 12:13 241,664 ---h----- C:\DOCUME~1\DEFAUL~1.WIN\NTUSER.DAT
2008-12-02 12:13 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2008-12-02 12:11 <REP> d--hs---- C:\DOCUME~1\ALLUSE~1.WIN\DRM
2008-12-02 12:09 86,016 --a------ C:\WINDOWS\system32\isign32.dll
2008-12-02 12:09 81,920 --a------ C:\WINDOWS\system32\ils.dll
2008-12-02 12:09 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2008-12-02 12:09 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2008-12-02 12:09 73,600 --a------ C:\WINDOWS\system32\drivers\sr.sys
2008-12-02 12:09 72,192 --a------ C:\WINDOWS\system32\acctres.dll
2008-12-02 12:09 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-12-02 12:09 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2008-12-02 12:09 691,712 --a------ C:\WINDOWS\system32\inetcomm.dll
2008-12-02 12:09 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2008-12-02 12:09 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2008-12-02 12:09 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2008-12-02 12:09 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2008-12-02 12:09 561,688 --a------ C:\WINDOWS\system32\wuapi.dll
2008-12-02 12:09 51,224 --a------ C:\WINDOWS\system32\wuauclt.exe
2008-12-02 12:09 50,688 --a------ C:\WINDOWS\system32\inetres.dll
2008-12-02 12:09 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2008-12-02 12:09 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2008-12-02 12:09 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2008-12-02 12:09 409,088 --a------ C:\WINDOWS\system32\qmgr.dll
2008-12-02 12:09 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2008-12-02 12:09 34,328 --a------ C:\WINDOWS\system32\wups.dll
2008-12-02 12:09 323,608 --a------ C:\WINDOWS\system32\wucltui.dll
2008-12-02 12:09 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2008-12-02 12:09 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2008-12-02 12:09 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2008-12-02 12:09 282,624 --a------ C:\WINDOWS\system32\inetcfg.dll
2008-12-02 12:09 281,600 --a------ C:\WINDOWS\system32\mstask.dll
2008-12-02 12:09 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2008-12-02 12:09 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2008-12-02 12:09 241,664 --a------ C:\WINDOWS\system32\srrstr.dll
2008-12-02 12:09 23,040 --a------ C:\WINDOWS\system32\fltMc.exe
2008-12-02 12:09 202,776 --a------ C:\WINDOWS\system32\wuweb.dll
2008-12-02 12:09 194,560 --a------ C:\WINDOWS\system32\schedsvc.dll
2008-12-02 12:09 184,320 --a------ C:\WINDOWS\system32\wuaueng1.dll
2008-12-02 12:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-12-02 12:09 171,520 --a------ C:\WINDOWS\system32\srsvc.dll
2008-12-02 12:09 168,960 --a------ C:\WINDOWS\system32\wuauclt1.exe
2008-12-02 12:09 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2008-12-02 12:09 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2008-12-02 12:09 129,792 --a------ C:\WINDOWS\system32\drivers\fltMgr.sys
2008-12-02 12:09 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2008-12-02 12:09 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2008-12-02 12:09 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2008-12-02 12:09 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2008-12-02 12:09 1,809,944 --a------ C:\WINDOWS\system32\wuaueng.dll
2008-12-02 12:08 21,892 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-12-02 12:07 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2008-12-02 12:07 5,632 --a------ C:\WINDOWS\system32\write.exe
2008-12-02 12:07 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2008-12-02 12:07 232,960 --a------ C:\WINDOWS\system32\avtapi.dll
2008-12-02 12:07 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2008-12-02 12:07 139,264 --a------ C:\WINDOWS\system32\sndvol32.exe
2008-12-02 12:06 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2008-12-02 12:06 956,928 --a------ C:\WINDOWS\system32\msdtctm.dll
2008-12-02 12:06 94,208 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2008-12-02 12:06 91,648 --a------ C:\WINDOWS\system32\mtxoci.dll
2008-12-02 12:06 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2008-12-02 12:06 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2008-12-02 12:06 80,896 --a------ C:\WINDOWS\system32\charmap.exe
2008-12-02 12:06 677,888 --a------ C:\WINDOWS\system32\mstsc.exe
2008-12-02 12:06 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2008-12-02 12:06 634,880 --a------ C:\WINDOWS\system32\getuname.dll
2008-12-02 12:06 625,664 --a------ C:\WINDOWS\system32\catsrvut.dll
2008-12-02 12:06 62,976 --a------ C:\WINDOWS\system32\rdpclip.exe
2008-12-02 12:06 61,952 --a------ C:\WINDOWS\system32\remotepg.dll
2008-12-02 12:06 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2008-12-02 12:06 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2008-12-02 12:06 6,144 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2008-12-02 12:06 59,392 --a------ C:\WINDOWS\system32\stclient.dll
2008-12-02 12:06 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2008-12-02 12:06 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2008-12-02 12:06 57,344 --a------ C:\WINDOWS\system32\sol.exe
2008-12-02 12:06 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2008-12-02 12:06 55,808 --a------ C:\WINDOWS\system32\freecell.exe
2008-12-02 12:06 539,648 --a------ C:\WINDOWS\system32\comuid.dll
2008-12-02 12:06 539,136 --a------ C:\WINDOWS\system32\spider.exe
2008-12-02 12:06 53,248 --a------ C:\WINDOWS\system32\tsgqec.dll
2008-12-02 12:06 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2008-12-02 12:06 427,008 --a------ C:\WINDOWS\system32\msdtcprx.dll
2008-12-02 12:06 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2008-12-02 12:06 4,608 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2008-12-02 12:06 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2008-12-02 12:06 39,424 --a------ C:\WINDOWS\system32\cfgbkend.dll
2008-12-02 12:06 354,304 --a------ C:\WINDOWS\system32\hypertrm.dll
2008-12-02 12:06 35,840 --a------ C:\WINDOWS\system32\winchat.exe
2008-12-02 12:06 347,648 --a------ C:\WINDOWS\system32\mspaint.exe
2008-12-02 12:06 34,304 --a------ C:\WINDOWS\system32\mtxlegih.dll
2008-12-02 12:06 33,792 --a------ C:\WINDOWS\system32\regini.exe
2008-12-02 12:06 30,720 --a------ C:\WINDOWS\system32\mtxdm.dll
2008-12-02 12:06 297,984 --a------ C:\WINDOWS\system32\termsrv.dll
2008-12-02 12:06 290,304 --a------ C:\WINDOWS\system32\rhttpaa.dll
2008-12-02 12:06 28,160 --a------ C:\WINDOWS\system32\comaddin.dll
2008-12-02 12:06 226,304 --a------ C:\WINDOWS\system32\catsrv.dll
2008-12-02 12:06 22,528 --a------ C:\WINDOWS\system32\qwinsta.exe
2008-12-02 12:06 22,528 --a------ C:\WINDOWS\system32\msg.exe
2008-12-02 12:06 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2008-12-02 12:06 20,992 --a------ C:\WINDOWS\system32\qprocess.exe
2008-12-02 12:06 2,061,824 --a------ C:\WINDOWS\system32\mstscax.dll
2008-12-02 12:06 196,224 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-12-02 12:06 191,488 --a------ C:\WINDOWS\system32\cmprops.dll
2008-12-02 12:06 190,464 --a------ C:\WINDOWS\system32\accwiz.exe
2008-12-02 12:06 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2008-12-02 12:06 17,920 --a------ C:\WINDOWS\system32\mmfutil.dll
2008-12-02 12:06 17,408 --a------ C:\WINDOWS\system32\tsshutdn.exe
2008-12-02 12:06 17,408 --a------ C:\WINDOWS\system32\qappsrv.exe
2008-12-02 12:06 167,424 --a------ C:\WINDOWS\system32\comsnap.dll
2008-12-02 12:06 161,792 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2008-12-02 12:06 16,896 --a------ C:\WINDOWS\system32\tskill.exe
2008-12-02 12:06 16,384 --a------ C:\WINDOWS\system32\rwinsta.exe
2008-12-02 12:06 15,872 --a------ C:\WINDOWS\system32\logoff.exe
2008-12-02 12:06 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2008-12-02 12:06 15,360 --a------ C:\WINDOWS\system32\tscon.exe
2008-12-02 12:06 15,360 --a------ C:\WINDOWS\system32\shadow.exe
2008-12-02 12:06 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2008-12-02 12:06 142,848 --a------ C:\WINDOWS\system32\sessmgr.exe
2008-12-02 12:06 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2008-12-02 12:06 139,656 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2008-12-02 12:06 136,192 --a------ C:\WINDOWS\system32\aaclient.dll
2008-12-02 12:06 133,120 --a------ C:\WINDOWS\system32\sndrec32.exe
2008-12-02 12:06 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2008-12-02 12:06 128,000 --a------ C:\WINDOWS\system32\mshearts.exe
2008-12-02 12:06 124,928 --a------ C:\WINDOWS\system32\mplay32.exe
2008-12-02 12:06 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2008-12-02 12:06 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2008-12-02 12:06 115,200 --a------ C:\WINDOWS\system32\calc.exe
2008-12-02 12:06 110,592 --a------ C:\WINDOWS\system32\clbcatex.dll
2008-12-02 12:06 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2008-12-02 12:06 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2008-12-02 12:06 104,448 --a------ C:\WINDOWS\system32\clipbrd.exe
2008-12-02 12:06 10,240 --a------ C:\WINDOWS\system32\reset.exe
2008-12-02 12:06 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2008-12-02 12:06 1,263 --a------ C:\WINDOWS\system32\usrlogon.cmd
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-12-16 14:36:08 -------- d-----w C:\Program Files\Windows Live
2008-12-07 13:09:46 -------- d--h--w C:\Program Files\InstallShield Installation Information
2008-12-06 18:11:21 -------- d-----w C:\Program Files\LimeWire
2008-12-03 15:53:45 -------- d-----w C:\Program Files\QuickTime
2008-12-03 15:49:30 71,248 ----a-w C:\WINDOWS\system32\perfc00C.dat
2008-12-03 15:49:30 458,230 ----a-w C:\WINDOWS\system32\perfh00C.dat
2008-12-02 12:01:00 -------- d-----w C:\Program Files\Realtek AC97
2008-10-24 11:21:09 455,296 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-10-23 12:36:51 286,720 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-10-16 13:09:44 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09:44 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-03 10:03:53 247,326 ----a-w C:\WINDOWS\system32\strmdll.dll
2008-09-30 15:43:34 1,286,152 ----a-w C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre6\bin\ssv.dll [2008-11-10 05:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 15:24]
{DBC80044-A445-435b-BC74-9C25C1C588A9}=C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-11-10 05:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 18:18]
"SoundMan"="SOUNDMAN.EXE" []
"Cmaudio"="cmicnfg.cpl" []
"PD0620 STISvc"="P0620Pin.dll" [2005-05-10 18:03 C:\WINDOWS\system32\P0620Pin.dll]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 09:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-11-10 05:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 18:34]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-03-29 07:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
%SystemRoot%\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command- F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dfa7e13e-24eb-11dd-8bbe-0019660cba68}]
AutoRun\command- F:\CDSTART.EXE
Contents of the 'Scheduled Tasks' folder
2008-12-15 15:42:06 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2008-12-24 19:00:00 C:\WINDOWS\tasks\zjckplwb.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-24 20:15:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\JavaQuickStarterService]
"ImagePath"="\"C:\Program Files\Java\jre6\bin\jqs.exe\" -service -config \"C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf\""
Completion time: 2008-12-24 20:16:08
C:\ComboFix-quarantined-files.txt ... 2008-12-24 20:15
--- E O F ---
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 297
24 déc. 2008 à 20:29
24 déc. 2008 à 20:29
--> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe
--> Lance l'installation avec les paramètres par défaut.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.
--> Double-clique sur le raccourci UsbFix sur ton Bureau.
--> Choisis l'option 1 (Nettoyage).
--> Le PC va redémarrer.
--> Après redémarrage, poste le rapport UsbFix.txt
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe
--> Lance l'installation avec les paramètres par défaut.
--> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.
--> Double-clique sur le raccourci UsbFix sur ton Bureau.
--> Choisis l'option 1 (Nettoyage).
--> Le PC va redémarrer.
--> Après redémarrage, poste le rapport UsbFix.txt
Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)