Avis sur rapport de désinfection
Regenium
Messages postés
87
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour à tous.
Je tente de désinfecter un ordi qui n'avait pas d'antivirus.
Ci-dessous 3 rapports après désinfection par AVG et Malwarebytes' :
Hijackthis
Malwarebytes' Anti Malware
Gmer
Pourriez vous me dire si vous voyez des restes?
Malwarebytes' a trouvé des restes de Vundo ( =( ):
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> No action taken.
Fichier(s) infecté(s):
C:\WINDOWS\system32\avgrsstx.dll (Trojan.Vundo) -> No action taken.
Merci pour le coup de main !
1) j'ai installé AVG (propriétaire novice en informatique) et voici tous les virus repérés:
http://img386.imageshack.us/img386/650/collectionwr6.th.jpg
2) Les rapports
Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:41, on 24.12.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\CardDetector\ICON225\CardDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=4061114
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=4061114
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\ScanSoft\NaturallySpeaking8\Program\ereg.exe" -r "C:\Program Files\ScanSoft\NaturallySpeaking8\Program\ereg.ini"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CardDetector] C:\Program Files\CardDetector\ICON225\CardDetector.exe
O4 - HKLM\..\Run: [BEWINTERNET-FR-DMESessionManager] C:\Program Files\OrangeBS\BEWInternet\SessionManager\SessionManager.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: wxvault.dll,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Malwarebytes:
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1539
Windows 5.1.2600 Service Pack 3
24.12.2008 19:57:24
mbam-log-2008-12-24 (19-57-24).txt
Type de recherche: Examen rapide
Eléments examinés: 53010
Temps écoulé: 8 minute(s), 5 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
et enfin Gmer:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-12-24 19:44:39
Windows 5.1.2600 Service Pack 3
---- Kernel code sections - GMER 1.0.14 ----
? pwtmltfz.sys Le fichier spécifié est introuvable. !
---- User code sections - GMER 1.0.14 ----
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 005F6DCE C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 005F72BA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 005F5BBB C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 005F737D C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 005F724D C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 005F5AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 005F73E3 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 005F6C79 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 005F595F C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 005F61DA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 005F65B6 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 005F6AEA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 005F633F C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 005F6261 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 005F62BB C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 005F6035 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 005F66AD C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 005F6A54 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 005F59B9 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 005F64E4 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 005F6EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 005F6F53 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 005F6725 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 005F7202 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 005F5C61 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 005F5BDA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 005F718A C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 005F6BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 005F644C C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 005F69D0 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 005F6135 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 005F7001 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 005F6D63 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 005F5E5A C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 005F6E31 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 005F5F4C C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 005F5A83 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 005F7108 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 005F7236 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 005F71E7 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.d
Je tente de désinfecter un ordi qui n'avait pas d'antivirus.
Ci-dessous 3 rapports après désinfection par AVG et Malwarebytes' :
Hijackthis
Malwarebytes' Anti Malware
Gmer
Pourriez vous me dire si vous voyez des restes?
Malwarebytes' a trouvé des restes de Vundo ( =( ):
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> No action taken.
Fichier(s) infecté(s):
C:\WINDOWS\system32\avgrsstx.dll (Trojan.Vundo) -> No action taken.
Merci pour le coup de main !
1) j'ai installé AVG (propriétaire novice en informatique) et voici tous les virus repérés:
http://img386.imageshack.us/img386/650/collectionwr6.th.jpg
2) Les rapports
Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:41, on 24.12.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\CardDetector\ICON225\CardDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Wave Systems Corp\Common\DataServer.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=4061114
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=4061114
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Document Manager] C:\Program Files\Wave Systems Corp\Services Manager\DocMgr\bin\docmgr.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\ScanSoft\NaturallySpeaking8\Program\ereg.exe" -r "C:\Program Files\ScanSoft\NaturallySpeaking8\Program\ereg.ini"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CardDetector] C:\Program Files\CardDetector\ICON225\CardDetector.exe
O4 - HKLM\..\Run: [BEWINTERNET-FR-DMESessionManager] C:\Program Files\OrangeBS\BEWInternet\SessionManager\SessionManager.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: wxvault.dll,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: DataSvr2 - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Common\DataServer.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: NTRU Hybrid TSS v2.0.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Malwarebytes:
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1539
Windows 5.1.2600 Service Pack 3
24.12.2008 19:57:24
mbam-log-2008-12-24 (19-57-24).txt
Type de recherche: Examen rapide
Eléments examinés: 53010
Temps écoulé: 8 minute(s), 5 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
et enfin Gmer:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-12-24 19:44:39
Windows 5.1.2600 Service Pack 3
---- Kernel code sections - GMER 1.0.14 ----
? pwtmltfz.sys Le fichier spécifié est introuvable. !
---- User code sections - GMER 1.0.14 ----
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 005F6DCE C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 005F72BA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 005F5BBB C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 005F737D C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 005F724D C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 005F5AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 005F73E3 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 005F6C79 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 005F595F C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 005F61DA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 005F65B6 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 005F6AEA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 005F633F C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 005F6261 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 005F62BB C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 005F6035 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 005F66AD C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 005F6A54 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 005F59B9 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 005F64E4 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 005F6EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 005F6F53 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 005F6725 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 005F7202 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 005F5C61 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 005F5BDA C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 005F718A C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 005F6BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 005F644C C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 005F69D0 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 005F6135 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 005F7001 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 005F6D63 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 005F5E5A C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 005F6E31 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 005F5F4C C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 005F5A83 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 005F7108 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 005F7236 C:\WINDOWS\system32\wxvault.dll
.text C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe[168] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 005F71E7 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\spoolsv.exe[304] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\WINDOWS\system32\wuauclt.exe[344] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Documents and Settings\O.Dulac\Bureau\gmer.exe[412] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] KERNEL32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Wave Systems Corp\Services Manager\Secure Update\AutoUpdate.exe[456] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetDriveTypeW 7C80B360 5 Bytes JMP 100061DA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileAttributesW 7C80B7DC 5 Bytes JMP 100065B6 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!DuplicateHandle 7C80DE8E 7 Bytes JMP 10006AEA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FindFirstFileExW 7C80EB0D 5 Bytes JMP 1000633F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FindClose 7C80EE67 7 Bytes JMP 10006261 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FindNextFileW 7C80EFCA 7 Bytes JMP 100062BB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 10006035 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileSizeEx 7C810A99 5 Bytes JMP 100066AD C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileInformationByHandle 7C810CFD 5 Bytes JMP 10006A54 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 100059B9 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetFileAttributesExW 7C811185 5 Bytes JMP 100064E4 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetLongPathNameW 7C8133E3 5 Bytes JMP 10006EA5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetShortPathNameW 7C81F256 5 Bytes JMP 10006F53 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!MoveFileWithProgressW 7C81F716 5 Bytes JMP 10006725 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!SetFilePointerEx 7C82103F 5 Bytes JMP 10007202 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CopyFileExW 7C827B1A 7 Bytes JMP 10005C61 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!ReadFileEx 7C82BCF3 5 Bytes JMP 10005BDA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!WriteFileGather 7C82DD9D 7 Bytes JMP 1000718A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!ReadFileScatter 7C82DE49 7 Bytes JMP 10006BE5 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!SetFileAttributesW 7C8314C5 5 Bytes JMP 1000644C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetOverlappedResult 7C8315B4 5 Bytes JMP 100069D0 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!DeleteFileW 7C831F4B 5 Bytes JMP 10006135 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!SetEndOfFile 7C83205E 5 Bytes JMP 10007001 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!FlushViewOfFile 7C835989 5 Bytes JMP 10006D63 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!RemoveDirectoryW 7C836F73 5 Bytes JMP 10005E5A C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!BackupRead 7C8571CA 5 Bytes JMP 10006E31 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateDirectoryExW 7C85B4FA 5 Bytes JMP 10005F4C C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!WriteFileEx 7C85D609 5 Bytes JMP 10005A83 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!GetCompressedFileSizeW 7C85E279 5 Bytes JMP 10007108 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] kernel32.dll!CreateHardLinkW 7C86C44C 7 Bytes JMP 10007236 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe[500] USER32.dll!ExitWindowsEx 7E3DA275 5 Bytes JMP 100071E7 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtFlushVirtualMemory 7C91D340 5 Bytes JMP 10006DCE C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtMapViewOfSection 7C91D500 5 Bytes JMP 100072BA C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtReadFile 7C91D9B0 5 Bytes JMP 10005BBB C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtUnmapViewOfSection 7C91DEF0 5 Bytes JMP 1000737D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] ntdll.dll!NtWriteFile 7C91DF60 5 Bytes JMP 1000724D C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!ReadFile 7C801812 7 Bytes JMP 10005AF1 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 100073E3 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!CreateFileMappingW 7C809420 5 Bytes JMP 10006C79 C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.dll!CloseHandle 7C809BD7 5 Bytes JMP 1000595F C:\WINDOWS\system32\wxvault.dll
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[612] kernel32.d
A voir également:
- Avis sur rapport de désinfection
- Plan rapport de stage - Guide
- Rapport de crash windows - Guide
- Impression rapport de stage ✓ - Forum Word
- Exemple de thème de rapport de stage en ressources humaines - Forum Réseau
- Acheter un rapport de stage - Forum Programmation
3 réponses
Bonsoir, en voyant le premier résultat de malwarebytes anti-malware il n'a pas supprimé les traces de vundo(no action taken). Je vous conseille d'effectuer un examen complet et pas rapide de l'ordinateur et regardez si les traces de vundo sont en quarantaine, et si c'est le cas , cliquer sur tout supprimer