Problème Google et sécurité.

Thomas59 -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,

depuis environ une semaine j'ai quelques soucis. Tout d'abord, à propos de Google, quand je clique sur un lien après une recherche, le lien s'affiche dans une nouvelle page, et le site ne s'affiche qu'au bout d'une dizaine de secondes. Parfois j'ai le site demandé, d'autre fois, je suis redirigée sur Google, ou encore, je tombe sur une pub. De plus, j'ai l'impression que la mise en page a légèrement changé (je n'ai jamais vraiment analysé comment c'était avant la semaine dernière, mais je la trouve bizarre). Les liens commerciaux sont bidouillards, et les descriptions des sites affichés dans la recherche sont parfois un peu louches aussi (ex: "class="f">6 posts - 5 authors - Last post: 4 days ago" ; je n'ai jamais eu ça auparavant).

Je soupçonne un petit malware, mais malheureusement, impossible de faire la mise à jour Avira ("impossible d'établir une connection internet" alors que je suis pourtant bel et bien connecté. Lorsque que je fais un scan, rien n'est trouvé. Même chose avec Ad-Aware qui ne détecte rien. Et quand à Spybot, impossible de le lancer (même chose après l'avoir réinstallé). Il se trouve pourtant bien dans les processus quand je vais dans le gestionnaire des tâches.

Merci d'avance de votre aide !
A voir également:

27 réponses

jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt,

Télécharge Rooter de l'équipe IDN sur ton bureau :
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/Rooter.exe?attachauth=ANoY7cpzQksLcJt-e1z30LGu7t4JjUhh8amzWs_oSPSJpXbXp8ythGbW2WF8ysioh5NNlarrn7zMnYCRfsT5rCwNrfw5_CZYELApylTiY_MGu0G6uKzWpLEF2YXM3tF7nKZZAWj0JSAajXlZhd8dIyI3MrZ-lAIT5ZrAdcrct9_7bshwVpaZRPizuMTv9SDvmvY31BX4Vvvh2F2Brp1cy_K0jtTTfjttEA%3D%3D&attredirects=2

! Déconnecte toi d'internet et ferme toutes applications en cours !

Exécute Rooter et laisse travailler l'outil .

Une fois terminé, poste le rapport obtenu pour analyse.

________________________

Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

NB : Les rapports sont sauvegardés dans le dossier C:\rsit
0
Thomas59
 
Salut,

merci de ta réponse, j'ai fais ce que tu m'avais décrit.

Tout d'abord, voici la copie de Rooter.txt:

Microsoft Windows XP Professional (5.1.2600) Service Pack 3

C:\ [Fixed] - NTFS - (Total:10244 Mo/Free:1106 Mo)
D:\ [Fixed] - NTFS - (Total:146820 Mo/Free:254 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)

28/03/2009|13:57

----------------------\\ Processes..

--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
---------- C:\WINDOWS\system32\CTHELPER.EXE
---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\Documents and Settings\Quentin\Desktop\Rooter.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe

----------------------\\ Search..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
DhcpNameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters]
DhcpNameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
DhcpNameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}]
NameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}]
DhcpNameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}]
NameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}]
DhcpNameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}]
NameServer REG_SZ 85.255.112.134,85.255.112.10
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}]
DhcpNameServer REG_SZ 85.255.112.134,85.255.112.10
[b]==> WAREOUT <==/b

----------------------\\ ROOTKIT !!



1 - "C:\Rooter$\Rooter_1.txt" - 28/03/2009|13:57

----------------------\\ Scan completed at 13:57


Ensuite, voici log.txt:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Quentin at 2009-03-28 13:59:57
Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (51%) free of 10 GB
Total RAM: 2047 MB (79% free)

HijackThis download failed

======Scheduled tasks folder======

C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
Octh Class - C:\Program Files\Orbitdownloader\orbitcth.dll [2008-06-10 187512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-12 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2008-01-28 1554256]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-03-20 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-20 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-20 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - C:\Program Files\Orbitdownloader\GrabPro.dll [2008-06-10 457848]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"=C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe [2002-12-03 45056]
"CTSysVol"=C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe [2003-07-02 57344]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2003-06-20 24576]
"AsioReg"=REGSVR32.EXE /S CTASIO.DLL []
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-03-19 515416]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-20 136600]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"=C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-03-12 3885408]
"NuonSoft Wallpaper Cycler"=C:\Program Files\NuonSoft\WallpaperCycler3\WallpaperCycler Lite.exe [2007-12-15 1947704]

C:\Documents and Settings\Quentin\Start Menu\Programs\Startup
RocketDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-06-03 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SynchronousMachineGroupPolicy"=0
"SynchronousUserGroupPolicy"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSMHelp"=1
"ForceClassicControlPanel"=1
"NoResolveTrack"=1
"NoResolveSearch"=1
"NoStartMenuPinnedList"=1
"NoSMConfigurePrograms"=1
"NoActiveDesktop"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HideRunAsVerb"=
"NoDriveTypeAutoRun"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2009-03-28 13:59:58 ----D---- C:\Program Files\trend micro
2009-03-28 13:59:57 ----D---- C:\rsit
2009-03-28 13:57:34 ----A---- C:\Rooter.txt
2009-03-28 13:57:23 ----D---- C:\Rooter$
2009-03-26 17:07:27 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-03-26 17:07:27 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-03-26 17:07:27 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-03-26 17:07:27 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-03-26 17:07:26 ----A---- C:\WINDOWS\system32\unrar.dll
2009-03-26 17:07:25 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-03-26 17:07:25 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-03-26 17:07:25 ----A---- C:\WINDOWS\system32\x264vfw.dll
2009-03-26 17:07:25 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-03-26 17:07:24 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-03-26 17:07:23 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-03-26 17:07:23 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-03-26 17:07:22 ----D---- C:\Documents and Settings\Quentin\Application Data\Real
2009-03-26 17:07:22 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-03-26 17:07:22 ----A---- C:\WINDOWS\system32\pthreadGC2.dll
2009-03-26 17:06:40 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
2009-03-26 17:06:37 ----D---- C:\Program Files\QT Lite
2009-03-25 18:14:59 ----D---- C:\Documents and Settings\Quentin\Application Data\Nero
2009-03-25 16:11:40 ----A---- C:\trace.txt
2009-03-25 16:03:45 ----D---- C:\Program Files\CCleaner
2009-03-24 17:25:23 ----D---- C:\WINDOWS\Sun
2009-03-21 15:04:20 ----A---- C:\WINDOWS\War3Unin.exe
2009-03-21 14:54:51 ----D---- C:\Documents and Settings\All Users\Application Data\{dd9a9e7625afb6d9307f2cd8e4c1abd8}
2009-03-20 16:38:46 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-03-19 18:52:01 ----D---- C:\Program Files\JRE
2009-03-19 18:51:59 ----D---- C:\Program Files\OpenOffice.org 3
2009-03-19 18:51:51 ----A---- C:\WINDOWS\system32\javaws.exe
2009-03-19 18:51:51 ----A---- C:\WINDOWS\system32\javaw.exe
2009-03-19 18:51:51 ----A---- C:\WINDOWS\system32\java.exe
2009-03-19 18:51:24 ----D---- C:\Documents and Settings\Quentin\Application Data\Sun
2009-03-19 17:38:20 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-03-19 17:26:27 ----HDC---- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-19 17:26:20 ----D---- C:\Program Files\Lavasoft
2009-03-19 17:26:20 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-03-19 17:06:33 ----D---- C:\Documents and Settings\Quentin\Application Data\gtk-2.0
2009-03-19 17:00:28 ----D---- C:\Program Files\Guitar Pro 5
2009-03-18 18:31:32 ----D---- C:\Program Files\PhotoFiltre Studio
2009-03-16 20:42:40 ----D---- C:\Documents and Settings\Quentin\Application Data\vlc
2009-03-16 20:42:24 ----D---- C:\Program Files\adslTV
2009-03-13 18:58:12 ----D---- C:\Documents and Settings\All Users\Application Data\TrackMania
2009-03-13 17:36:23 ----D---- C:\WINDOWS\system32\DirectX
2009-03-13 16:34:20 ----D---- C:\WINDOWS\system32\appmgmt
2009-03-12 17:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2009-03-12 16:55:21 ----D---- C:\Program Files\NuonSoft
2009-03-12 16:33:24 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-03-12 16:33:23 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-03-12 16:33:09 ----D---- C:\Program Files\Windows Media Connect 2
2009-03-12 16:33:04 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-03-12 16:32:26 ----D---- C:\WINDOWS\system32\LogFiles
2009-03-12 16:32:22 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-03-12 16:31:57 ----D---- C:\Program Files\Windows Media Player
2009-03-12 16:31:50 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-03-11 20:58:16 ----D---- C:\Program Files\Messenger Plus! Live
2009-03-11 19:05:05 ----D---- C:\Program Files\Microsoft
2009-03-11 19:04:48 ----D---- C:\Program Files\Windows Live SkyDrive
2009-03-11 19:02:01 ----D---- C:\Program Files\Common Files\Windows Live
2009-03-11 17:52:30 ----D---- C:\Program Files\Avira
2009-03-11 15:58:54 ----A---- C:\WINDOWS\NeroDigital.ini
2009-03-11 14:20:23 ----N---- C:\WINDOWS\Ctregrun.exe
2009-03-11 14:20:00 ----N---- C:\WINDOWS\Updreg.EXE
2009-03-11 14:19:56 ----N---- C:\WINDOWS\system32\SFCVRT32.DLL
2009-03-11 14:19:56 ----N---- C:\WINDOWS\system32\INETWH32.DLL
2009-03-11 14:19:56 ----N---- C:\WINDOWS\system32\CTWFLT32.DLL
2009-03-11 14:19:56 ----N---- C:\WINDOWS\CTRES.DLL
2009-03-11 14:19:56 ----N---- C:\WINDOWS\CTCCW.DLL
2009-03-11 14:19:56 ----N---- C:\WINDOWS\AC3API.INI
2009-03-11 14:19:55 ----N---- C:\WINDOWS\system32\CTL3D.DLL
2009-03-11 14:19:54 ----D---- C:\WINDOWS\system32\Defaults
2009-03-11 14:19:18 ----A---- C:\WINDOWS\system32\e10kxwdm.ini
2009-03-11 14:19:18 ----A---- C:\WINDOWS\system32\ctzapxx.ini
2009-03-11 14:19:18 ----A---- C:\WINDOWS\INRES.DLL
2009-03-11 14:19:18 ----A---- C:\WINDOWS\CTDCRES.DLL
2009-03-11 14:19:11 ----A---- C:\WINDOWS\system32\ctdvinst.dll
2009-03-11 14:19:11 ----A---- C:\WINDOWS\system32\ctcoinst.dll
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\sfman32.dll
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\PIAPROXY.DLL
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\KILLAPPS.EXE
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\KILL.INI
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\ENSDEF.INI
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\ENSDEF.EXE
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\ctsblfx.dll
2009-03-11 14:19:09 ----A---- C:\WINDOWS\system32\CTEMUPIA.DLL
2009-03-11 14:19:09 ----A---- C:\WINDOWS\MIDIDEF.EXE
2009-03-11 14:19:08 ----A---- C:\WINDOWS\system32\REGPLIB.EXE
2009-03-11 14:19:08 ----A---- C:\WINDOWS\system32\EAXAC3.DLL
2009-03-11 14:19:08 ----A---- C:\WINDOWS\system32\ctaudfx.dll
2009-03-11 14:19:08 ----A---- C:\WINDOWS\system32\CTAGENT.DLL
2009-03-11 14:19:08 ----A---- C:\WINDOWS\system32\commonfx.dll
2009-03-11 14:19:08 ----A---- C:\WINDOWS\READREG.EXE
2009-03-11 14:19:08 ----A---- C:\WINDOWS\PSCONV.EXE
2009-03-11 14:19:08 ----A---- C:\WINDOWS\DEVREG.DLL
2009-03-11 14:19:07 ----A---- C:\WINDOWS\system32\CTTHXCAL.DLL
2009-03-11 14:19:07 ----A---- C:\WINDOWS\system32\CTSPKHLP.DLL
2009-03-11 14:19:07 ----A---- C:\WINDOWS\system32\CTSCAL.DLL
2009-03-11 14:19:07 ----A---- C:\WINDOWS\system32\CTOSUSER.DLL
2009-03-11 14:19:07 ----A---- C:\WINDOWS\system32\CTMMEP.DLL
2009-03-11 14:19:07 ----A---- C:\WINDOWS\system32\CTHELPER.EXE
2009-03-11 14:19:02 ----A---- C:\WINDOWS\system32\CTDPROXY.DLL
2009-03-11 14:19:02 ----A---- C:\WINDOWS\system32\CTDCIFCE.DLL
2009-03-11 14:19:02 ----A---- C:\WINDOWS\system32\CTDC0001.DLL
2009-03-11 14:19:02 ----A---- C:\WINDOWS\system32\CTDC0000.DLL
2009-03-11 14:19:02 ----A---- C:\WINDOWS\system32\CTASIO.DLL
2009-03-11 14:19:01 ----A---- C:\WINDOWS\system32\a3d.dll
2009-03-11 14:18:29 ----A---- C:\WINDOWS\system32\AHQCpURes.dll
2009-03-11 14:14:29 ----D---- C:\WINDOWS\system32\Win9X
2009-03-11 14:09:53 ----SHD---- C:\RECYCLER
2009-03-11 14:09:34 ----A---- C:\WINDOWS\system32\h323log.txt
2009-03-11 14:07:54 ----N---- C:\WINDOWS\system32\MFCUIA32.DLL
2009-03-11 14:07:54 ----N---- C:\WINDOWS\system32\MFCANS32.DLL
2009-03-11 14:07:43 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-03-11 14:07:23 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2009-03-11 14:06:48 ----D---- C:\WINDOWS\system32\data
2009-03-11 14:06:47 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-03-11 14:06:08 ----A---- C:\WINDOWS\system32\usbui.dll
2009-03-11 14:06:08 ----A---- C:\WINDOWS\SBWIN.INI
2009-03-11 14:03:52 ----SHD---- C:\WINDOWS\Installer
2009-03-11 14:03:52 ----D---- C:\Program Files\Common Files\ODBC
2009-03-11 14:03:52 ----D---- C:\Program Files\Common Files
2009-03-11 14:03:52 ----D---- C:\Program Files
2009-03-11 14:03:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-11 14:03:52 ----A---- C:\WINDOWS\ODBCINST.INI
2009-03-11 14:03:45 ----A---- C:\WINDOWS\system32\irclass.dll
2009-03-11 14:03:44 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-03-11 14:03:44 ----A---- C:\WINDOWS\system32\batt.dll
2009-03-11 14:03:43 ----A---- C:\WINDOWS\system32\storprop.dll
2009-03-11 14:03:43 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-03-11 14:03:37 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-03-11 14:03:26 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-11 14:03:26 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-11 14:03:20 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-03-11 14:02:41 ----D---- C:\Program Files\Driver Cleaner Pro
2009-03-11 14:00:57 ----A---- C:\WINDOWS\system32\sfms32.dll
2009-03-11 14:00:56 ----A---- C:\WINDOWS\system32\ac3api.dll
2009-03-11 13:59:51 ----D---- C:\temp
2009-03-11 13:59:14 ----D---- C:\Documents and Settings
2009-03-11 13:59:13 ----SHD---- C:\System Volume Information
2009-03-11 13:58:50 ----SH---- C:\boot.ini
2009-03-11 13:56:51 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-11 13:56:51 ----RSD---- C:\WINDOWS\Fonts
2009-03-11 13:56:51 ----RD---- C:\WINDOWS\Offline Web Pages
2009-03-11 13:56:51 ----D---- C:\WINDOWS\WinSxS
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Web
2009-03-11 13:56:51 ----D---- C:\WINDOWS\WBEM
2009-03-11 13:56:51 ----D---- C:\WINDOWS\twain_32
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Temp
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\wins
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\wbem
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\usmt
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\spool
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\ShellExt
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\Setup
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\scripting
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\ras
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\PreInstall
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\mui
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\inetsrv
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\icsxml
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\ias
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\export
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\en-US
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\en
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\drivers
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\dhcp
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\config
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\3com_dmi
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\3076
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\2052
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1054
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1042
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1041
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1037
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1033
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1031
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1028
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32\1025
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system32
2009-03-11 13:56:51 ----D---- C:\WINDOWS\system
2009-03-11 13:56:51 ----D---- C:\WINDOWS\SoftwareDistribution
2009-03-11 13:56:51 ----D---- C:\WINDOWS\security
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Resources
2009-03-11 13:56:51 ----D---- C:\WINDOWS\repair
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Provisioning
2009-03-11 13:56:51 ----D---- C:\WINDOWS\PeerNet
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Network Diagnostic
2009-03-11 13:56:51 ----D---- C:\WINDOWS\mui
2009-03-11 13:56:51 ----D---- C:\WINDOWS\msapps
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Media
2009-03-11 13:56:51 ----D---- C:\WINDOWS\L2Schemas
2009-03-11 13:56:51 ----D---- C:\WINDOWS\java
2009-03-11 13:56:51 ----D---- C:\WINDOWS\inf
2009-03-11 13:56:51 ----D---- C:\WINDOWS\ime
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Help
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Driver Cache
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Debug
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Cursors
2009-03-11 13:56:51 ----D---- C:\WINDOWS\Config
2009-03-11 13:56:51 ----D---- C:\WINDOWS\AppPatch
2009-03-11 13:56:51 ----D---- C:\WINDOWS\addins
2009-03-11 13:56:51 ----D---- C:\WINDOWS
2009-03-11 13:56:37 ----D---- C:\Documents and Settings\Quentin\Application Data\Media Player Classic
2009-03-11 13:56:09 ----D---- C:\Documents and Settings\Quentin\Application Data\WinRAR
2009-03-11 13:49:47 ----D---- C:\Documents and Settings\Quentin\Application Data\Macromedia
2009-03-11 13:49:46 ----D---- C:\Documents and Settings\Quentin\Application Data\Adobe
2009-03-11 13:48:03 ----D---- C:\Documents and Settings\Quentin\Application Data\Mozilla
2009-03-11 13:42:36 ----D---- C:\Documents and Settings\Quentin\Application Data\atitray
2009-03-11 13:39:15 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2009-03-11 13:38:57 ----D---- C:\ATI
2009-03-11 13:37:51 ----D---- C:\Program Files\Ray Adams
2009-03-11 13:37:17 ----D---- C:\Program Files\ATITool
2009-03-11 13:34:42 ----D---- C:\WINDOWS\Prefetch
2009-03-11 13:31:02 ----D---- C:\Documents and Settings\Quentin\Application Data\Identities
2009-03-11 13:30:59 ----HD---- C:\Program Files\Uninstall Information
2009-03-11 13:30:52 ----D---- C:\Program Files\HHD Software
2009-03-11 13:30:47 ----D---- C:\Program Files\Windows Live
2009-03-11 13:30:27 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-11 13:30:20 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-03-11 13:29:52 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-03-11 13:29:33 ----D---- C:\Program Files\jv16 PowerTools
2009-03-11 13:28:21 ----D---- C:\Program Files\Paint.NET
2009-03-11 13:28:14 ----D---- C:\Documents and Settings\Quentin\Application Data\foobar2000
2009-03-11 13:28:10 ----D---- C:\Program Files\foobar2000
2009-03-11 13:27:51 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-03-11 13:27:00 ----D---- C:\Program Files\K-Lite Codec Pack
2009-03-11 13:26:51 ----D---- C:\Program Files\UltraFXP
2009-03-11 13:26:48 ----D---- C:\Program Files\mIRC
2009-03-11 13:26:39 ----D---- C:\Program Files\Common Files\Adobe
2009-03-11 13:26:39 ----D---- C:\Program Files\Adobe
2009-03-11 13:26:39 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-03-11 13:25:54 ----A---- C:\WINDOWS\system32\TwnLib4.dll
2009-03-11 13:25:54 ----A---- C:\WINDOWS\system32\imagXRA7.dll
2009-03-11 13:25:54 ----A---- C:\WINDOWS\system32\imagXR7.dll
2009-03-11 13:25:54 ----A---- C:\WINDOWS\system32\imagXpr7.dll
2009-03-11 13:25:53 ----D---- C:\Program Files\Nero
2009-03-11 13:25:53 ----D---- C:\Documents and Settings\All Users\Application Data\Nero
2009-03-11 13:25:53 ----A---- C:\WINDOWS\system32\imagX7.dll
2009-03-11 13:25:52 ----D---- C:\Program Files\Common Files\Nero
2009-03-11 13:25:17 ----D---- C:\Program Files\Java
2009-03-11 13:25:17 ----D---- C:\Program Files\Common Files\Java
2009-03-11 13:25:03 ----D---- C:\Program Files\FastStone MaxView
2009-03-11 13:25:00 ----D---- C:\Program Files\Mozilla Thunderbird
2009-03-11 13:24:53 ----D---- C:\WINDOWS\system32\Adobe
2009-03-11 13:24:47 ----D---- C:\downloads
2009-03-11 13:24:47 ----D---- C:\Documents and Settings\Quentin\Application Data\GrabPro
2009-03-11 13:24:45 ----D---- C:\Documents and Settings\Quentin\Application Data\Orbit
2009-03-11 13:24:44 ----D---- C:\Program Files\Orbitdownloader
2009-03-11 13:24:39 ----D---- C:\Program Files\Mozilla Firefox
2009-03-11 13:24:29 ----D---- C:\Program Files\7-Zip
2009-03-11 13:24:27 ----D---- C:\Program Files\WinRAR
2009-03-11 13:24:24 ----D---- C:\Program Files\JkDefrag
2009-03-11 13:21:21 ----D---- C:\WINDOWS\system32\XPSViewer
2009-03-11 13:21:21 ----D---- C:\Program Files\MSBuild
2009-03-11 13:21:18 ----D---- C:\Program Files\Reference Assemblies
2009-03-11 13:21:12 ----N---- C:\WINDOWS\system32\spmsg2.dll
2009-03-11 13:20:23 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-03-11 13:20:17 ----HDC---- C:\WINDOWS\$NtUninstallWIC$
2009-03-11 13:19:04 ----RSD---- C:\WINDOWS\assembly
2009-03-11 13:19:04 ----D---- C:\WINDOWS\Microsoft.NET
2009-03-11 13:19:02 ----D---- C:\WINDOWS\system32\URTTemp
2009-03-11 13:18:55 ----N---- C:\WINDOWS\system32\XpsSvcs.dll
2009-03-11 13:18:55 ----N---- C:\WINDOWS\system32\XPSSHHDR.dll
2009-03-11 13:18:55 ----N---- C:\WINDOWS\system32\WMPhoto.dll
2009-03-11 13:18:55 ----N---- C:\WINDOWS\system32\WindowsCodecsExt.dll
2009-03-11 13:18:55 ----N---- C:\WINDOWS\system32\WindowsCodecs.dll
2009-03-11 13:18:46 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-03-11 13:18:46 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2009-03-11 13:18:15 ----A---- C:\WINDOWS\ODBC.INI
2009-03-11 13:18:14 ----A---- C:\WINDOWS\system32\mdimon.dll
2009-03-11 13:18:00 ----D---- C:\Program Files\Common Files\DESIGNER
2009-03-11 13:17:58 ----D---- C:\WINDOWS\SHELLNEW
2009-03-11 13:17:58 ----D---- C:\WINDOWS\PCHEALTH
2009-03-11 13:17:58 ----D---- C:\Program Files\Microsoft Office
2009-03-11 13:17:34 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-11 13:17:34 ----D---- C:\Program Files\Creative
2009-03-11 13:17:32 ----D---- C:\Program Files\Common Files\InstallShield
2009-03-11 13:17:05 ----SD---- C:\Documents and Settings\Quentin\Application Data\Microsoft
2009-03-11 13:17:05 ----D---- C:\Documents and Settings\Quentin\Application Data\Creative
2009-03-11 13:17:05 ----ASH---- C:\Documents and Settings\Quentin\Application Data\desktop.ini
2009-03-11 13:16:52 ----SD---- C:\WINDOWS\system32\Microsoft
2009-03-11 13:16:51 ----N---- C:\WINDOWS\SchedLgU.Txt
2009-03-11 13:15:53 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2009-03-11 13:13:54 ----A---- C:\WINDOWS\BricoPackUninst.txt
2009-03-11 13:13:54 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2009-03-11 13:13:45 ----D---- C:\WINDOWS\BricoPacks
2009-03-11 13:13:22 ----HDC---- C:\WINDOWS\$NtUninstallKB942763$
2009-03-11 13:13:22 ----HD---- C:\WINDOWS\$hf_mig$
2009-03-11 13:13:15 ----A---- C:\WINDOWS\control.ini
2009-03-11 13:13:15 ----A---- C:\AUTOEXEC.BAT
2009-03-11 13:13:13 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-03-11 13:13:07 ----D---- C:\WINDOWS\system32\dllcache
2009-03-11 13:12:47 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-03-11 13:12:45 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-03-11 13:12:40 ----HD---- C:\Program Files\WindowsUpdate
2009-03-11 13:12:29 ----A---- C:\WINDOWS\system32\desktop.ini
2009-03-11 13:12:29 ----A---- C:\WINDOWS\desktop.ini
2009-03-11 13:12:27 ----D---- C:\Program Files\Common Files\Services
2009-03-11 13:12:27 ----A---- C:\WINDOWS\system32\acctres.dll
2009-03-11 13:12:26 ----SD---- C:\WINDOWS\Tasks
2009-03-11 13:12:25 ----D---- C:\Program Files\Common Files\MSSoap
2009-03-11 13:12:23 ----D---- C:\WINDOWS\system32\Macromed
2009-03-11 13:12:23 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-03-11 13:12:23 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-03-11 13:12:23 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-03-11 13:12:23 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\wups.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-03-11 13:12:22 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-03-11 13:12:21 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-03-11 13:12:21 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-03-11 13:12:21 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-03-11 13:12:21 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-03-11 13:12:21 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-03-11 13:12:20 ----A---- C:\WINDOWS\system32\inetres.dll
2009-03-11 13:12:20 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-03-11 13:12:18 ----D---- C:\Program Files\Outlook Express
2009-03-11 13:12:18 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-03-11 13:12:18 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-03-11 13:12:18 ----A---- C:\WINDOWS\system32\mstask.dll
2009-03-11 13:12:15 ----D---- C:\Program Files\Common Files\System
2009-03-11 13:12:14 ----D---- C:\Program Files\Internet Explorer
2009-03-11 13:11:40 ----A---- C:\WINDOWS\vbaddin.ini
2009-03-11 13:11:40 ----A---- C:\WINDOWS\vb.ini
2009-03-11 13:11:36 ----D---- C:\WINDOWS\Registration
2009-03-11 13:11:29 ----A---- C:\WINDOWS\system32\vb40032.dll
2009-03-11 13:11:28 ----A---- C:\WINDOWS\system32\ssleay32.dll
2009-03-11 13:11:28 ----A---- C:\WINDOWS\system32\msvcr71.dll
2009-03-11 13:11:28 ----A---- C:\WINDOWS\system32\msvcr70.dll
2009-03-11 13:11:28 ----A---- C:\WINDOWS\system32\msvcp71.dll
2009-03-11 13:11:27 ----A---- C:\WINDOWS\system32\msvcp70.dll
2009-03-11 13:11:27 ----A---- C:\WINDOWS\system32\msvci70.dll
2009-03-11 13:11:27 ----A---- C:\WINDOWS\system32\msstkprp.dll
2009-03-11 13:11:27 ----A---- C:\WINDOWS\system32\MSSTDFMT.DLL
2009-03-11 13:11:26 ----A---- C:\WINDOWS\system32\mfc71u.dll
2009-03-11 13:11:26 ----A---- C:\WINDOWS\system32\mfc71.dll
2009-03-11 13:11:25 ----A---- C:\WINDOWS\system32\mfc70u.dll
2009-03-11 13:11:25 ----A---- C:\WINDOWS\system32\mfc70.dll
2009-03-11 13:11:25 ----A---- C:\WINDOWS\system32\libssl32.dll
2009-03-11 13:11:25 ----A---- C:\WINDOWS\system32\libmmd.dll
2009-03-11 13:11:24 ----A---- C:\WINDOWS\system32\libintl3.dll
2009-03-11 13:11:24 ----A---- C:\WINDOWS\system32\libiconv2.dll
2009-03-11 13:11:24 ----A---- C:\WINDOWS\system32\libeay32.dll
2009-03-11 13:11:24 ----A---- C:\WINDOWS\system32\cygwinb19.dll
2009-03-11 13:11:23 ----A---- C:\WINDOWS\system32\cygwin1.dll
2009-03-11 13:11:23 ----A---- C:\WINDOWS\system32\autoitx3.dll
2009-03-11 13:11:23 ----A---- C:\WINDOWS\system32\atl71.dll
2009-03-11 13:11:23 ----A---- C:\WINDOWS\system32\atl70.dll
2009-03-11 13:11:22 ----D---- C:\WINDOWS\system32\cplicons
2009-03-11 13:11:22 ----A---- C:\WINDOWS\system32\memtest.exe
2009-03-11 13:11:21 ----D---- C:\Program Files\Unlocker
2009-03-11 13:11:20 ----D---- C:\Program Files\SysInternals
2009-03-11 13:11:20 ----A---- C:\WINDOWS\system32\Contig.exe
2009-03-11 13:11:19 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-03-11 13:11:19 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-03-11 13:11:19 ----A---- C:\WINDOWS\system32\getuname.dll
2009-03-11 13:11:19 ----A---- C:\WINDOWS\system32\charmap.exe
2009-03-11 13:11:18 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-03-11 13:11:18 ----A---- C:\WINDOWS\system32\calc.exe
2009-03-11 13:11:15 ----D---- C:\WINDOWS\system32\MsDtc
2009-03-11 13:11:15 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-03-11 13:11:15 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-03-11 13:11:15 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-03-11 13:11:14 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-03-11 13:11:13 ----D---- C:\WINDOWS\system32\Com
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\stclient.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\colbact.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-03-11 13:11:13 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-03-11 13:11:12 ----A---- C:\WINDOWS\system32\comuid.dll
2009-03-11 13:11:12 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-03-11 13:11:12 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-03-11 13:11:12 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-03-11 13:11:08 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-03-11 13:11:08 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-03-11 13:11:08 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-03-11 13:11:07 ----A---- C:\WINDOWS\system32\cmprops.dll

======List of files/folders modified in the last 1 months======

2009-03-12 16:42:11 ----A---- C:\WINDOWS\win.ini
2009-03-11 14:03:49 ----A---- C:\WINDOWS\system.ini
2009-03-11 13:15:52 ----A---- C:\WINDOWS\system32\uxtheme.dll
2009-03-11 13:09:40 ----A---- C:\WINDOWS\system32\wrap_oal.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 ATITool;ATITool Overclocking Utility; C:\WINDOWS\system32\DRIVERS\ATITool.sys [2007-08-08 28968]
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-11 75072]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-11-08 21248]
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2008-07-09 16877]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-07-09 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2008-07-09 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2008-07-09 55936]
R2 PfModNT;PfModNT; \??\C:\WINDOWS\system32\drivers\PfModNT.sys []
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-06-03 3100160]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2003-07-10 651792]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2003-06-20 509328]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2003-06-20 6144]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2003-06-20 136016]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2003-07-10 145232]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2003-06-27 860592]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2003-06-27 159040]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-07-09 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-07-09 12160]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2003-06-20 190208]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-07-09 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-04-29 288896]
S3 COMMONFX.DLL;COMMONFX.DLL; C:\WINDOWS\system32\COMMONFX.DLL [2003-06-20 114688]
S3 CT20XUT.DLL;CT20XUT.DLL; C:\WINDOWS\system32\CT20XUT.DLL []
S3 CTAUDFX.DLL;CTAUDFX.DLL; C:\WINDOWS\system32\CTAUDFX.DLL [2003-06-20 589824]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2003-03-27 287920]
S3 CTEAPSFX.DLL;CTEAPSFX.DLL; C:\WINDOWS\system32\CTEAPSFX.DLL []
S3 CTEDSPFX.DLL;CTEDSPFX.DLL; C:\WINDOWS\system32\CTEDSPFX.DLL []
S3 CTEDSPIO.DLL;CTEDSPIO.DLL; C:\WINDOWS\system32\CTEDSPIO.DLL []
S3 CTEDSPSY.DLL;CTEDSPSY.DLL; C:\WINDOWS\system32\CTEDSPSY.DLL []
S3 CTERFXFX.DLL;CTERFXFX.DLL; C:\WINDOWS\system32\CTERFXFX.DLL []
S3 CTEXFIFX.DLL;CTEXFIFX.DLL; C:\WINDOWS\system32\CTEXFIFX.DLL []
S3 CTHWIUT.DLL;CTHWIUT.DLL; C:\WINDOWS\system32\CTHWIUT.DLL []
S3 CTSBLFX.DLL;CTSBLFX.DLL; C:\WINDOWS\system32\CTSBLFX.DLL [2003-06-20 602112]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirScheduler;Planificateur Avira AntiVir Personal - Free Antivirus; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-06-03 552960]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-20 152984]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-19 951632]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-06-02 593920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-07-09 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]

-----------------EOF-----------------


Et pour finir, info.txt:
info.txt logfile of random's system information tool 1.06 2009-03-28 14:00:30

======Uninstall list======

-->"C:\Program Files\Creative\SBAudigy2ZS\Program\Ctzapxx.EXE" /W /U /S
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{236FADD8-58FD-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5210ED6D-52A9-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5CDDF96A-BC34-4D72-9ABA-E1FFF0C39977}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87499F38-FD69-4A2B-B41A-BAB8DE9B94FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9A4D2983-4662-4387-BE3D-4CFC2FA9C100}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A1185190-514F-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B3549608-69D3-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DEBD7BF3-5856-11D6-A285-00A0CC51B2FE}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB2292C6-1F0A-11D7-AB2D-0090271A23A2}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x9
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FD851F7E-F887-405D-9E1C-488811113EF3}\setup.exe" -l0x9 /remove
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9
7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9 Lite-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Adobe Shockwave Player-->MsiExec.exe /X{3E864262-1415-4308-9FF1-870BB20ED45D}
adsl TV-->C:\Program Files\adslTV\Uninstal.exe
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATITool Overclocking Utility-->"C:\Program Files\ATITool\Uninstall.exe"
Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Creative Audio Console-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9 /remove
Creative System Information-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87499F38-FD69-4A2B-B41A-BAB8DE9B94FE}\setup.exe" -l0x9 /remove
DH Driver Cleaner Professional Edition-->C:\Program Files\Driver Cleaner Pro\Uninst.exe
FastStone MaxView 2.1-->C:\Program Files\FastStone MaxView\uninst.exe
foobar2000 v0.9.4.5-->"C:\Program Files\foobar2000\uninstall.exe"
Guitar Pro 5.2-->"C:\Program Files\Guitar Pro 5\unins000.exe"
HHD Software Free Hex Editor 3.12-->"C:\Program Files\HHD Software\Hex Editor 3.x\Uninstaller.exe"
HijackThis 2.0.2-->"C:\Documents and Settings\Quentin\Desktop\HijackThis.exe" /uninstall
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
jv16 PowerTools 1.3-->"C:\Program Files\jv16 PowerTools\unins000.exe"
K-Lite Mega Codec Pack 4.7.0-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783}
Microsoft .NET Framework 3.5-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe
Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office Professional Edition 2003-->MsiExec.exe /I{9011040C-6000-11D3-8CFE-0150048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.14)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
Nero 8 Lite 8.3.2.1b-->"C:\Program Files\Nero\unins000.exe"
NuonSoft Wallpaper Cycler 3.5 Lite-->"C:\Program Files\NuonSoft\WallpaperCycler3\unins000.exe"
OpenOffice.org 3.0-->MsiExec.exe /I{F44DA61E-720D-4E79-871F-F6E628B33242}
Orbit Downloader-->"C:\Program Files\Orbitdownloader\unins000.exe"
Pack Vista Inspirat 2 1.0-->C:\WINDOWS\BricoPacks\Vista Inspirat 2\Remove.exe
Paint.NET v3.36-->MsiExec.exe /X{43602F34-1AA3-44FB-AEB2-D08C2C73743F}
PhotoFiltre Studio-->"C:\Program Files\PhotoFiltre Studio\Uninst.exe"
QT Lite 2.8.0-->"C:\Program Files\QT Lite\unins000.exe"
Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
Slayers Online-->"D:\_Jeux\Slayers Online\unins000.exe"
Sound Blaster Audigy 2 ZS-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E2514D9-DC24-4634-B348-61F3EF0F1628}\SETUP.EXE" -l0x9
Spybot - Search & Destroy Updates-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SysInternals Programs Collection v3.5-->rundll32.exe advpack.dll,LaunchINFSection SysInter.inf,DefaultUninstall
TmNationsForever-->"D:\_Jeux\Trackmania Nations Forever\unins000.exe"
UltraFXP (remove only)-->"C:\Program Files\UltraFXP\uninstall.exe"
Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
Windows Live Messenger-->MsiExec.exe /X{0AAA9C97-74D4-47CE-B089-0B147EF3553C}
Windows Live Sign-in Assistant-->MsiExec.exe /I{45338B07-A236-4270-9A77-EBB4115517B5}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe

======Hosts File======

127.0.0.1 search.netzany.co
127.0.0.1 urawa.cool.ne.jp
127.0.0.1 gamehouse.com
127.0.0.1 www.gamehouse.com
127.0.0.1 kqzyfj.com
127.0.0.1 www.kqzyfj.com
127.0.0.1 apmebf.com
127.0.0.1 www.apmebf.com
127.0.0.1 emjcd.com
127.0.0.1 www.emjcd.com

Securitycenter WMI appears to be broken

======System event log======

Computer Name: JOSSNETWORK
Event Code: 3032
Message: The redirector was unable to register the domain WORKGROUP on to transport NetBT_Tcpip_{35851DA5-9960-43FC-AD6C for the following reason: . Transport has been taken offline.

Record Number: 70
Source Name: MRxSmb
Time Written: 20090311142118.000000+060
Event Type: warning
User:

Computer Name: JOSSNETWORK
Event Code: 10005
Message: DCOM got error "%1058" attempting to start the service wuauserv with arguments ""
in order to run the server:
{E60687F7-01A1-40AA-86AC-DB1CBF673334}

Record Number: 60
Source Name: DCOM
Time Written: 20090311141251.000000+060
Event Type: error
User: JOSSNETWORK\Quentin

Computer Name: JOSSNETWORK
Event Code: 20
Message: Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- mxdwdrv.dll, unidrvui.dll, mxdwdui.gpd, unidrv.hlp, mxdwdui.dll, mxdwdui.ini, stddtype.gdl, stdnames.gpd, stdschem.gdl, stdschmx.gdl, unidrv.dll, unires.dll, XpsSvcs.dll.

Record Number: 15
Source Name: Print
Time Written: 20090311132113.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: JOSSNETWORK
Event Code: 20
Message: Printer Driver Microsoft Office Document Image Writer Driver for Windows NT x86 Version-3 was added or updated. Files:- mdigraph.dll, mdiui.dll, mdiui.dll.

Record Number: 13
Source Name: Print
Time Written: 20090311131814.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: JOSSNETWORK
Event Code: 60055
Message: Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.
Record Number: 8
Source Name: Setup
Time Written: 20090311131614.000000+060
Event Type: error
User:

=====Application event log=====

Computer Name: JOSSNETWORK
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 12
Source Name: WinMgmt
Time Written: 20090311131208.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: JOSSNETWORK
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.

Record Number: 11
Source Name: WinMgmt
Time Written: 20090311131208.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: JOSSNETWORK
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 10
Source Name: WinMgmt
Time Written: 20090311131208.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: JOSSNETWORK
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 9
Source Name: WinMgmt
Time Written: 20090311131208.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: JOSSNETWORK
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.

Record Number: 8
Source Name: WinMgmt
Time Written: 20090311131207.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 9, GenuineIntel
"PROCESSOR_REVISION"=0209
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"DEVMGR_SHOW_DETAILS"=1
"DEVMGR_SHOW_NONPRESENT_DEVICES"=1

-----------------EOF-----------------
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
smit fraud fix (colle le rapport)

1/ telecharger :

http://siri.urz.free.fr/Fix/SmitfraudFix.php

2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes.
0
Thomas59
 
Salut, voici le rapport du logiciel:

Scan done at 19:14:36,67, 28/03/2009
Run from C:\Documents and Settings\Quentin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Quentin\Desktop\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

»»»»»»»»»»»»»»»»»»»»»»»» C:\

C:\autorun.inf FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Quentin

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Quentin\LOCALS~1\Temp

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Quentin\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Quentin\FAVORI~1

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, following keys are not inevitably infected!!!

o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, following keys are not inevitably infected!!!

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, following keys are not inevitably infected!!!

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

Your computer may be victim of a DNS Hijack: 85.255.x.x detected !

Description: 3Com 3C940 Gigabit LOM Ethernet Adapter
DNS Server Search Order: 85.255.112.200
DNS Server Search Order: 85.255.112.182

HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: DhcpNameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: DhcpNameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: DhcpNameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.200,85.255.112.182
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=85.255.112.200,85.255.112.182

»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

»»»»»»»»»»»»»»»»»»»»»»»» End
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
refais smitfraudfix , choisi l'option 5 et colle le rapport

puis

scan avec malwarebyte , fais un scan minutieux et colle le rapport obtenu et vire ce qui est trouvé:

https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­

______________________

Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

NB : Les rapports sont sauvegardés dans le dossier C:\rsit
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Thomas59
 
Lorsque je fais l'option 5 de Smitfraudfix, j'ai un message d'alerte :
"Your computer may be victim of a DNS Hijack : 85.255.x.x" (bon jusque là ok, c'est dans ma config internet...)
[...]
"Do you want to set your network to dynamic -DHCP- server ?"

C'est cette dernière phrase que je trouve bizarre. En quoi cela consiste ? Et est-ce que cela changera quelque chose dans ma connexion et mon réseau ?
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
tu mets yes
0
Thomas59
 
Voici le rapport de Smitfraud (option 5):
SmitFraudFix v2.405

Scan done at 20:35:37,39, 29/03/2009
Run from C:\Documents and Settings\Quentin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix

Your computer may be victim of a DNS Hijack: 85.255.x.x detected !

Description: 3Com 3C940 Gigabit LOM Ethernet Adapter
DNS Server Search Order: 85.255.112.74
DNS Server Search Order: 85.255.112.102

HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: NameServer=85.255.112.74,85.255.112.102

»»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix

HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.74,85.255.112.102
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=85.255.112.74,85.255.112.102


Malwarebytes ne veut pas se lancer (il n'apparait même pas dans le gestionnaire des tâches), mais je ne sais pas pourquoi.

Quand à RSIT, je l'ai déjà effectuer (voir plus haut).

A propos du message d'erreur que j'avais eu avec Smitfraud, ça m'a reset ma connection internet (les données en tout cas, avec les IPs...), est-ce normal et y-a-t'il eu d'autres changements ?
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général) puis lance smitfraudfix , sélectionne l'option 2 et appuyer sur entrée pour commencer la désinfection. lorsque le programme demande si tu veux nettoyer le registre mets oui en tapant 0 et entrée (colle le rapport dans ton prochain message)

__________________

remets toi en mode normal et refais l'option 5 et mets le rapport

________________

colle un rapport hijackthis

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

manuel :

https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

Ensuite avec Explorer créer un dossier c:\hijackthis
Décompresser Hijackthis dans ce dossier.
C'est important pour les sauvegardes."
0
Thomas59
 
N'est-il pas dangereux de nettoyer le registre ? Je veux dire: si je le nettoie, cela ,aura des conséquences (comment windows marche si il manqumykue des objets dedans ?).
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
non il faut le faire car tu es toujours détourné en ukraine !
0
Thomas9
 
Rapport option 2:
SmitFraudFix v2.405

Scan done at 18:56:27,57, 31/03/2009
Run from C:\Documents and Settings\Quentin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process

»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

127.0.0.1 search.netzany.co
127.0.0.1 urawa.cool.ne.jp
127.0.0.1 gamehouse.com
127.0.0.1 www.gamehouse.com
127.0.0.1 kqzyfj.com
127.0.0.1 www.kqzyfj.com
127.0.0.1 apmebf.com
127.0.0.1 www.apmebf.com
...

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

»»»»»»»»»»»»»»»»»»»»»»»» RK

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""

»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» End


A noter que durant l'opération, le fichier cleanmgr n'a pas été trouvé, je ne sais pas si c'était important où pas.

Ensuite, rapport de l'option 5:

SmitFraudFix v2.405

Scan done at 19:02:14,23, 31/03/2009
Run from C:\Documents and Settings\Quentin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» DNS Before Fix

Description: 3Com 3C940 Gigabit LOM Ethernet Adapter
DNS Server Search Order: 212.27.53.252
DNS Server Search Order: 212.27.54.252

HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252

»»»»»»»»»»»»»»»»»»»»»»»» DNS After Fix

Description: 3Com 3C940 Gigabit LOM Ethernet Adapter
DNS Server Search Order: 212.27.53.252
DNS Server Search Order: 212.27.54.252

HKLM\SYSTEM\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252
HKLM\SYSTEM\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252
HKLM\SYSTEM\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer=212.27.53.252,212.27.54.252


Et le rapport HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:07:34, on 31/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NuonSoft Wallpaper Cycler] "C:\Program Files\NuonSoft\WallpaperCycler3\WallpaperCycler Lite.exe" -cycle_and_exit
O4 - HKUS\S-1-5-19\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
ok parfait tu n'est plus détourné!

vire ad aware qui est dépassé si tu paye pas

et
mets malwarebyte a la place

scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:

https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­­

______________________

puis

Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

NB : Les rapports sont sauvegardés dans le dossier C:\rsit
0
Thomas59
 
Bonjour,

J'ai essayé de réinstaller Malwarebyte, néanmoins, il ne marche toujours pas (pas de lancement du tout, tout comme Spybot).

Voici le rapport log.txt de RSIT (le fichier info.txt) n'apparait plus et ce après avoir re-télécharger le logiciel, bizarre):

Logfile of random's system information tool 1.06 (written by random/random)
Run by Quentin at 2009-04-02 17:59:13
Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (48%) free of 10 GB
Total RAM: 2047 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:59:18, on 02/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Quentin\Desktop\RSIT.exe
C:\Program Files\trend micro\HijackThis\Quentin.exe

O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NuonSoft Wallpaper Cycler] "C:\Program Files\NuonSoft\WallpaperCycler3\WallpaperCycler Lite.exe" -cycle_and_exit
O4 - HKUS\S-1-5-19\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
0
Thomas59
 
J'ai oublié de préciser que j'ai toujours un problème avec Google. Les pages ne s'ouvrent plus dans un nouvel onglet, mais le temps de chargement est toujours de 5-10sec, et je suis parfois redirigée vers des pubs.
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
Télécharge combofix (par sUBs) ici :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

et enregistre le sur le bureau.

déconnecte toi d'internet et ferme toutes tes applications.

désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

double-clique sur combofix.exe et suis les instructions

à la fin, il va produire un rapport C:\ComboFix.txt

réactive ton parefeu, ton antivirus, la garde de ton antispyware

copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

Tu as un tutoriel complet ici :

http://www.bleepingcomputer.com/combofix/fr/comment-utiliser­-combofix
0
Thomas59
 
Le lien ne fonctionne pas, pourrais-tu me le redonner ?
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
0
Thomas59
 
Salut,

voici le rapport de Combofix. Apparemment il y avait des fichiers malveillants que ni l'antivirus, ni ad-aware n'avaient trouvés:

ComboFix 09-04-03.01 - Quentin 2009-04-04 13:54:09.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1630 [GMT 2:00]
Running from: c:\documents and settings\Quentin\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\gaopdxcxeypbpydwwqbuhhbqpkltenlefrqaim.sys
c:\windows\system32\drivers\gaopdxhwaqbrfvkiomtbqvrgicbdjnthxirprr.sys
c:\windows\system32\drivers\gaopdxnbrxcwfowsrufnaqksmevatconbxfpro.sys
c:\windows\system32\drivers\gaopdxnsecbdviuterttivkyfwoxapquowolre.sys
c:\windows\system32\drivers\gaopdxqvcacplwknchhhcrtkuotvfnyrwwfvyq.sys
c:\windows\system32\drivers\gaopdxykdjxyaosunjexlmjepsxowrmmecotep.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxwowtltebbwkllntjlapgsdotonxcoevy.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\instsrv.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\pthreadGC2.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gaopdxserv.sys

((((((((((((((((((((((((( Files Created from 2009-03-04 to 2009-04-04 )))))))))))))))))))))))))))))))
.

2009-04-02 17:39 . 2008-04-13 22:15 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2009-04-02 17:34 . 2009-04-02 17:34 <DIR> d-------- c:\program files\Canon
2009-04-02 17:34 . 2009-04-02 17:34 <DIR> d--h----- C:\CanoScan
2009-04-02 17:34 . 2002-05-24 03:04 389,180 --a------ c:\windows\system32\UCS32P.DLL
2009-04-02 17:34 . 2004-03-17 19:54 274,432 --a------ c:\windows\system32\CNQL1208.dll
2009-04-02 17:34 . 2004-03-01 11:43 40,960 --a------ c:\windows\system32\CNQU77.DLL
2009-04-02 17:31 . 2009-04-02 17:31 <DIR> d-------- c:\windows\StartHtmico
2009-04-02 17:31 . 2009-04-02 17:31 <DIR> d-------- c:\windows\IP4000,3000
2009-04-02 17:31 . 2009-04-02 17:31 <DIR> d--h----- C:\BJPrinter
2009-04-02 17:31 . 2004-04-23 07:00 116,736 --a------ c:\windows\system32\CNMLM64.DLL
2009-04-02 17:31 . 2004-03-11 18:06 86,016 -ra------ c:\windows\system32\CNMCP64.exe
2009-04-02 17:31 . 2004-04-23 07:00 7,680 --a------ c:\windows\system32\CNMVS64.DLL
2009-04-01 12:24 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-04-01 12:23 . 2009-04-01 12:24 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-01 12:23 . 2009-04-01 12:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-01 12:23 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-30 20:01 . 2009-03-19 18:38 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-03-29 19:17 . 2009-03-29 19:17 <DIR> d-------- c:\documents and settings\Quentin\Application Data\OpenOffice.org
2009-03-28 14:59 . 2009-03-28 15:00 <DIR> d-------- C:\rsit
2009-03-28 14:59 . 2009-03-31 19:04 <DIR> d-------- c:\program files\trend micro
2009-03-28 14:57 . 2009-03-28 14:57 <DIR> d-------- C:\Rooter$
2009-03-26 18:06 . 2009-03-26 18:06 <DIR> d-------- c:\program files\QT Lite
2009-03-26 18:06 . 2009-03-26 18:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-03-26 18:06 . 2009-01-05 17:18 90,112 --a------ c:\windows\system32\QuickTimeVR.qtx
2009-03-26 18:06 . 2009-01-05 17:18 57,344 --a------ c:\windows\system32\QuickTime.qts
2009-03-25 19:14 . 2009-03-25 19:14 <DIR> d-------- c:\documents and settings\Quentin\Application Data\Nero
2009-03-25 17:03 . 2009-03-25 17:03 <DIR> d-------- c:\program files\CCleaner
2009-03-24 18:25 . 2009-03-24 18:25 <DIR> d-------- c:\windows\Sun
2009-03-21 16:04 . 2009-03-21 16:04 126,976 --a------ c:\windows\War3Unin.exe
2009-03-21 16:04 . 2009-03-21 16:17 25,556 --a------ c:\windows\War3Unin.dat
2009-03-21 16:04 . 2009-03-21 16:04 2,829 --a------ c:\windows\War3Unin.pif
2009-03-21 15:54 . 2009-03-21 15:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\{dd9a9e7625afb6d9307f2cd8e4c1abd8}
2009-03-20 17:38 . 2009-03-09 05:19 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-19 19:52 . 2009-03-19 19:52 <DIR> d-------- c:\program files\JRE
2009-03-19 19:51 . 2009-03-19 19:51 <DIR> d-------- c:\program files\OpenOffice.org 3
2009-03-19 18:38 . 2009-03-19 18:38 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-19 18:38 . 2009-03-19 18:37 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-03-19 18:26 . 2009-03-19 18:26 <DIR> d-------- c:\program files\Lavasoft
2009-03-19 18:26 . 2009-03-19 18:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-19 18:26 . 2009-03-19 18:26 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-03-19 18:06 . 2009-03-19 18:23 <DIR> d-------- c:\documents and settings\Quentin\Application Data\gtk-2.0
2009-03-19 18:06 . 2009-03-19 18:06 <DIR> d-------- c:\documents and settings\Quentin\.thumbnails
2009-03-19 18:05 . 2009-03-19 18:25 <DIR> d-------- c:\documents and settings\Quentin\.gimp-2.6
2009-03-19 18:05 . 2009-03-19 18:05 <DIR> d-------- c:\documents and settings\Quentin\.gegl-0.0
2009-03-19 18:00 . 2009-03-19 18:00 <DIR> d-------- c:\program files\Guitar Pro 5
2009-03-18 19:31 . 2009-03-18 19:43 <DIR> d-------- c:\program files\PhotoFiltre Studio
2009-03-18 19:31 . 2009-03-18 19:31 45 ---h----- c:\windows\dsez6020.dat
2009-03-16 21:42 . 2009-04-03 20:02 <DIR> d-------- c:\program files\adslTV
2009-03-16 21:42 . 2009-03-16 23:02 <DIR> d-------- c:\documents and settings\Quentin\Application Data\vlc
2009-03-13 19:58 . 2009-03-27 17:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\TrackMania
2009-03-12 21:06 . 2009-03-12 21:06 664 --a------ c:\windows\system32\d3d9caps.dat
2009-03-12 21:06 . 2009-03-12 21:06 552 --a------ c:\windows\system32\d3d8caps.dat
2009-03-12 20:25 . 2009-03-15 00:15 926 --a------ c:\windows\system32\CTHELPER.RPT
2009-03-12 18:04 . 2009-03-23 19:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-12 17:55 . 2009-03-12 17:55 <DIR> d-------- c:\program files\NuonSoft
2009-03-12 17:33 . 2009-03-12 17:33 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-03-12 17:33 . 2009-03-12 17:33 <DIR> d--hs---- c:\documents and settings\All Users\DRM
2009-03-12 17:33 . 2009-03-12 17:33 23,392 --a------ c:\windows\system32\nscompat.tlb
2009-03-12 17:33 . 2009-03-12 17:33 16,832 --a------ c:\windows\system32\amcompat.tlb
2009-03-12 17:32 . 2009-03-12 17:32 <DIR> d-------- c:\windows\system32\LogFiles
2009-03-11 21:58 . 2009-03-11 21:58 <DIR> d-------- c:\program files\Messenger Plus! Live
2009-03-11 20:05 . 2009-03-11 20:05 <DIR> d-------- c:\program files\Microsoft
2009-03-11 20:05 . 2009-04-04 13:01 <DIR> d-------- c:\documents and settings\Quentin\Tracing
2009-03-11 20:04 . 2009-03-11 20:04 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-03-11 20:02 . 2009-03-11 20:02 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-03-11 19:04 . 2009-03-11 19:04 0 --a------ c:\windows\nsreg.dat
2009-03-11 18:52 . 2009-03-11 18:52 <DIR> d-------- c:\program files\Avira
2009-03-11 16:58 . 2009-04-03 22:12 69 --a------ c:\windows\NeroDigital.ini
2009-03-11 15:26 . 2003-12-31 09:48 106,496 --a------ c:\windows\system32\drivers\CTTHXCal.DLL
2009-03-11 15:21 . 2009-04-04 13:49 4,923,561 --a------ c:\windows\{00000002-00000000-0000000D-00001102-00000004-20021102}.CDF
2009-03-11 15:20 . 2000-05-11 02:00 90,112 --------- c:\windows\Updreg.EXE
2009-03-11 15:20 . 1999-10-10 19:00 41,984 --------- c:\windows\Ctregrun.exe
2009-03-11 15:20 . 2009-04-04 13:52 32,592 --a------ c:\windows\system32\BMXStateBkp-{00000002-00000000-0000000D-00001102-00000004-20021102}.rfx
2009-03-11 15:20 . 2009-04-04 13:52 32,592 --a------ c:\windows\system32\BMXState-{00000002-00000000-0000000D-00001102-00000004-20021102}.rfx
2009-03-11 15:20 . 2009-04-04 13:52 31,728 --a------ c:\windows\system32\BMXCtrlState-{00000002-00000000-0000000D-00001102-00000004-20021102}.rfx
2009-03-11 15:20 . 2009-04-04 13:52 31,728 --a------ c:\windows\system32\BMXBkpCtrlState-{00000002-00000000-0000000D-00001102-00000004-20021102}.rfx
2009-03-11 15:20 . 2009-04-04 13:52 1,080 --a------ c:\windows\system32\settingsbkup.sfm
2009-03-11 15:20 . 2009-04-04 13:52 1,080 --a------ c:\windows\system32\settings.sfm
2009-03-11 15:20 . 2009-04-04 13:52 384 --a------ c:\windows\system32\DVCStateBkp-{00000002-00000000-0000000D-00001102-00000004-20021102}.dat
2009-03-11 15:20 . 2009-04-04 13:52 384 --a------ c:\windows\system32\DVCState-{00000002-00000000-0000000D-00001102-00000004-20021102}.dat
2009-03-11 15:18 . 2001-05-28 14:47 32,768 --a------ c:\windows\system32\AudioHQU.cpl
2009-03-11 15:18 . 2001-05-28 14:47 12,288 --a------ c:\windows\system32\AHQCpURes.dll
2009-03-11 15:18 . 2009-03-11 15:18 184 --a------ c:\windows\system32\e000002.dat
2009-03-11 15:16 . 2003-03-05 09:07 15,840 --a------ c:\windows\system32\drivers\pfmodnt.sys
2009-03-11 15:14 . 2009-03-11 15:14 <DIR> d-------- c:\windows\system32\Win9X
2009-03-11 15:09 . 2008-04-14 00:15 172,416 --a------ c:\windows\system32\drivers\kmixer.sys
2009-03-11 15:09 . 2008-04-13 22:09 142,592 --a------ c:\windows\system32\drivers\aec.sys
2009-03-11 15:09 . 2008-04-14 00:47 83,072 --a------ c:\windows\system32\drivers\wdmaud.sys
2009-03-11 15:09 . 2008-04-14 00:45 60,800 --a------ c:\windows\system32\drivers\sysaudio.sys
2009-03-11 15:09 . 2008-04-14 00:15 56,576 --a------ c:\windows\system32\drivers\swmidi.sys
2009-03-11 15:09 . 2008-04-14 00:15 52,864 --a------ c:\windows\system32\drivers\DMusic.sys
2009-03-11 15:09 . 2008-04-14 00:09 7,552 --a------ c:\windows\system32\drivers\MSKSSRV.sys
2009-03-11 15:09 . 2008-04-14 00:15 6,272 --a------ c:\windows\system32\drivers\splitter.sys
2009-03-11 15:09 . 2008-04-14 00:09 5,376 --a------ c:\windows\system32\drivers\MSPCLOCK.sys
2009-03-11 15:09 . 2008-04-14 00:09 4,992 --a------ c:\windows\system32\drivers\MSPQM.sys
2009-03-11 15:09 . 2001-08-17 13:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2009-03-11 15:09 . 2008-04-14 00:15 2,944 --a------ c:\windows\system32\drivers\drmkaud.sys
2009-03-11 15:08 . 2008-04-14 00:10 57,600 --a------ c:\windows\system32\drivers\redbook.sys
2009-03-11 15:08 . 2008-04-14 00:17 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2009-03-11 15:07 . 2003-06-20 05:36 163,840 --a------ c:\windows\system32\OpenAL32.dll
2009-03-11 15:07 . 1995-01-13 08:10 149,504 --------- c:\windows\system32\MFCANS32.DLL
2009-03-11 15:07 . 1995-01-13 08:10 108,032 --------- c:\windows\system32\MFCUIA32.DLL
2009-03-11 15:07 . 2009-03-11 15:07 184 --a------ c:\windows\system32\e000001.dat
2009-03-11 15:06 . 2009-03-11 15:19 <DIR> d-------- c:\windows\system32\data
2009-03-11 15:06 . 2008-04-13 23:49 146,048 --a------ c:\windows\system32\drivers\portcls.sys
2009-03-11 15:06 . 2008-04-14 04:42 129,536 --a------ c:\windows\system32\ksproxy.ax
2009-03-11 15:06 . 2008-04-14 05:42 74,240 --a------ c:\windows\system32\usbui.dll
2009-03-11 15:06 . 2008-04-13 23:15 60,160 --a------ c:\windows\system32\drivers\drmk.sys
2009-03-11 15:06 . 2008-04-14 00:06 42,368 --a------ c:\windows\system32\drivers\AGP440.SYS
2009-03-11 15:06 . 2008-04-13 23:15 10,624 --a------ c:\windows\system32\drivers\gameenum.sys
2009-03-11 15:06 . 2001-08-17 11:46 6,400 --a------ c:\windows\system32\drivers\enum1394.sys
2009-03-11 15:06 . 2008-04-14 04:41 4,096 --a------ c:\windows\system32\ksuser.dll
2009-03-11 15:06 . 2009-03-11 15:20 75 --a------ c:\windows\SBWIN.INI
2009-03-11 15:04 . 2009-03-11 15:20 99 --a------ c:\windows\È
2009-03-11 15:03 . 2009-03-14 18:55 <DIR> dr------- c:\documents and settings\All Users\Documents
2009-03-11 15:02 . 2009-03-11 15:02 <DIR> d-------- c:\program files\Driver Cleaner Pro
2009-03-11 15:00 . 2008-02-25 11:43 1,372,568 --a------ c:\windows\system32\drivers\CTMMFILT.SYS
2009-03-11 15:00 . 2008-02-25 11:43 1,366,424 --a------ c:\windows\system32\drivers\CT0531FL.SYS
2009-03-11 15:00 . 2005-06-07 22:58 765,952 --a------ c:\windows\system\CRLDS3D.DLL
2009-03-11 15:00 . 2008-02-20 22:59 163,840 --a------ c:\windows\system32\CTDVINST.DL_
2009-03-11 15:00 . 2008-02-20 22:46 104,448 --a------ c:\windows\system32\sfms32.dll
2009-03-11 15:00 . 2008-02-20 22:59 86,016 --a------ c:\windows\system32\CTCOINST.DL_
2009-03-11 15:00 . 2008-02-20 22:59 27,648 --a------ c:\windows\system32\ac3api.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-04 09:06 --------- d-----w c:\documents and settings\Quentin\Application Data\foobar2000
2009-04-02 15:34 --------- d--h--w c:\program files\InstallShield Installation Information
2009-04-01 15:42 --------- d-----w c:\program files\Orbitdownloader
2009-03-31 17:13 --------- d-----w c:\program files\Java
2009-03-26 16:07 --------- d-----w c:\program files\K-Lite Codec Pack
2009-03-25 15:03 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-25 14:53 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-23 19:56 --------- d-----w c:\documents and settings\Quentin\Application Data\GrabPro
2009-03-18 17:20 --------- d-----w c:\program files\Paint.NET
2009-03-18 16:09 --------- d-----w c:\program files\Ray Adams
2009-03-12 18:11 --------- d-----w c:\program files\foobar2000
2009-03-11 18:05 --------- d-----w c:\program files\Windows Live
2009-03-11 16:52 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-03-11 14:53 --------- d-----w c:\documents and settings\Quentin\Application Data\Creative
2009-03-11 13:22 --------- d-----w c:\program files\Creative
2009-03-11 13:07 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\Creative
2009-03-11 12:56 --------- d-----w c:\documents and settings\Quentin\Application Data\Media Player Classic
2009-03-11 12:42 --------- d-----w c:\documents and settings\Quentin\Application Data\atitray
2009-03-11 12:39 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-11 12:37 --------- d-----w c:\program files\ATITool
2009-03-11 12:30 --------- d-----w c:\program files\HHD Software
2009-03-11 12:29 --------- d-----w c:\program files\jv16 PowerTools
2009-03-11 12:26 --------- d-----w c:\program files\UltraFXP
2009-03-11 12:26 --------- d-----w c:\program files\Nero
2009-03-11 12:26 --------- d-----w c:\program files\mIRC
2009-03-11 12:26 --------- d-----w c:\program files\Common Files\Nero
2009-03-11 12:26 --------- d-----w c:\program files\Common Files\Adobe
2009-03-11 12:25 --------- d-----w c:\program files\Mozilla Thunderbird
2009-03-11 12:25 --------- d-----w c:\program files\FastStone MaxView
2009-03-11 12:25 --------- d-----w c:\program files\Common Files\Java
2009-03-11 12:25 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-03-11 12:24 --------- d-----w c:\program files\JkDefrag
2009-03-11 12:24 --------- d-----w c:\program files\7-Zip
2009-03-11 12:24 --------- d-----w c:\documents and settings\Quentin\Application Data\Orbit
2009-03-11 12:21 --------- d-----w c:\program files\Reference Assemblies
2009-03-11 12:21 --------- d-----w c:\program files\MSBuild
2009-03-11 12:15 6,120 ----a-w c:\windows\BricoPackFoldersDelete.cmd
2009-03-11 12:15 51,036 ----a-w c:\windows\BricoPackUninst.cmd
2009-03-11 12:15 218,624 ----a-w c:\windows\system32\uxtheme.dll
2009-03-11 12:13 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-11 12:11 --------- d-----w c:\program files\Unlocker
2009-03-11 12:11 --------- d-----w c:\program files\SysInternals
2009-03-11 12:09 413,696 ----a-w c:\windows\system32\wrap_oal.dll
2009-02-24 23:26 2,255,360 ----a-w c:\windows\system32\x264vfw.dll
2009-02-09 18:56 67,584 ----a-w c:\windows\system32\ff_vfw.dll
2009-02-06 17:52 49,504 ----a-w c:\windows\system32\sirenacm.dll
2007-05-28 22:37 29,124,480 ----a-w c:\windows\system32\config\systemprofile\pack-vista-inspirat-2-1.0.exe
2007-05-28 22:37 29,124,480 ----a-w c:\documents and settings\Quentin\pack-vista-inspirat-2-1.0.exe
2007-05-28 22:37 29,124,480 ----a-w c:\documents and settings\Default User\pack-vista-inspirat-2-1.0.exe
.

------- Sigcheck -------

2008-07-09 15:00 821248 ded5c5e1901f3daf78f5f0ad036e8ea9 c:\windows\system32\wininet.dll

2008-07-09 15:00 361600 a29e1209f925a0e9b330e11da5fc7bab c:\windows\system32\drivers\tcpip.sys

2008-07-09 15:00 2185216 d78b8fef28298c32aad37745ab26bde5 c:\windows\system32\ntkrnlpa.exe

2008-07-09 15:00 2306560 8c4050bd9fd87e23cded28ffa889b0ba c:\windows\system32\ntoskrnl.exe

2008-07-09 15:00 975872 561a50497324f378e30f55d09b4e1258 c:\windows\explorer.exe

2008-07-09 15:00 68440 84d9a61860272d6177d46c86b8431557 c:\windows\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-19 630784]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-03-12 3885408]
"NuonSoft Wallpaper Cycler"="c:\program files\NuonSoft\WallpaperCycler3\WallpaperCycler Lite.exe" [2007-12-15 1947704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 45056]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-07-02 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-19 515416]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"CTHelper"="CTHELPER.EXE" [2003-06-20 c:\windows\system32\CTHELPER.EXE]
"AsioReg"="CTASIO.DLL" [2003-06-20 c:\windows\system32\CTASIO.DLL]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SetDefaultMIDI"="MIDIDEF.EXE" [2002-12-03 c:\windows\MIDIDEF.EXE]
"nltide_3"="advpack.dll" [2008-07-09 c:\windows\system32\advpack.dll]

c:\documents and settings\Quentin\Start Menu\Programs\Startup\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 630784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideRunAsVerb"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0x00000000"
"UpdatesDisableNotify"="0x00000000"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-19 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 951632]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - ASPI32

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
DcomLaunch REG_MULTI_SZ DcomLaunch

[COLOR=RED]NETSVCS REQUIRES REPAIRS - current entries shown/COLOR
6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Schedule
SENS
Sharedaccess
Tapisrv
Themes
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
napagent
hkmsvc
BITS
wuauserv
ShellHWDetection
WmdmPmSN

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

.
Contents of the 'Scheduled Tasks' folder

2009-03-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-19 18:37]
.
.
------- Supplementary Scan -------
.
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: {35851DA5-9960-43FC-AD6C-B369F26A135A} = 212.27.53.252,212.27.54.252
FF - ProfilePath - c:\documents and settings\Quentin\Application Data\Mozilla\Firefox\Profiles\as0c1y8d.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - plugin: c:\progra~1\MOZILL~1\plugins\npdeploytk.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npdivx32.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npdsplay.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npnul32.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\NPOFFICE.DLL
FF - plugin: c:\progra~1\MOZILL~1\plugins\nppdf32.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\nppl3260.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin2.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin3.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin4.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\npqtplugin5.dll
FF - plugin: c:\progra~1\MOZILL~1\plugins\nprpjplug.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-04 13:55:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(500)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-04 13:56:48
ComboFix-quarantined-files.txt 2009-04-04 11:56:46

Pre-Run: 5,223,260,160 bytes free
Post-Run: 5,214,609,408 bytes free

374


De plus, j'ai essayé de lancer par curiosité Spybot, et il s'est lancé. J'essayerais donc de faire de re-télécharger Malwarebyte en supposant qu'il marchera lui aussi maintenant.

Je te tiendrais aussi au courant au niveau des pubs avec google.

A+.
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
ok oui mets le rapport malwarebyte

puis un nouveau RSIT

a plus
0
Thomas59
 
Voici pour Malwarebyte:
Malwarebytes' Anti-Malware 1.35
Database version: 1940
Windows 5.1.2600 Service Pack 3

04/04/2009 20:36:10
mbam-log-2009-04-04 (20-36-10).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 117211
Time elapsed: 27 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Et RSIT (encore une fois, seul log.txt s'affiche):
Logfile of random's system information tool 1.06 (written by random/random)
Run by Quentin at 2009-04-05 12:07:24
Microsoft Windows XP Professional Service Pack 3
System drive C: has 4 GB (35%) free of 10 GB
Total RAM: 2047 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:07:33, on 05/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Quentin\Desktop\RSIT.exe
C:\Program Files\trend micro\HijackThis\Quentin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NuonSoft Wallpaper Cycler] "C:\Program Files\NuonSoft\WallpaperCycler3\WallpaperCycler Lite.exe" -cycle_and_exit
O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy' (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CS1\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O17 - HKLM\System\CS2\Services\Tcpip\..\{35851DA5-9960-43FC-AD6C-B369F26A135A}: NameServer = 212.27.53.252,212.27.54.252
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CiSvc - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
0