Lien face book en conversation MSN
daniel
-
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité -
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité -
Bonjour,
lors d'une conversation sur MSN, la fenêtre de dialogue se ferme. je suis obligé de me déconnecter / reconnecter
La fenêtre se erme à l'arrivée d'un lien proposant une photo via Face Book.
Je me suis fait "pièger" en cliquant sur la proposition (trop curieux).
Galère impoossible d'échanger sur MSN et ça se propage vite.... j'ai contaminé un contact également curieux.
Merci de votre aide précieuse.
Bien cordialement
lors d'une conversation sur MSN, la fenêtre de dialogue se ferme. je suis obligé de me déconnecter / reconnecter
La fenêtre se erme à l'arrivée d'un lien proposant une photo via Face Book.
Je me suis fait "pièger" en cliquant sur la proposition (trop curieux).
Galère impoossible d'échanger sur MSN et ça se propage vite.... j'ai contaminé un contact également curieux.
Merci de votre aide précieuse.
Bien cordialement
A voir également:
- Lien face book en conversation MSN
- Lien url - Guide
- Créer un lien pour partager des photos - Guide
- Face book conection - Guide
- Recuperer conversation whatsapp - Guide
- Comment enregistrer une conversation - Guide
86 réponses
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 03/24/2010 at 01:31 AM
Application Version : 4.34.1000
Core Rules Database Version : 4596
Trace Rules Database Version: 1978
Scan type : Complete Scan
Total Scan Time : 02:52:48
Memory items scanned : 511
Memory threats detected : 0
Registry items scanned : 6675
Registry threats detected : 1
File items scanned : 121692
File threats detected : 228
Trojan.Downloader-Gen/FotoMoto
HKU\S-1-5-21-4070011834-265495275-3555933719-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7C90A5E-BE0A-44DD-83D2-1BE138460BAC}
Adware.Tracking Cookie
C:\Documents and Settings\DAN\Cookies\dan@bluestreak[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adfarm1.adition[2].txt
C:\Documents and Settings\DAN\Cookies\dan@boursoramabanque.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads1.partnerlogic[1].txt
C:\Documents and Settings\DAN\Cookies\dan@bwincom.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@clickbank[1].txt
C:\Documents and Settings\DAN\Cookies\dan@bs.serving-sys[1].txt
C:\Documents and Settings\DAN\Cookies\dan@nestlecereals.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.zanox[1].txt
C:\Documents and Settings\DAN\Cookies\dan@yadro[2].txt
C:\Documents and Settings\DAN\Cookies\dan@partyaccount[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserver.aol[1].txt
C:\Documents and Settings\DAN\Cookies\dan@bannerconnect[1].txt
C:\Documents and Settings\DAN\Cookies\dan@overture[2].txt
C:\Documents and Settings\DAN\Cookies\dan@247realmedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@advertstream[1].txt
C:\Documents and Settings\DAN\Cookies\dan@clicksor[2].txt
C:\Documents and Settings\DAN\Cookies\dan@westernunionglobal.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.adgo-online[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.easyad[2].txt
C:\Documents and Settings\DAN\Cookies\dan@track.adform[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.e-pickmeup[2].txt
C:\Documents and Settings\DAN\Cookies\dan@zbox.zanox[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.mefeedia[2].txt
C:\Documents and Settings\DAN\Cookies\dan@weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@www.mediatraffic[2].txt
C:\Documents and Settings\DAN\Cookies\dan@server.iad.liveperson[3].txt
C:\Documents and Settings\DAN\Cookies\dan@2o7[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adv.bewebmedia[2].txt
C:\Documents and Settings\DAN\Cookies\dan@rotator.its.adjuggler[2].txt
C:\Documents and Settings\DAN\Cookies\dan@server.lon.liveperson[2].txt
C:\Documents and Settings\DAN\Cookies\dan@groupecarmignac.solution.weborama[1].txt
C:\Documents and Settings\DAN\Cookies\dan@conforama.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@stats.universalflower[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.glispa[2].txt
C:\Documents and Settings\DAN\Cookies\dan@bouyguestelecom.solution.weborama[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserving.favorit-network[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adviva[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tracking.publicidees[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adtech[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.caradisiac[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tracking.veille-referencement[2].txt
C:\Documents and Settings\DAN\Cookies\dan@serving-sys[2].txt
C:\Documents and Settings\DAN\Cookies\dan@my-adserver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cms.trafficmp[1].txt
C:\Documents and Settings\DAN\Cookies\dan@cewecolor.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@tradedoubler[1].txt
C:\Documents and Settings\DAN\Cookies\dan@rotator.adjuggler[2].txt
C:\Documents and Settings\DAN\Cookies\dan@fr.at.atwola[1].txt
C:\Documents and Settings\DAN\Cookies\dan@media6degrees[1].txt
C:\Documents and Settings\DAN\Cookies\dan@msnaccountservices.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@questionmarket[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserving.ezanga[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.us.e-planning[1].txt
C:\Documents and Settings\DAN\Cookies\dan@secure.partyaccount[1].txt
C:\Documents and Settings\DAN\Cookies\dan@sonyeurope.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@content.yieldmanager[2].txt
C:\Documents and Settings\DAN\Cookies\dan@xiti[1].txt
C:\Documents and Settings\DAN\Cookies\dan@specificclick[2].txt
C:\Documents and Settings\DAN\Cookies\dan@dealtime[1].txt
C:\Documents and Settings\DAN\Cookies\dan@estat[1].txt
C:\Documents and Settings\DAN\Cookies\dan@statse.webtrendslive[2].txt
C:\Documents and Settings\DAN\Cookies\dan@zedo[1].txt
C:\Documents and Settings\DAN\Cookies\dan@doubleclick[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.pointroll[1].txt
C:\Documents and Settings\DAN\Cookies\dan@trafficmp[2].txt
C:\Documents and Settings\DAN\Cookies\dan@apmebf[1].txt
C:\Documents and Settings\DAN\Cookies\dan@rambler[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.ctasnet[1].txt
C:\Documents and Settings\DAN\Cookies\dan@cetelem.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@aimfar.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.addynamix[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.partypoker[1].txt
C:\Documents and Settings\DAN\Cookies\dan@partypoker[2].txt
C:\Documents and Settings\DAN\Cookies\dan@statsweb.bnpparibas[1].txt
C:\Documents and Settings\DAN\Cookies\dan@pro-market[2].txt
C:\Documents and Settings\DAN\Cookies\dan@atdmt[1].txt
C:\Documents and Settings\DAN\Cookies\dan@pointroll[2].txt
C:\Documents and Settings\DAN\Cookies\dan@stats.canalblog[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mediatraffic[2].txt
C:\Documents and Settings\DAN\Cookies\dan@content.yieldmanager[3].txt
C:\Documents and Settings\DAN\Cookies\dan@smartadserver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@advertising[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mediaffiliation[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adbrite[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mmedia.t134[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.audxch[2].txt
C:\Documents and Settings\DAN\Cookies\dan@list[1].txt
C:\Documents and Settings\DAN\Cookies\dan@zanox[1].txt
C:\Documents and Settings\DAN\Cookies\dan@server.iad.liveperson[2].txt
C:\Documents and Settings\DAN\Cookies\dan@azjmp[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mediaplex[2].txt
C:\Documents and Settings\DAN\Cookies\dan@server.lon.liveperson[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.smartadserver[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.clicmanager[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cache.trafficmp[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ds.clickexperts[1].txt
C:\Documents and Settings\DAN\Cookies\dan@market1.the-adult-company[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.yieldmanager[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ad1.adclickmanager[2].txt
C:\Documents and Settings\DAN\Cookies\dan@track.effiliation[1].txt
C:\Documents and Settings\DAN\Cookies\dan@gettoplisted[2].txt
C:\Documents and Settings\DAN\Cookies\dan@himedia.individuad[2].txt
C:\Documents and Settings\DAN\Cookies\dan@t.bbtrack[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.raasnet[2].txt
C:\Documents and Settings\DAN\Cookies\dan@simyofr.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@trunitybe2.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adrevolver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cortalconsors.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@stat.dealtime[1].txt
C:\Documents and Settings\DAN\Cookies\dan@interflora2.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@virginmobile.solution.weborama[1].txt
C:\Documents and Settings\DAN\Cookies\dan@phoneandphone.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@account.live[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.canalblog[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adultfriendfinder[1].txt
C:\Documents and Settings\DAN\Cookies\dan@msnportal.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@movitex.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@trackers.1st-affiliation[2].txt
C:\Documents and Settings\DAN\Cookies\dan@fr.partypoker[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserver.adtechus[1].txt
C:\Documents and Settings\DAN\Cookies\dan@find-best-offers[1].txt
C:\Documents and Settings\DAN\Cookies\dan@myroitracking[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ww57.smartadserver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@burstnet[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.burstnet[2].txt
C:\Documents and Settings\DAN\Cookies\dan@oasn-en1.247realmedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tracking.i2smedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@carrefourfr.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@media.adrevolver[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ttbsagetpepme.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.myswitzerland[2].txt
C:\Documents and Settings\DAN\Cookies\dan@www.tracklead[1].txt
C:\Documents and Settings\DAN\Cookies\dan@opel.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@static.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.elevanet[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cdn5.specificclick[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.sexyavenue[2].txt
C:\Documents and Settings\DAN\Cookies\dan@lfstmedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@fr.sitestat[1].txt
C:\Documents and Settings\DAN\Cookies\dan@sfr.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@revsci[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tribalfusion[2].txt
C:\Documents and Settings\DAN\Cookies\dan@xm.xtendmedia[2].txt
C:\Documents and Settings\DAN\Cookies\dan@view.atdmt[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.mktrack[1].txt
C:\Documents and Settings\DAN\Cookies\dan@chitika[1].txt
C:\Documents and Settings\DAN\Cookies\dan@batiwebgroupe.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@fastclick[1].txt
C:\Documents and Settings\DAN\Cookies\dan@eas.apm.emediate[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad1.emediate[1].txt
C:\Documents and Settings\DAN\Cookies\dan@fortuneopub.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.wsod[2].txt
C:\Documents and Settings\DAN\Cookies\dan@statcounter[2].txt
Adware.Vundo/Variant-Qoodl-S
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152310.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152362.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152364.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152375.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152403.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152404.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152411.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP828\A0152419.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP828\A0152442.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152465.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152469.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152503.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152508.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152518.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152558.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP830\A0152591.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP830\A0152592.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP830\A0152651.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP831\A0152677.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP831\A0152700.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP832\A0152733.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP832\A0152797.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP832\A0152800.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152816.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152834.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152842.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152868.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP834\A0152928.DLL
Adware.Vundo/Variant-Huge
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP834\A0152930.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP835\A0152951.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP835\A0152971.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP836\A0155007.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP836\A0155009.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP837\A0155083.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP838\A0157128.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157150.DLL
Adware.Agent/Gen-Qoodl-T
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157162.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157164.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157176.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP840\A0157190.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP840\A0157232.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP841\A0157265.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP844\A0159385.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159409.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159418.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159455.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159460.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159478.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159479.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159480.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159481.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159482.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0161489.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0161513.DLL
Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163859.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163868.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163869.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163871.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163872.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164102.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164103.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164104.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164105.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164106.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163865.EXE
D:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163866.EXE
Adware.ContextHelper
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163867.DLL
Adware.Vundo/Variant
C:\WINDOWS\SYSTEM32\NSEF.DLL
C:\WINDOWS\SYSTEM32\NSH1A.DLL
C:\WINDOWS\SYSTEM32\NSQ17.DLL
Trojan.Downloader-Gen/FotoMoto-B
C:\WINDOWS\SYSTEM32\NSJ80.DLL
C:\WINDOWS\SYSTEM32\NST95.DLL
Adware.AdServer
C:\WINDOWS\SYSTEM32\NSS8E.DLL
C:\WINDOWS\SYSTEM32\NSZ16.DLL
https://www.superantispyware.com/
Generated 03/24/2010 at 01:31 AM
Application Version : 4.34.1000
Core Rules Database Version : 4596
Trace Rules Database Version: 1978
Scan type : Complete Scan
Total Scan Time : 02:52:48
Memory items scanned : 511
Memory threats detected : 0
Registry items scanned : 6675
Registry threats detected : 1
File items scanned : 121692
File threats detected : 228
Trojan.Downloader-Gen/FotoMoto
HKU\S-1-5-21-4070011834-265495275-3555933719-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7C90A5E-BE0A-44DD-83D2-1BE138460BAC}
Adware.Tracking Cookie
C:\Documents and Settings\DAN\Cookies\dan@bluestreak[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adfarm1.adition[2].txt
C:\Documents and Settings\DAN\Cookies\dan@boursoramabanque.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads1.partnerlogic[1].txt
C:\Documents and Settings\DAN\Cookies\dan@bwincom.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@clickbank[1].txt
C:\Documents and Settings\DAN\Cookies\dan@bs.serving-sys[1].txt
C:\Documents and Settings\DAN\Cookies\dan@nestlecereals.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.zanox[1].txt
C:\Documents and Settings\DAN\Cookies\dan@yadro[2].txt
C:\Documents and Settings\DAN\Cookies\dan@partyaccount[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserver.aol[1].txt
C:\Documents and Settings\DAN\Cookies\dan@bannerconnect[1].txt
C:\Documents and Settings\DAN\Cookies\dan@overture[2].txt
C:\Documents and Settings\DAN\Cookies\dan@247realmedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@advertstream[1].txt
C:\Documents and Settings\DAN\Cookies\dan@clicksor[2].txt
C:\Documents and Settings\DAN\Cookies\dan@westernunionglobal.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.adgo-online[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.easyad[2].txt
C:\Documents and Settings\DAN\Cookies\dan@track.adform[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.e-pickmeup[2].txt
C:\Documents and Settings\DAN\Cookies\dan@zbox.zanox[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.mefeedia[2].txt
C:\Documents and Settings\DAN\Cookies\dan@weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@www.mediatraffic[2].txt
C:\Documents and Settings\DAN\Cookies\dan@server.iad.liveperson[3].txt
C:\Documents and Settings\DAN\Cookies\dan@2o7[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adv.bewebmedia[2].txt
C:\Documents and Settings\DAN\Cookies\dan@rotator.its.adjuggler[2].txt
C:\Documents and Settings\DAN\Cookies\dan@server.lon.liveperson[2].txt
C:\Documents and Settings\DAN\Cookies\dan@groupecarmignac.solution.weborama[1].txt
C:\Documents and Settings\DAN\Cookies\dan@conforama.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@stats.universalflower[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.glispa[2].txt
C:\Documents and Settings\DAN\Cookies\dan@bouyguestelecom.solution.weborama[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserving.favorit-network[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adviva[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tracking.publicidees[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adtech[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.caradisiac[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tracking.veille-referencement[2].txt
C:\Documents and Settings\DAN\Cookies\dan@serving-sys[2].txt
C:\Documents and Settings\DAN\Cookies\dan@my-adserver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cms.trafficmp[1].txt
C:\Documents and Settings\DAN\Cookies\dan@cewecolor.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@tradedoubler[1].txt
C:\Documents and Settings\DAN\Cookies\dan@rotator.adjuggler[2].txt
C:\Documents and Settings\DAN\Cookies\dan@fr.at.atwola[1].txt
C:\Documents and Settings\DAN\Cookies\dan@media6degrees[1].txt
C:\Documents and Settings\DAN\Cookies\dan@msnaccountservices.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@questionmarket[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserving.ezanga[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.us.e-planning[1].txt
C:\Documents and Settings\DAN\Cookies\dan@secure.partyaccount[1].txt
C:\Documents and Settings\DAN\Cookies\dan@sonyeurope.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@content.yieldmanager[2].txt
C:\Documents and Settings\DAN\Cookies\dan@xiti[1].txt
C:\Documents and Settings\DAN\Cookies\dan@specificclick[2].txt
C:\Documents and Settings\DAN\Cookies\dan@dealtime[1].txt
C:\Documents and Settings\DAN\Cookies\dan@estat[1].txt
C:\Documents and Settings\DAN\Cookies\dan@statse.webtrendslive[2].txt
C:\Documents and Settings\DAN\Cookies\dan@zedo[1].txt
C:\Documents and Settings\DAN\Cookies\dan@doubleclick[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.pointroll[1].txt
C:\Documents and Settings\DAN\Cookies\dan@trafficmp[2].txt
C:\Documents and Settings\DAN\Cookies\dan@apmebf[1].txt
C:\Documents and Settings\DAN\Cookies\dan@rambler[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.ctasnet[1].txt
C:\Documents and Settings\DAN\Cookies\dan@cetelem.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@aimfar.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.addynamix[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.partypoker[1].txt
C:\Documents and Settings\DAN\Cookies\dan@partypoker[2].txt
C:\Documents and Settings\DAN\Cookies\dan@statsweb.bnpparibas[1].txt
C:\Documents and Settings\DAN\Cookies\dan@pro-market[2].txt
C:\Documents and Settings\DAN\Cookies\dan@atdmt[1].txt
C:\Documents and Settings\DAN\Cookies\dan@pointroll[2].txt
C:\Documents and Settings\DAN\Cookies\dan@stats.canalblog[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mediatraffic[2].txt
C:\Documents and Settings\DAN\Cookies\dan@content.yieldmanager[3].txt
C:\Documents and Settings\DAN\Cookies\dan@smartadserver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@advertising[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mediaffiliation[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adbrite[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mmedia.t134[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.audxch[2].txt
C:\Documents and Settings\DAN\Cookies\dan@list[1].txt
C:\Documents and Settings\DAN\Cookies\dan@zanox[1].txt
C:\Documents and Settings\DAN\Cookies\dan@server.iad.liveperson[2].txt
C:\Documents and Settings\DAN\Cookies\dan@azjmp[1].txt
C:\Documents and Settings\DAN\Cookies\dan@mediaplex[2].txt
C:\Documents and Settings\DAN\Cookies\dan@server.lon.liveperson[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.smartadserver[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.clicmanager[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cache.trafficmp[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ds.clickexperts[1].txt
C:\Documents and Settings\DAN\Cookies\dan@market1.the-adult-company[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.yieldmanager[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ad1.adclickmanager[2].txt
C:\Documents and Settings\DAN\Cookies\dan@track.effiliation[1].txt
C:\Documents and Settings\DAN\Cookies\dan@gettoplisted[2].txt
C:\Documents and Settings\DAN\Cookies\dan@himedia.individuad[2].txt
C:\Documents and Settings\DAN\Cookies\dan@t.bbtrack[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.raasnet[2].txt
C:\Documents and Settings\DAN\Cookies\dan@simyofr.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@trunitybe2.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adrevolver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cortalconsors.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@stat.dealtime[1].txt
C:\Documents and Settings\DAN\Cookies\dan@interflora2.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@virginmobile.solution.weborama[1].txt
C:\Documents and Settings\DAN\Cookies\dan@phoneandphone.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@account.live[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.canalblog[2].txt
C:\Documents and Settings\DAN\Cookies\dan@adultfriendfinder[1].txt
C:\Documents and Settings\DAN\Cookies\dan@msnportal.112.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@movitex.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@trackers.1st-affiliation[2].txt
C:\Documents and Settings\DAN\Cookies\dan@fr.partypoker[1].txt
C:\Documents and Settings\DAN\Cookies\dan@adserver.adtechus[1].txt
C:\Documents and Settings\DAN\Cookies\dan@find-best-offers[1].txt
C:\Documents and Settings\DAN\Cookies\dan@myroitracking[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ww57.smartadserver[2].txt
C:\Documents and Settings\DAN\Cookies\dan@burstnet[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.burstnet[2].txt
C:\Documents and Settings\DAN\Cookies\dan@oasn-en1.247realmedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tracking.i2smedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@carrefourfr.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@media.adrevolver[1].txt
C:\Documents and Settings\DAN\Cookies\dan@ttbsagetpepme.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.myswitzerland[2].txt
C:\Documents and Settings\DAN\Cookies\dan@www.tracklead[1].txt
C:\Documents and Settings\DAN\Cookies\dan@opel.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@static.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ads.elevanet[2].txt
C:\Documents and Settings\DAN\Cookies\dan@cdn5.specificclick[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.sexyavenue[2].txt
C:\Documents and Settings\DAN\Cookies\dan@lfstmedia[1].txt
C:\Documents and Settings\DAN\Cookies\dan@fr.sitestat[1].txt
C:\Documents and Settings\DAN\Cookies\dan@sfr.122.2o7[1].txt
C:\Documents and Settings\DAN\Cookies\dan@revsci[1].txt
C:\Documents and Settings\DAN\Cookies\dan@tribalfusion[2].txt
C:\Documents and Settings\DAN\Cookies\dan@xm.xtendmedia[2].txt
C:\Documents and Settings\DAN\Cookies\dan@view.atdmt[1].txt
C:\Documents and Settings\DAN\Cookies\dan@www.mktrack[1].txt
C:\Documents and Settings\DAN\Cookies\dan@chitika[1].txt
C:\Documents and Settings\DAN\Cookies\dan@batiwebgroupe.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@fastclick[1].txt
C:\Documents and Settings\DAN\Cookies\dan@eas.apm.emediate[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad1.emediate[1].txt
C:\Documents and Settings\DAN\Cookies\dan@fortuneopub.solution.weborama[2].txt
C:\Documents and Settings\DAN\Cookies\dan@ad.wsod[2].txt
C:\Documents and Settings\DAN\Cookies\dan@statcounter[2].txt
Adware.Vundo/Variant-Qoodl-S
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152310.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152362.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152364.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152375.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152403.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152404.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP827\A0152411.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP828\A0152419.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP828\A0152442.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152465.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152469.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152503.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152508.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152518.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP829\A0152558.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP830\A0152591.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP830\A0152592.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP830\A0152651.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP831\A0152677.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP831\A0152700.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP832\A0152733.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP832\A0152797.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP832\A0152800.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152816.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152834.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152842.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP833\A0152868.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP834\A0152928.DLL
Adware.Vundo/Variant-Huge
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP834\A0152930.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP835\A0152951.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP835\A0152971.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP836\A0155007.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP836\A0155009.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP837\A0155083.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP838\A0157128.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157150.DLL
Adware.Agent/Gen-Qoodl-T
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157162.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157164.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP839\A0157176.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP840\A0157190.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP840\A0157232.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP841\A0157265.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP844\A0159385.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159409.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159418.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159455.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159460.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159478.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159479.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159480.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159481.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0159482.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0161489.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP845\A0161513.DLL
Trojan.Agent/Gen-Nullo[Short]
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163859.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163868.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163869.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163871.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163872.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164102.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164103.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164104.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164105.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0164106.DLL
D:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163865.EXE
D:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163866.EXE
Adware.ContextHelper
C:\SYSTEM VOLUME INFORMATION\_RESTORE{8CEE87BF-8C19-46ED-B1DB-A2F238916F97}\RP850\A0163867.DLL
Adware.Vundo/Variant
C:\WINDOWS\SYSTEM32\NSEF.DLL
C:\WINDOWS\SYSTEM32\NSH1A.DLL
C:\WINDOWS\SYSTEM32\NSQ17.DLL
Trojan.Downloader-Gen/FotoMoto-B
C:\WINDOWS\SYSTEM32\NSJ80.DLL
C:\WINDOWS\SYSTEM32\NST95.DLL
Adware.AdServer
C:\WINDOWS\SYSTEM32\NSS8E.DLL
C:\WINDOWS\SYSTEM32\NSZ16.DLL
Bonsoir,
Et ba il a quand même trouvé :
Adware.Vundo/Variant-Qoodl-S
Adware.Vundo/Variant-Huge
Adware.Agent/Gen-Qoodl-T
Trojan.Agent/Gen-Nullo[Short]
Adware.ContextHelper
Adware.Vundo/Variant
Trojan.Downloader-Gen/FotoMoto-B
Adware.AdServer
Tu peux vider la quarantaine de SAS avec tout ça et ensuite me faire ce dernier scan :
DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)
? Télécharge List_Kill'em et enregistre le sur ton bureau
? double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation
? une fois terminée , clic sur "terminer" et le programme se lancera seul
? choisis choisis l'option Search
? une icone blanc et noir va s'afficher sur le bureau , il te servira à relancer le programme par la suite.
? laisse travailler l'outil
? à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.
? un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan
? Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
Ensuite héberger le rapport :
? Rendez-vous à cette adresse d'hébergement gratuit : http://www.cijoint.fr/
? Cliquez sur parcourir, chercher le rapport .txt puis cliquez sur ici pour déposer le fichier
? Une fois le lien crée, faite un clique droit dessus et copier l'adresse du lien pour venir le coller dans votre réponse
En formation pour éradiquer les méchants virus.
Et ba il a quand même trouvé :
Adware.Vundo/Variant-Qoodl-S
Adware.Vundo/Variant-Huge
Adware.Agent/Gen-Qoodl-T
Trojan.Agent/Gen-Nullo[Short]
Adware.ContextHelper
Adware.Vundo/Variant
Trojan.Downloader-Gen/FotoMoto-B
Adware.AdServer
Tu peux vider la quarantaine de SAS avec tout ça et ensuite me faire ce dernier scan :
DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)
? Télécharge List_Kill'em et enregistre le sur ton bureau
? double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation
? une fois terminée , clic sur "terminer" et le programme se lancera seul
? choisis choisis l'option Search
? une icone blanc et noir va s'afficher sur le bureau , il te servira à relancer le programme par la suite.
? laisse travailler l'outil
? à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.
? un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan
? Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
Ensuite héberger le rapport :
? Rendez-vous à cette adresse d'hébergement gratuit : http://www.cijoint.fr/
? Cliquez sur parcourir, chercher le rapport .txt puis cliquez sur ici pour déposer le fichier
? Une fois le lien crée, faite un clique droit dessus et copier l'adresse du lien pour venir le coller dans votre réponse
En formation pour éradiquer les méchants virus.
List'em by g3n-h@ckm@n 1.6.0.5
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 22:48:18 | 24/03/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ (!) Disabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,49 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (13,98 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\sony\vaio power management\SPMgr.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\modem ADSL USB\modem ADSL USB\dslmon.exe
C:\Documents and Settings\DAN\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\List_Kill'em\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
SUPERAntiSpyware REG_SZ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
ATIPTA REG_SZ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKSERV.EXE REG_SZ C:\Program Files\Sony\HotKey Utility\HKserv.exe
Switcher.exe REG_SZ C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
SonyPowerCfg REG_SZ C:\Program Files\sony\vaio power management\SPMgr.exe
Hcontrol REG_SZ C:\WINDOWS\ATK0100\Hcontrol.exe
Mouse Suite 98 Daemon REG_SZ ICO.EXE
BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
ezShieldProtector for Px REG_SZ C:\WINDOWS\system32\ezSP_Px.exe
PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
iTunesHelper REG_SZ C:\Program Files\iTunes\iTunesHelper.exe
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Symantec NetDriver Monitor REG_SZ C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
TSE_PLUtil REG_SZ C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
PLFFAP REG_SZ C:\WINDOWS\system32\HotfixQ0306270.exe
adiras REG_SZ adiras.exe
NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
VAIO Update 3 REG_SZ "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
Easy PDF Creator REG_SZ C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
UserFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -u
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
NoDriveAutoRun REG_DWORD 255 (0xff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 255 (0xff)
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ PORTABLE-DANIEL
DefaultUserName REG_SZ DAN
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ DAN
AltDefaultDomainName REG_SZ PORTABLE-DANIEL
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe REG_SZ C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
C:\WINDOWS\System\CSRSS.EXE REG_SZ C:\WINDOWS\System\CSRSS.EXE:*:Enabled:Microsoft Update
C:\Program Files\Messager Voila\Messager Voila.exe REG_SZ C:\Program Files\Messager Voila\Messager Voila.exe:*:Disabled:Application Messager
D:\StubInstaller.exe REG_SZ D:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer
C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
C:\Program Files\sony\vaio media 3.1\Vc.exe REG_SZ C:\Program Files\sony\vaio media 3.1\Vc.exe:*:Disabled:[VAIO Media] VAIO Media
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
C:\Documents and Settings\DAN\Local Settings\Temporary Internet Files\Content.IE5\2CJWQZIB\PICT12082010-jpg-www-facebook-com[1].exe REG_SZ C:\Documents and Settings\DAN\Local Settings\Temporary Internet Files\Content.IE5\2CJWQZIB\PICT12082010-jpg-www-facebook-com[1].exe:*:Enabled:Userinit
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{02BCC737-B171-4746-94C9-0D8A0B2C0089}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0D9392CD-A784-4FCA-9342-0F75F7D7C8CB}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{254E4AA8-659F-4A93-A9D2-C924F5975DCD}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5ED80217-570B-4DA9-BF44-BE107C0EC166}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{88764F69-3831-4EC1-B40B-FF21D8381345}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x2 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
##
86912,95b858761a00e1d4f81f79a0da019aca,5e41dae055bcb8ee8ad23d3c77d69df09c6b1e301c889aec6f02193d7dec352b,C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
=======
D'fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
27,95 Go total, 8,50 Go libre (30%), 25% fragment' (fragmentation du fichier 45%)
Vous devriez d'fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\WINDOWS\000001_.tmp
Present !! : C:\WINDOWS\003422_.tmp
Present !! : C:\WINDOWS\_wi190.tmp
Present !! : C:\WINDOWS\System32\_*.dll
Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : C:\WINDOWS\unins000.dat
Present !! : C:\WINDOWS\unins000.exe
Present !! : C:\Documents and Settings\DAN\Local Settings\Temp\dw.log
Present !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-24 22:59:07
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe >>UNKNOWN [0x82B8D0E8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x82b8d0e8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 22:59:09,03
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 22:48:18 | 24/03/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ (!) Disabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,49 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (13,98 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\sony\vaio power management\SPMgr.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\modem ADSL USB\modem ADSL USB\dslmon.exe
C:\Documents and Settings\DAN\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\List_Kill'em\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
SUPERAntiSpyware REG_SZ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
ATIPTA REG_SZ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKSERV.EXE REG_SZ C:\Program Files\Sony\HotKey Utility\HKserv.exe
Switcher.exe REG_SZ C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
SonyPowerCfg REG_SZ C:\Program Files\sony\vaio power management\SPMgr.exe
Hcontrol REG_SZ C:\WINDOWS\ATK0100\Hcontrol.exe
Mouse Suite 98 Daemon REG_SZ ICO.EXE
BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
ezShieldProtector for Px REG_SZ C:\WINDOWS\system32\ezSP_Px.exe
PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
iTunesHelper REG_SZ C:\Program Files\iTunes\iTunesHelper.exe
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Symantec NetDriver Monitor REG_SZ C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
TSE_PLUtil REG_SZ C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
PLFFAP REG_SZ C:\WINDOWS\system32\HotfixQ0306270.exe
adiras REG_SZ adiras.exe
NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
VAIO Update 3 REG_SZ "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
Easy PDF Creator REG_SZ C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
UserFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -u
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
NoDriveAutoRun REG_DWORD 255 (0xff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 255 (0xff)
NoDriveTypeAutoRun REG_DWORD 255 (0xff)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ PORTABLE-DANIEL
DefaultUserName REG_SZ DAN
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ DAN
AltDefaultDomainName REG_SZ PORTABLE-DANIEL
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe REG_SZ C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
C:\WINDOWS\System\CSRSS.EXE REG_SZ C:\WINDOWS\System\CSRSS.EXE:*:Enabled:Microsoft Update
C:\Program Files\Messager Voila\Messager Voila.exe REG_SZ C:\Program Files\Messager Voila\Messager Voila.exe:*:Disabled:Application Messager
D:\StubInstaller.exe REG_SZ D:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer
C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
C:\Program Files\sony\vaio media 3.1\Vc.exe REG_SZ C:\Program Files\sony\vaio media 3.1\Vc.exe:*:Disabled:[VAIO Media] VAIO Media
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
C:\Documents and Settings\DAN\Local Settings\Temporary Internet Files\Content.IE5\2CJWQZIB\PICT12082010-jpg-www-facebook-com[1].exe REG_SZ C:\Documents and Settings\DAN\Local Settings\Temporary Internet Files\Content.IE5\2CJWQZIB\PICT12082010-jpg-www-facebook-com[1].exe:*:Enabled:Userinit
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{02BCC737-B171-4746-94C9-0D8A0B2C0089}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0D9392CD-A784-4FCA-9342-0F75F7D7C8CB}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{254E4AA8-659F-4A93-A9D2-C924F5975DCD}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5ED80217-570B-4DA9-BF44-BE107C0EC166}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{88764F69-3831-4EC1-B40B-FF21D8381345}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x2 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
##
86912,95b858761a00e1d4f81f79a0da019aca,5e41dae055bcb8ee8ad23d3c77d69df09c6b1e301c889aec6f02193d7dec352b,C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
=======
D'fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
27,95 Go total, 8,50 Go libre (30%), 25% fragment' (fragmentation du fichier 45%)
Vous devriez d'fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\WINDOWS\000001_.tmp
Present !! : C:\WINDOWS\003422_.tmp
Present !! : C:\WINDOWS\_wi190.tmp
Present !! : C:\WINDOWS\System32\_*.dll
Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : C:\WINDOWS\unins000.dat
Present !! : C:\WINDOWS\unins000.exe
Present !! : C:\Documents and Settings\DAN\Local Settings\Temp\dw.log
Present !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-24 22:59:07
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe >>UNKNOWN [0x82B8D0E8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x82b8d0e8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 22:59:09,03
Tu as un rootkit dans ton pc :
detected MBR rootkit hooks:
\Driver\Disk -> 0x82b8d0e8
Warning: possible MBR rootkit infection !
▶ Téléchargez mbr.exe de Gmer sur le Bureau : mbr.exe
▶ Désactivez vos protections et coupez la connexion.
▶ Sous Windows XP : double-cliquez sur mbr.exe / Sous Windows Vista ou Seven, faites un clic-droit sur mbr.exe et choisissez "Exécuter en temps qu'administrateur"
▶ Un rapport sera généré : mbr.log
▶ En cas d'infection, le message MBR rootkit code detected va apparaître dans le rapport. Si c'est le cas, cliquez sur le Menu démarrer --> Exécuter, et tapez la commande suivante :
▶ Sous XP : "%userprofile%\Bureau\mbr" -f
▶ Sous Vista/Seven : "%userprofile%\Desktop\mbr" -f
▶ Dans le mbr.log cette ligne apparaîtra : original MBR restored successfully !
▶ Postez le rapport
detected MBR rootkit hooks:
\Driver\Disk -> 0x82b8d0e8
Warning: possible MBR rootkit infection !
▶ Téléchargez mbr.exe de Gmer sur le Bureau : mbr.exe
▶ Désactivez vos protections et coupez la connexion.
▶ Sous Windows XP : double-cliquez sur mbr.exe / Sous Windows Vista ou Seven, faites un clic-droit sur mbr.exe et choisissez "Exécuter en temps qu'administrateur"
▶ Un rapport sera généré : mbr.log
▶ En cas d'infection, le message MBR rootkit code detected va apparaître dans le rapport. Si c'est le cas, cliquez sur le Menu démarrer --> Exécuter, et tapez la commande suivante :
▶ Sous XP : "%userprofile%\Bureau\mbr" -f
▶ Sous Vista/Seven : "%userprofile%\Desktop\mbr" -f
▶ Dans le mbr.log cette ligne apparaîtra : original MBR restored successfully !
▶ Postez le rapport
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Pas grand chose dans ce rapport.. et pas bestiole apparemment
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Pas grand chose dans ce rapport.. et pas bestiole apparemment
As tu eu ce message : le message MBR rootkit code detected
Sinon fait moi ceci :
/!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\
* Rends toi sur cette page, et clique sur "Download EXE" pour télécharger Gmer (sous un nom aléatoire, pour éviter qu'il soit bloqué par une infection)
* Lance Gmer
* Dans l'onglet "Rootkit", clique sur "Scan" puis patiente.
* A la fin, clique sur "Save" et enregistre le rapport sur ton Bureau.
* Héberge le rapport sur ce site, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
Sinon fait moi ceci :
/!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\
* Rends toi sur cette page, et clique sur "Download EXE" pour télécharger Gmer (sous un nom aléatoire, pour éviter qu'il soit bloqué par une infection)
* Lance Gmer
* Dans l'onglet "Rootkit", clique sur "Scan" puis patiente.
* A la fin, clique sur "Save" et enregistre le rapport sur ton Bureau.
* Héberge le rapport sur ce site, puis copie/colle le lien fourni dans ta prochaine réponse sur le forum.
http://www.cijoint.fr/cjlink.php?file=cj201003/cijjGXsZVH.txt
Et voilà..!
Pour info, je n'avais eu le message : MBR rootkit code detected lors du scan avec mbr.exe. Si vous avez un doute, je peux le refaire.
Et voilà..!
Pour info, je n'avais eu le message : MBR rootkit code detected lors du scan avec mbr.exe. Si vous avez un doute, je peux le refaire.
Bonjour,
Attention bien suivre les indications à ne pas reproduire sur n'importe quel ordinateur :
▶ Télécharge Combofix de sUBs
▶ et enregistre le sur le Bureau.
▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)
Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
▶ Je te conseille d'installer la console de récupération !!
ensuite envois le rapport stp
si combofix n'a pas installé la console de récupération, suivre ceci pour l'installe et relance combofix ensuite : http://www.zebulon.fr/dossiers/61-2-installation-console-recuperation-disque.html
Attention bien suivre les indications à ne pas reproduire sur n'importe quel ordinateur :
▶ Télécharge Combofix de sUBs
▶ et enregistre le sur le Bureau.
▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)
Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
▶ Je te conseille d'installer la console de récupération !!
ensuite envois le rapport stp
si combofix n'a pas installé la console de récupération, suivre ceci pour l'installe et relance combofix ensuite : http://www.zebulon.fr/dossiers/61-2-installation-console-recuperation-disque.html
ComboFix 10-03-28.01 - DAN 28/03/2010 19:56:58.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.219 [GMT 2:00]
Lancé depuis: c:\documents and settings\DAN\Bureau\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Internet Security *disabled* {825036E0-9F94-4752-8789-8B92454AF49B}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Ijl11.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-28 au 2010-03-28 ))))))))))))))))))))))))))))))))))))
.
2010-03-24 21:48 . 2010-03-24 21:48 -------- d-----w- C:\Kill'em
2010-03-24 21:45 . 2010-03-24 21:59 -------- d-----w- c:\program files\List_Kill'em
2010-03-23 21:27 . 2010-03-23 21:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-23 21:26 . 2010-03-23 21:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-03-23 21:26 . 2010-03-23 21:26 -------- d-----w- c:\documents and settings\DAN\Application Data\SUPERAntiSpyware.com
2010-03-23 21:24 . 2010-03-23 21:24 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2010-03-16 21:58 . 2010-03-18 20:33 1956 ----a-w- C:\UsbFix_Upload_Me_PORTABLE-DANIEL.zip
2010-03-15 20:08 . 2010-03-21 17:03 -------- d-----w- C:\UsbFix
2010-03-15 00:27 . 2010-03-15 00:27 1470 ----a-w- C:\FindyKill_Upload_Me_PORTABLE-DANIEL.zip
2010-03-14 22:49 . 2010-03-15 04:43 -------- d-----w- C:\FyK
2010-03-14 13:31 . 2010-03-14 15:15 -------- d-----w- C:\Ad-Remover
2010-03-14 00:31 . 2010-03-14 00:31 -------- d-----w- c:\documents and settings\DAN\Application Data\Malwarebytes
2010-03-14 00:31 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-14 00:31 . 2010-03-14 00:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-14 00:31 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-14 00:31 . 2010-03-14 02:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-13 21:20 . 2010-03-14 22:23 -------- d-----w- c:\program files\trend micro
2010-03-13 21:20 . 2010-03-14 22:47 -------- d-----w- C:\rsit
2010-03-13 19:56 . 2010-03-13 19:56 -------- d-----w- c:\program files\AxBx
2010-03-13 10:13 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-28 09:46 . 2004-08-27 08:33 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2010-03-23 21:28 . 2010-03-23 21:28 52224 ----a-w- c:\documents and settings\DAN\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-23 21:28 . 2010-03-23 21:28 117760 ----a-w- c:\documents and settings\DAN\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-28 20:30 . 2005-10-08 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2010-02-28 20:29 . 2008-01-02 15:43 -------- d-----w- c:\program files\Messenger Plus! Live
2009-12-31 16:50 . 2004-08-26 14:34 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-05 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 339968]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2004-06-29 122880]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2004-01-19 290816]
"SonyPowerCfg"="c:\program files\sony\vaio power management\SPMgr.exe" [2004-06-29 180224]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2003-09-19 61440]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-21 58984]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"PDService.exe"="c:\program files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 40960]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-10-13 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-08-15 100056]
"TSE_PLUtil"="c:\program files\USB 2.0 Flash Drive Utility\PLBkMon.exe" [2004-09-15 94208]
"PLFFAP"="c:\windows\system32\HotfixQ0306270.exe" [2003-08-05 45056]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VAIO Update 3"="c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [2007-01-25 546936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-19 54424]
c:\documents and settings\DAN\Menu D'marrer\Programmes\D'marrage\
Notification de cadeaux MSN.lnk - c:\documents and settings\DAN\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe [2009-6-7 135680]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2007-12-3 82026]
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-3 110592]
Assistant d'Acrobat.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-7-30 217195]
BTTray.lnk - c:\program files\WIDCOMM\Logiciel Bluetooth\BTTray.exe [2003-9-19 503869]
DSLMON.lnk - c:\program files\modem ADSL USB\modem ADSL USB\dslmon.exe [2005-5-5 925770]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2004-11-20 135680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"=SSMSFltr.dll
"mixer1"=SSMSFltr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\sony\\vaio media 3.1\\Vc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R0 PLFF;USB Flash Disk Driver;c:\windows\system32\drivers\plff.sys [23/03/2005 15:15 7424]
R1 PrivateDisk;PrivateDisk;c:\windows\system32\drivers\privatediskm.sys [06/07/2004 15:07 45627]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2010 11:15 66632]
R2 Apache-Catalina;Apache-Catalina;c:\program files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe [05/07/2007 17:56 65536]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [30/10/2002 17:10 71961]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07/05/2006 23:32 642560]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [12/11/2004 22:23 223232]
S3 EPUSBSTOR;EPSON USB Storage Driver;c:\windows\system32\drivers\epusbsto.sys [10/09/2001 02:00 17976]
S3 P1171VID;Creative WebCam Notebook #2;c:\windows\system32\drivers\P1171Vid.sys [15/06/2005 21:30 91392]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [17/02/2010 11:15 12872]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [07/05/2006 23:36 223128]
.
Contenu du dossier 'Tâches planifiées'
2010-03-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2010-01-01 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2003-08-22 19:06]
2010-03-28 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-12 18:03]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Envoyer à &Bluetooth - c:\program files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0D9392CD-A784-4FCA-9342-0F75F7D7C8CB} - hxxp://www.cltnet.de/login/dplaunch.cab
DPF: {254E4AA8-659F-4A93-A9D2-C924F5975DCD} - hxxp://www.libersud.com/Liber'Chat.CAB
DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-2.0.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-adiras - adiras.exe
HKLM-Run-Easy PDF Creator - c:\program files\Easy PDF Creator\EasyPDFCreator.exe
AddRemove-ForPilots Logbook - d:\daniel\travail\05_offres\stratégie eau\offre services\z2-logbook_2\DeIsL1.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-28 20:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-4070011834-265495275-3555933719-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(904)
c:\windows\system32\SSMSFltr.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(960)
c:\windows\system32\SSMSFltr.dll
.
Heure de fin: 2010-03-28 20:11:14
ComboFix-quarantined-files.txt 2010-03-28 18:11
Avant-CF: 8 988 975 104 octets libres
Après-CF: 8 961 916 928 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
- - End Of File - - 17552A2CBD95D3EA7F99EEA72C19B074
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.219 [GMT 2:00]
Lancé depuis: c:\documents and settings\DAN\Bureau\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {B5510F6F-87E1-47F7-A411-360BC453007C}
FW: Norton Internet Security *disabled* {825036E0-9F94-4752-8789-8B92454AF49B}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Ijl11.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-28 au 2010-03-28 ))))))))))))))))))))))))))))))))))))
.
2010-03-24 21:48 . 2010-03-24 21:48 -------- d-----w- C:\Kill'em
2010-03-24 21:45 . 2010-03-24 21:59 -------- d-----w- c:\program files\List_Kill'em
2010-03-23 21:27 . 2010-03-23 21:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-03-23 21:26 . 2010-03-23 21:26 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-03-23 21:26 . 2010-03-23 21:26 -------- d-----w- c:\documents and settings\DAN\Application Data\SUPERAntiSpyware.com
2010-03-23 21:24 . 2010-03-23 21:24 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2010-03-16 21:58 . 2010-03-18 20:33 1956 ----a-w- C:\UsbFix_Upload_Me_PORTABLE-DANIEL.zip
2010-03-15 20:08 . 2010-03-21 17:03 -------- d-----w- C:\UsbFix
2010-03-15 00:27 . 2010-03-15 00:27 1470 ----a-w- C:\FindyKill_Upload_Me_PORTABLE-DANIEL.zip
2010-03-14 22:49 . 2010-03-15 04:43 -------- d-----w- C:\FyK
2010-03-14 13:31 . 2010-03-14 15:15 -------- d-----w- C:\Ad-Remover
2010-03-14 00:31 . 2010-03-14 00:31 -------- d-----w- c:\documents and settings\DAN\Application Data\Malwarebytes
2010-03-14 00:31 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-14 00:31 . 2010-03-14 00:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-14 00:31 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-14 00:31 . 2010-03-14 02:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-13 21:20 . 2010-03-14 22:23 -------- d-----w- c:\program files\trend micro
2010-03-13 21:20 . 2010-03-14 22:47 -------- d-----w- C:\rsit
2010-03-13 19:56 . 2010-03-13 19:56 -------- d-----w- c:\program files\AxBx
2010-03-13 10:13 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-28 09:46 . 2004-08-27 08:33 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2010-03-23 21:28 . 2010-03-23 21:28 52224 ----a-w- c:\documents and settings\DAN\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-03-23 21:28 . 2010-03-23 21:28 117760 ----a-w- c:\documents and settings\DAN\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-28 20:30 . 2005-10-08 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
2010-02-28 20:29 . 2008-01-02 15:43 -------- d-----w- c:\program files\Messenger Plus! Live
2009-12-31 16:50 . 2004-08-26 14:34 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-05 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 339968]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2004-06-29 122880]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2004-01-19 290816]
"SonyPowerCfg"="c:\program files\sony\vaio power management\SPMgr.exe" [2004-06-29 180224]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2003-09-19 61440]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-02-21 58984]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"PDService.exe"="c:\program files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 40960]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-10-13 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-08-15 100056]
"TSE_PLUtil"="c:\program files\USB 2.0 Flash Drive Utility\PLBkMon.exe" [2004-09-15 94208]
"PLFFAP"="c:\windows\system32\HotfixQ0306270.exe" [2003-08-05 45056]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VAIO Update 3"="c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [2007-01-25 546936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-19 54424]
c:\documents and settings\DAN\Menu D'marrer\Programmes\D'marrage\
Notification de cadeaux MSN.lnk - c:\documents and settings\DAN\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe [2009-6-7 135680]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2007-12-3 82026]
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-3 110592]
Assistant d'Acrobat.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-7-30 217195]
BTTray.lnk - c:\program files\WIDCOMM\Logiciel Bluetooth\BTTray.exe [2003-9-19 503869]
DSLMON.lnk - c:\program files\modem ADSL USB\modem ADSL USB\dslmon.exe [2005-5-5 925770]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2004-11-20 135680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"wave1"=SSMSFltr.dll
"mixer1"=SSMSFltr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\sony\\vaio media 3.1\\Vc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R0 PLFF;USB Flash Disk Driver;c:\windows\system32\drivers\plff.sys [23/03/2005 15:15 7424]
R1 PrivateDisk;PrivateDisk;c:\windows\system32\drivers\privatediskm.sys [06/07/2004 15:07 45627]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 11:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17/02/2010 11:15 66632]
R2 Apache-Catalina;Apache-Catalina;c:\program files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe [05/07/2007 17:56 65536]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [30/10/2002 17:10 71961]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07/05/2006 23:32 642560]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [12/11/2004 22:23 223232]
S3 EPUSBSTOR;EPSON USB Storage Driver;c:\windows\system32\drivers\epusbsto.sys [10/09/2001 02:00 17976]
S3 P1171VID;Creative WebCam Notebook #2;c:\windows\system32\drivers\P1171Vid.sys [15/06/2005 21:30 91392]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [17/02/2010 11:15 12872]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [07/05/2006 23:36 223128]
.
Contenu du dossier 'Tâches planifiées'
2010-03-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2010-01-01 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2003-08-22 19:06]
2010-03-28 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-11-12 18:03]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Envoyer à &Bluetooth - c:\program files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0D9392CD-A784-4FCA-9342-0F75F7D7C8CB} - hxxp://www.cltnet.de/login/dplaunch.cab
DPF: {254E4AA8-659F-4A93-A9D2-C924F5975DCD} - hxxp://www.libersud.com/Liber'Chat.CAB
DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-2.0.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-adiras - adiras.exe
HKLM-Run-Easy PDF Creator - c:\program files\Easy PDF Creator\EasyPDFCreator.exe
AddRemove-ForPilots Logbook - d:\daniel\travail\05_offres\stratégie eau\offre services\z2-logbook_2\DeIsL1.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-28 20:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-4070011834-265495275-3555933719-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(904)
c:\windows\system32\SSMSFltr.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(960)
c:\windows\system32\SSMSFltr.dll
.
Heure de fin: 2010-03-28 20:11:14
ComboFix-quarantined-files.txt 2010-03-28 18:11
Avant-CF: 8 988 975 104 octets libres
Après-CF: 8 961 916 928 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
- - End Of File - - 17552A2CBD95D3EA7F99EEA72C19B074
Bonsoir,
tu es su d'avoir bien copié tout le rapport combo fix, sinon joint le avec ceci :
http://ww38.toofiles.com/fr/documents-upload.html
tu es su d'avoir bien copié tout le rapport combo fix, sinon joint le avec ceci :
http://ww38.toofiles.com/fr/documents-upload.html
Le lien :
http://ww38.toofiles.com/fr/oip/documents/txt/combofix.html
Hier, j'ai bien copier/coller tout le contenu du combo fix.
Si vous avez un doute je peux recommencer
http://ww38.toofiles.com/fr/oip/documents/txt/combofix.html
Hier, j'ai bien copier/coller tout le contenu du combo fix.
Si vous avez un doute je peux recommencer
plus de fenêtre intempestive
MSN OK
il rame tjs autant à l'ouverture et à la fermeture
ouverture internet longue
ouverture d'application word, excel tjs un peu longue
Je le sens plus en forme cependant
MSN OK
il rame tjs autant à l'ouverture et à la fermeture
ouverture internet longue
ouverture d'application word, excel tjs un peu longue
Je le sens plus en forme cependant
List'em by g3n-h@ckm@n 1.6.0.5
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 21:40:16 | 30/03/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ Enabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,31 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (14 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\sony\vaio power management\SPMgr.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\modem ADSL USB\modem ADSL USB\dslmon.exe
C:\Documents and Settings\DAN\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
SUPERAntiSpyware REG_SZ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
ATIPTA REG_SZ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKSERV.EXE REG_SZ C:\Program Files\Sony\HotKey Utility\HKserv.exe
Switcher.exe REG_SZ C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
SonyPowerCfg REG_SZ C:\Program Files\sony\vaio power management\SPMgr.exe
Hcontrol REG_SZ C:\WINDOWS\ATK0100\Hcontrol.exe
Mouse Suite 98 Daemon REG_SZ ICO.EXE
BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
ezShieldProtector for Px REG_SZ C:\WINDOWS\system32\ezSP_Px.exe
PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
iTunesHelper REG_SZ C:\Program Files\iTunes\iTunesHelper.exe
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Symantec NetDriver Monitor REG_SZ C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
TSE_PLUtil REG_SZ C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
PLFFAP REG_SZ C:\WINDOWS\system32\HotfixQ0306270.exe
NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
VAIO Update 3 REG_SZ "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
DisableRegistryTools REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ PORTABLE-DANIEL
DefaultUserName REG_SZ DAN
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ DAN
AltDefaultDomainName REG_SZ PORTABLE-DANIEL
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe REG_SZ C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
C:\Program Files\sony\vaio media 3.1\Vc.exe REG_SZ C:\Program Files\sony\vaio media 3.1\Vc.exe:*:Disabled:[VAIO Media] VAIO Media
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{02BCC737-B171-4746-94C9-0D8A0B2C0089}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0D9392CD-A784-4FCA-9342-0F75F7D7C8CB}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{254E4AA8-659F-4A93-A9D2-C924F5975DCD}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5ED80217-570B-4DA9-BF44-BE107C0EC166}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{88764F69-3831-4EC1-B40B-FF21D8381345}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x2 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ERDNT\cache\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ERDNT\cache\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
##
86912,95b858761a00e1d4f81f79a0da019aca,5e41dae055bcb8ee8ad23d3c77d69df09c6b1e301c889aec6f02193d7dec352b,C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
=======
D'fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
27,95 Go total, 8,31 Go libre (29%), 25% fragment' (fragmentation du fichier 45%)
Vous devriez d'fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\WINDOWS\000001_.tmp
Present !! : C:\WINDOWS\003422_.tmp
Present !! : C:\WINDOWS\_wi190.tmp
Present !! : C:\WINDOWS\System32\_*.dll
Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : C:\WINDOWS\unins000.dat
Present !! : C:\WINDOWS\unins000.exe
Present !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_USERS\S-1-5-21-4070011834-265495275-3555933719-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_USERS\S-1-5-21-4070011834-265495275-3555933719-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-30 21:51:00
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe >>UNKNOWN [0x82B8EE30]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x82b8ee30
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 21:51:01,16
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 21:40:16 | 30/03/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ Enabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,31 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (14 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
Boot: Normal
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\sony\vaio power management\SPMgr.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
C:\WINDOWS\system32\HotfixQ0306270.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
C:\Program Files\modem ADSL USB\modem ADSL USB\dslmon.exe
C:\Documents and Settings\DAN\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
swg REG_SZ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
SpybotSD TeaTimer REG_SZ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
SUPERAntiSpyware REG_SZ C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Apoint REG_SZ C:\Program Files\Apoint\Apoint.exe
ATIPTA REG_SZ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
HKSERV.EXE REG_SZ C:\Program Files\Sony\HotKey Utility\HKserv.exe
Switcher.exe REG_SZ C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
SonyPowerCfg REG_SZ C:\Program Files\sony\vaio power management\SPMgr.exe
Hcontrol REG_SZ C:\WINDOWS\ATK0100\Hcontrol.exe
Mouse Suite 98 Daemon REG_SZ ICO.EXE
BluetoothAuthenticationAgent REG_SZ rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
ISBMgr.exe REG_SZ C:\Program Files\Sony\ISB Utility\ISBMgr.exe
ccApp REG_SZ "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
ezShieldProtector for Px REG_SZ C:\WINDOWS\system32\ezSP_Px.exe
PDService.exe REG_SZ C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
iTunesHelper REG_SZ C:\Program Files\iTunes\iTunesHelper.exe
QuickTime Task REG_SZ "C:\Program Files\QuickTime\qttask.exe" -atboottime
Symantec NetDriver Monitor REG_SZ C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
TSE_PLUtil REG_SZ C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe
PLFFAP REG_SZ C:\WINDOWS\system32\HotfixQ0306270.exe
NeroFilterCheck REG_SZ C:\WINDOWS\system32\NeroCheck.exe
VAIO Update 3 REG_SZ "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
DisableRegistryTools REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
NoDriveTypeAutoRun REG_DWORD 323 (0x143)
NoDrives REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
AutoRestartShell REG_DWORD 1 (0x1)
DefaultDomainName REG_SZ PORTABLE-DANIEL
DefaultUserName REG_SZ DAN
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD -1 (0xffffffff)
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0 (0x0)
passwordexpirywarning REG_DWORD 14 (0xe)
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 1 (0x1)
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 1 (0x1)
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0 (0x0)
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
ShowLogonOptions REG_DWORD 0 (0x0)
AltDefaultUserName REG_SZ DAN
AltDefaultDomainName REG_SZ PORTABLE-DANIEL
ChangePasswordUseKerberos REG_DWORD 1 (0x1)
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AtiExtEvent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe REG_SZ C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix
C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
C:\Program Files\sony\vaio media 3.1\Vc.exe REG_SZ C:\Program Files\sony\vaio media 3.1\Vc.exe:*:Disabled:[VAIO Media] VAIO Media
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Disabled:iTunes
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Windows Live\Messenger\wlcsdk.exe REG_SZ C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call
C:\Program Files\Windows Live\Messenger\msnmsgr.exe REG_SZ C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe REG_SZ C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare
===============
ActivX controls
===============
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\Microsoft XML Parser for Java]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{02BCC737-B171-4746-94C9-0D8A0B2C0089}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{0D9392CD-A784-4FCA-9342-0F75F7D7C8CB}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{254E4AA8-659F-4A93-A9D2-C924F5975DCD}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5ED80217-570B-4DA9-BF44-BE107C0EC166}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{88764F69-3831-4EC1-B40B-FF21D8381345}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
[HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}]
===============
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{CB58DED6-4AF3-4080-9DF1-DEE72075169F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
==============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
===
DNS
===
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4180E8D4-D60E-437F-B270-8381C7FBC118}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.msn.com/fr-fr
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ https://www.google.com/?gws_rd=ssl
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3 ( OK = 3 )
EapHost : 0x2 ( OK = 2 )
SharedAccess : 0x2 ( OK = 2 )
wuauserv : 0x2 ( OK = 2 )
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ERDNT\cache\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ERDNT\cache\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
##
96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Program Files\List_Kill'em
## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
##
86912,95b858761a00e1d4f81f79a0da019aca,5e41dae055bcb8ee8ad23d3c77d69df09c6b1e301c889aec6f02193d7dec352b,C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
Référence :
==========
Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
Win XP_32b : a64013e98426e1877cb653685c5c0009
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e
=======
Drive :
=======
D'fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
27,95 Go total, 8,31 Go libre (29%), 25% fragment' (fragmentation du fichier 45%)
Vous devriez d'fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\WINDOWS\000001_.tmp
Present !! : C:\WINDOWS\003422_.tmp
Present !! : C:\WINDOWS\_wi190.tmp
Present !! : C:\WINDOWS\System32\_*.dll
Present !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Present !! : C:\WINDOWS\unins000.dat
Present !! : C:\WINDOWS\unins000.exe
Present !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_USERS\S-1-5-21-4070011834-265495275-3555933719-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : HKEY_USERS\S-1-5-21-4070011834-265495275-3555933719-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
============
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-30 21:51:00
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe >>UNKNOWN [0x82B8EE30]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> 0x82b8ee30
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
End of scan : 21:51:01,16
Le rootkit est encore là :
Peux tu faire L4option restor MBR de list&Killem et me poster le rapport s'il ya .
Peux tu faire L4option restor MBR de list&Killem et me poster le rapport s'il ya .
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
un certain gen-hackman venu en soutien m'a demandé de choisir l'option "Clean".
Je viens de le faire, je vous transmets le rapport :
Kill'em by g3n-h@ckm@n 1.6.0.5
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 19:58:41 | 03/04/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ (!) Disabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,11 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (14 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\WINDOWS\000001_.tmp
Quarantined & Deleted !! : C:\WINDOWS\003422_.tmp
Quarantined & Deleted !! : C:\WINDOWS\_wi190.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\_Source21.Dll
Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\WINDOWS\unins000.dat
Quarantined & Deleted !! : C:\WINDOWS\unins000.exe
Quarantined & Deleted !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
==============
host file OK !
==============
========
Registry
========
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
============
=================
anti-ver blaster : OK !!
=================
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Je viens de le faire, je vous transmets le rapport :
Kill'em by g3n-h@ckm@n 1.6.0.5
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 19:58:41 | 03/04/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ (!) Disabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,11 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (14 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\WINDOWS\000001_.tmp
Quarantined & Deleted !! : C:\WINDOWS\003422_.tmp
Quarantined & Deleted !! : C:\WINDOWS\_wi190.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\_Source21.Dll
Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\WINDOWS\unins000.dat
Quarantined & Deleted !! : C:\WINDOWS\unins000.exe
Quarantined & Deleted !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
==============
host file OK !
==============
========
Registry
========
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
============
=================
anti-ver blaster : OK !!
=================
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
bonsoir je viens apporter mon soutien :
▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'Option Clean
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
▶ colle le contenu dans ta reponse
▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
▶ choisis l'Option Clean
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
▶ colle le contenu dans ta reponse
j'ai fait ce que Pimprenel demandait et également ce que vouis demandiez :
Rapport de "clean" :
Kill'em by g3n-h@ckm@n 1.6.0.5
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 19:58:41 | 03/04/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ (!) Disabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,11 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (14 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\WINDOWS\000001_.tmp
Quarantined & Deleted !! : C:\WINDOWS\003422_.tmp
Quarantined & Deleted !! : C:\WINDOWS\_wi190.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\_Source21.Dll
Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\WINDOWS\unins000.dat
Quarantined & Deleted !! : C:\WINDOWS\unins000.exe
Quarantined & Deleted !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
==============
host file OK !
==============
========
Registry
========
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
============
=================
anti-ver blaster : OK !!
=================
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Rapport de "restor MBR de list&Killem"
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
Rapport de "clean" :
Kill'em by g3n-h@ckm@n 1.6.0.5
User : DAN (Administrateurs)
Update on 24/03/2010 by g3n-h@ckm@n ::::: 17.00
Start at: 19:58:41 | 03/04/2010
Intel(R) Pentium(R) M processor 1.60GHz
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : Norton AntiVirus 2004 [ (!) Disabled | (!) Outdated ]
FW : Norton Internet Security[ (!) Disabled ]2004
C:\ -> Disque fixe local | 27,95 Go (8,11 Go free) [Système Portable Daniel] | NTFS
D:\ -> Disque fixe local | 46,58 Go (14 Go free) [Données Portable Daniel] | NTFS
E:\ -> Disque amovible
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM | 556,94 Mo (0 Mo free) [SIMCITY4] | CDFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Giat Industries\Publigiat\Tomcat-4.0\bin\tomcat.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_Task.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\List_Kill'em\ERUNT.EXE
C:\Program Files\List_Kill'em\pv.exe
Detections :
==========
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\WINDOWS\000001_.tmp
Quarantined & Deleted !! : C:\WINDOWS\003422_.tmp
Quarantined & Deleted !! : C:\WINDOWS\_wi190.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\_Source21.Dll
Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\WINDOWS\unins000.dat
Quarantined & Deleted !! : C:\WINDOWS\unins000.exe
Quarantined & Deleted !! : C:\Documents and Settings\DAN\LOCAL Settings\Temp\SSUPDATE.EXE
==============
host file OK !
==============
========
Registry
========
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Deleted : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
========
Services
=========
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
============
Disk Cleaned
============
=================
anti-ver blaster : OK !!
=================
================
Prefetch cleaned
================
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Rapport de "restor MBR de list&Killem"
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
▶ Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
* - Coche Afficher les fichiers et dossiers cachés
* - Décoche Masquer les extensions des fichiers dont le type est connu
* - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
▶ clique sur Appliquer, puis OK.
N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important
Fais analyser le(s) fichier(s) suivants sur Virustotal :
Virus Total
* Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :
c:\windows\system32\ntoskrnl.exe
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
* Une nouvelle fenêtre de ton navigateur va apparaître
* Clique alors sur les deux fleches
* Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
* Enfin colle le résultat dans ta prochaine réponse.
Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.
* - Coche Afficher les fichiers et dossiers cachés
* - Décoche Masquer les extensions des fichiers dont le type est connu
* - Décoche Masquer les fichiers protégés du système d'exploitation (recommandé)
▶ clique sur Appliquer, puis OK.
N'oublie pas de recacher à nouveau les fichiers cachés et protégés du système d'exploitation en fin de désinfection, c'est important
Fais analyser le(s) fichier(s) suivants sur Virustotal :
Virus Total
* Clique sur Parcourir en haut, choisis Poste de travail et cherche ces fichiers :
c:\windows\system32\ntoskrnl.exe
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
* Une nouvelle fenêtre de ton navigateur va apparaître
* Clique alors sur les deux fleches
* Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
* Enfin colle le résultat dans ta prochaine réponse.
Note : Pour analyser un autre fichier, clique en bas sur Autre fichier.