Infecté par win32gen et d'autres trucs
Beastie Toy
-
Ben -
Ben -
Je suis infecté par plusieurs trojan...
Voici le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 13:07:19, on 02/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Documents and Settings\Kev\Bureau\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1036
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [remoteholenameamen] C:\Documents and Settings\All Users\Application Data\Mfcdbindremotehole\DeadGram.exe
O4 - HKLM\..\Run: [WellPhone DirectSync - ScheduleSync] C:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Tons Two] C:\DOCUME~1\Kev\APPLIC~1\FLAGDE~1\Ownscamppure.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Voici le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 13:07:19, on 02/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Documents and Settings\Kev\Bureau\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8&gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1036
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [remoteholenameamen] C:\Documents and Settings\All Users\Application Data\Mfcdbindremotehole\DeadGram.exe
O4 - HKLM\..\Run: [WellPhone DirectSync - ScheduleSync] C:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Tons Two] C:\DOCUME~1\Kev\APPLIC~1\FLAGDE~1\Ownscamppure.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
A voir également:
- Infecté par win32gen et d'autres trucs
- Alerte windows ordinateur infecté - Accueil - Arnaque
- L'ordinateur de simon a été infecté par un virus répertorié récemment ✓ - Forum Virus
- L'ordinateur de mustapha a été infecté par un virus répertorié récemment - Forum Virus
- Mustapha - Forum Windows
- L'ordinateur de samantha a ete infecte par un virus - Forum Virus
2 réponses
LE RAPPORT AVG ANTI SPYWARE
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 14:42:02 02/03/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026662.dll -> Adware.Virtumonde : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026520.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026521.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP98\A0014746.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\antzom[1].exe -> Downloader.Agent.bgn : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\WVR1MZZE\new[1].htm -> Downloader.Agent.bi : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\exp2[2].htm -> Downloader.Agent.bx : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp1[1].htm -> Downloader.Agent.cd : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\xc23[1].exe -> Downloader.Tiny.fk : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0025503.exe -> Downloader.Tiny.fk : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\exp3[2].htm -> Not-A-Virus.Exploit.HTML.IESlice.d : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp4[2].htm -> Not-A-Virus.Exploit.HTML.VML.d : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp5[2].htm -> Not-A-Virus.Exploit.JS.XMLCore.a : Aucune action entreprise.
:mozilla.8:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.128:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.129:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.130:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.245:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@adrevolver[2].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
:mozilla.173:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.174:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.88:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
:mozilla.131:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.142:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Com : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Aucune action entreprise.
:mozilla.63:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.62:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Estat : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
:mozilla.190:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.191:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@ehg-hollywoodmedia.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.76:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
:mozilla.198:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.199:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.200:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@guide.real[2].txt -> TrackingCookie.Real : Aucune action entreprise.
:mozilla.70:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.71:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.72:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.73:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.74:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.35:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Sexcounter : Aucune action entreprise.
:mozilla.36:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Sexcounter : Aucune action entreprise.
:mozilla.11:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.12:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.13:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.14:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.166:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Statcounter : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.141:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.181:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.
:mozilla.18:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.19:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.20:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.21:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Aucune action entreprise.
:mozilla.236:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Yadro : Aucune action entreprise.
:mozilla.237:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Yadro : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@zedo[2].txt -> TrackingCookie.Zedo : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\xc29[1].exe -> Trojan.Agent.qt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0023069.exe -> Trojan.Agent.qt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026724.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\Temp\mst1A3.tmp -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\Temp\mst310.tmp -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\system32\drvwuj.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\system32\drvxag.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\52NAT80B\srvowd[1].exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\52NAT80B\srvpxl[1].exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0024376.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0025502.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0026489.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026519.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP125\A0026581.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026656.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026664.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026682.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026716.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP128\A0026734.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\__delete_on_reboot__w_i_n_3_E_9_._t_m_p_._e_x_e_ -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\win4E9.tmp.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\win4EC.tmp.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\system32\__delete_on_reboot__u_d_i_a_l_._e_x_e_ -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0024394.exe -> Trojan.Inject.ba : Aucune action entreprise.
C:\Documents and Settings\Kev\Application Data\flagdebug\ribnrzoj.exe -> Trojan.Obfuscated.bk : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026663.exe -> Trojan.Obfuscated.bk : Aucune action entreprise.
Fin du rapport
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 14:42:02 02/03/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026662.dll -> Adware.Virtumonde : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026520.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026521.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP98\A0014746.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\antzom[1].exe -> Downloader.Agent.bgn : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\WVR1MZZE\new[1].htm -> Downloader.Agent.bi : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\exp2[2].htm -> Downloader.Agent.bx : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp1[1].htm -> Downloader.Agent.cd : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\xc23[1].exe -> Downloader.Tiny.fk : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0025503.exe -> Downloader.Tiny.fk : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\exp3[2].htm -> Not-A-Virus.Exploit.HTML.IESlice.d : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp4[2].htm -> Not-A-Virus.Exploit.HTML.VML.d : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp5[2].htm -> Not-A-Virus.Exploit.JS.XMLCore.a : Aucune action entreprise.
:mozilla.8:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.128:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.129:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.130:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.245:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@adrevolver[2].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
:mozilla.173:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.174:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.88:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
:mozilla.131:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.142:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Com : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Aucune action entreprise.
:mozilla.63:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.62:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Estat : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
:mozilla.190:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.191:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@ehg-hollywoodmedia.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.76:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
:mozilla.198:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.199:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.200:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@guide.real[2].txt -> TrackingCookie.Real : Aucune action entreprise.
:mozilla.70:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.71:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.72:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.73:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.74:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.35:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Sexcounter : Aucune action entreprise.
:mozilla.36:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Sexcounter : Aucune action entreprise.
:mozilla.11:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.12:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.13:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.14:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.166:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Statcounter : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.141:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.181:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.
:mozilla.18:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.19:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.20:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.21:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Aucune action entreprise.
:mozilla.236:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Yadro : Aucune action entreprise.
:mozilla.237:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Yadro : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@zedo[2].txt -> TrackingCookie.Zedo : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\xc29[1].exe -> Trojan.Agent.qt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0023069.exe -> Trojan.Agent.qt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026724.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\Temp\mst1A3.tmp -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\Temp\mst310.tmp -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\system32\drvwuj.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\system32\drvxag.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\52NAT80B\srvowd[1].exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\52NAT80B\srvpxl[1].exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0024376.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0025502.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0026489.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026519.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP125\A0026581.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026656.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026664.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026682.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026716.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP128\A0026734.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\__delete_on_reboot__w_i_n_3_E_9_._t_m_p_._e_x_e_ -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\win4E9.tmp.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\win4EC.tmp.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\system32\__delete_on_reboot__u_d_i_a_l_._e_x_e_ -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0024394.exe -> Trojan.Inject.ba : Aucune action entreprise.
C:\Documents and Settings\Kev\Application Data\flagdebug\ribnrzoj.exe -> Trojan.Obfuscated.bk : Aucune action entreprise.
C:\System Volume Information\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026663.exe -> Trojan.Obfuscated.bk : Aucune action entreprise.
Fin du rapport
Bonjour, même soucis avec un trojan/dialer qui se multiplie dès que le fichier est accédé sur le dd .. dans les temp/ cherchant toujours à se connecter à la même adresse ..
Pour mon premier, mon premier rapport
Logfile of HijackThis v1.99.1
Scan saved at 11:59:19, on 24/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\AVG AS 7.5\guard.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Kerio-Personal Firewall\persfw.exe
C:\windows\System32\snmp.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\carpserv.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\windows\system32\taskmgr.exe
E:\Program Files\wifi\Utility\Gear511.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Direct Folders\df.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVG AS 7.5\avgas.exe
C:\Program Files\Desktop Calendar\Desktop Calendar.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
C:\Documents and Settings\Propriétaire\Bureau\VundoFix\scanner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bens-world.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:6588
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1; 192.168.*;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {69C670C4-CF71-4795-9085-2158B8653778} - C:\windows\system32\rqrpqnm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {D91A1F3E-0905-41C1-A9FA-EE3609E4E675} - C:\windows\system32\vturq.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TV Now] "C:\Program Files\HPQ\Notebook Utilities\TvNow.exe" /RK
O4 - HKLM\..\Run: [Display Settings] "C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" /s
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AS00_Gear511] "E:\Program Files\wifi\Utility\Gear511.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [DirectFolders] "C:\Program Files\Direct Folders\df.exe"
O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\windows\system32\drvxaw.dll,startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG AS 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O8 - Extra context menu item: Save Flash - res://C:\Program Files\Flash Saving Plugin\FlashSButton.dll/210
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\Flash Saving Plugin\FlashSButton.dll (HKCU)
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\windows\System32\shdocvw.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\windows\System32\shdocvw.dll (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: https://www.ngswing.com/
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0(...)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb(...)
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = P266
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: NavLogon - C:\windows\System32\NavLogon.dll
O20 - Winlogon Notify: rqrpqnm - C:\windows\SYSTEM32\rqrpqnm.dll
O20 - Winlogon Notify: vturq - C:\windows\system32\vturq.dll
O20 - Winlogon Notify: winezn32 - C:\windows\SYSTEM32\winezn32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG AS 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: COM+ Messages - Unknown owner - C:\windows\system32\svchosts.exe" -e mc-110-12-0000272 (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio-Personal Firewall\persfw.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Unknown owner - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
Les fichiers temp sont souvent lockés par winlogon.exe
Se multipliant à intervalles réguliers (et de lecture)
Le checksum de explorer.exe ayant changé au début de l'infection ..
Merci de vos lumières :super:
[img]http://img451.imageshack.us/img451/7506/trojancx6.jpg[/img]
Ce dialer Trojan vient bien de l'Italie apparement .. mais aucun removal tool à ce jour ..
Pour mon premier, mon premier rapport
Logfile of HijackThis v1.99.1
Scan saved at 11:59:19, on 24/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\AVG AS 7.5\guard.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Kerio-Personal Firewall\persfw.exe
C:\windows\System32\snmp.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\carpserv.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\windows\system32\taskmgr.exe
E:\Program Files\wifi\Utility\Gear511.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Direct Folders\df.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVG AS 7.5\avgas.exe
C:\Program Files\Desktop Calendar\Desktop Calendar.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
C:\Documents and Settings\Propriétaire\Bureau\VundoFix\scanner.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bens-world.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:6588
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1; 192.168.*;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {69C670C4-CF71-4795-9085-2158B8653778} - C:\windows\system32\rqrpqnm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {D91A1F3E-0905-41C1-A9FA-EE3609E4E675} - C:\windows\system32\vturq.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [TV Now] "C:\Program Files\HPQ\Notebook Utilities\TvNow.exe" /RK
O4 - HKLM\..\Run: [Display Settings] "C:\Program Files\HPQ\Notebook Utilities\hptasks.exe" /s
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AS00_Gear511] "E:\Program Files\wifi\Utility\Gear511.exe" -hide
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [DirectFolders] "C:\Program Files\Direct Folders\df.exe"
O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\windows\system32\drvxaw.dll,startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG AS 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\WebshotsTray.exe
O8 - Extra context menu item: Save Flash - res://C:\Program Files\Flash Saving Plugin\FlashSButton.dll/210
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Fichiers communs\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\Flash Saving Plugin\FlashSButton.dll (HKCU)
O9 - Extra button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\windows\System32\shdocvw.dll (HKCU)
O9 - Extra 'Tools' menuitem: Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - C:\windows\System32\shdocvw.dll (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: https://www.ngswing.com/
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0(...)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb(...)
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = P266
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: NavLogon - C:\windows\System32\NavLogon.dll
O20 - Winlogon Notify: rqrpqnm - C:\windows\SYSTEM32\rqrpqnm.dll
O20 - Winlogon Notify: vturq - C:\windows\system32\vturq.dll
O20 - Winlogon Notify: winezn32 - C:\windows\SYSTEM32\winezn32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG AS 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: COM+ Messages - Unknown owner - C:\windows\system32\svchosts.exe" -e mc-110-12-0000272 (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio-Personal Firewall\persfw.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Unknown owner - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\UltraVNC\WinVNC.exe" -service (file missing)
Les fichiers temp sont souvent lockés par winlogon.exe
Se multipliant à intervalles réguliers (et de lecture)
Le checksum de explorer.exe ayant changé au début de l'infection ..
Merci de vos lumières :super:
[img]http://img451.imageshack.us/img451/7506/trojancx6.jpg[/img]
Ce dialer Trojan vient bien de l'Italie apparement .. mais aucun removal tool à ce jour ..