Deux petits virus passant par la...
tnomor
Messages postés
13
Statut
Membre
-
zorinho Messages postés 829 Statut Membre -
zorinho Messages postés 829 Statut Membre -
Bonjour,
j'ai découvert deux petits virus avec kapersky online alors que pcillin ne les avait pas retrouvé? pouvez vous me dire comment les faire disparaitre?
Win32.Blen.r
Win32.Zapchast.gm
quelques rapports
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 17, 2008 7:13:30 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/05/2008
Kaspersky Anti-Virus database records: 695606
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 156809
Number of viruses found: 3
Number of infected objects: 136
Number of suspicious objects: 0
Duration of the scan process: 03:33:19
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Aventail\nglog.lgf Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\jour\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\jour\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Historique\History.IE5\MSHist012008051620080517\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Temp\0exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\10exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\11exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\12exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\13exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\14exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\14exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\15exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\16exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\16exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\18exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\1exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\21exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\23exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\24exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\26exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\27exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\28exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\33exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\33exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\36exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\37exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\3exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\3exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\41exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\41exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\43exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\44exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\45exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\48exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\49exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\50exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\51exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\52exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\52exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\53exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\54exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\55exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\57exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\58exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\59exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\62exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\63exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\67exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\68exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\70exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\71exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\72exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\73exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\76exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\77exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\78exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\81exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\82exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\83exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\84exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\85exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\86exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\86exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\88exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\88exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\90exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\91exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\93exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\95exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\96exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\96exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\97exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\98exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\9exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\9exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\Perflib_Perfdata_274.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\jour\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\jour\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\jour\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\Internet Security\Trusted.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP231\A0063729.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP231\A0063730.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065083.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065084.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065085.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065086.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065087.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065088.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065089.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065090.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065091.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065092.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065093.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065094.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065095.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065096.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065097.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065098.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065099.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065100.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065101.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065102.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065103.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065104.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065105.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065106.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065107.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065108.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065109.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065110.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065111.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065112.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065113.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065114.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065115.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065116.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065117.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065118.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065119.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065120.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065121.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065122.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065123.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065124.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065125.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065126.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065127.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065128.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065129.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065130.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065131.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065132.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065133.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065134.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065135.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065136.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065137.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065138.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065139.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065140.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065141.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065142.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065143.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065144.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065145.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP237\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd6605.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\laurent\pcillin\tis12fr_gm_shop.exe Object is locked skipped
G:\laurent\pcillin\tis14fr_1487_shop.exe Object is locked skipped
G:\laurent\pcillin\tis15fr_1419_shop.exe Object is locked skipped
G:\laurent\pcillin\TIS3264FR.exe Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:21:39, on 17/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Pidgin\pidgin.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FAMTCDE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://2.255.255.254:455/postauth/pacs/AV1192190383555VL.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe
O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_SB3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Aventail VPN Client (NgVpnMgr) - Aventail Corporation - C:\WINDOWS\system32\ngvpnmgr.exe
O23 - Service: PMounter - Unknown owner - C:\WINDOWS\system32\PMounter.exe
O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O24 - Desktop Component 0: (no name) - About:Home
j'ai découvert deux petits virus avec kapersky online alors que pcillin ne les avait pas retrouvé? pouvez vous me dire comment les faire disparaitre?
Win32.Blen.r
Win32.Zapchast.gm
quelques rapports
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 17, 2008 7:13:30 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/05/2008
Kaspersky Anti-Virus database records: 695606
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 156809
Number of viruses found: 3
Number of infected objects: 136
Number of suspicious objects: 0
Duration of the scan process: 03:33:19
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Aventail\nglog.lgf Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\jour\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\jour\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Historique\History.IE5\MSHist012008051620080517\index.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Temp\0exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\10exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\11exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\12exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\13exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\14exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\14exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\15exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\16exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\16exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\18exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\1exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\21exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\23exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\24exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\26exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\27exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\28exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\33exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\33exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\36exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\37exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\3exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\3exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\41exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\41exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\43exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\44exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\45exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\48exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\49exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\50exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\51exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\52exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\52exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\53exymupcnt7.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\54exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\55exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\57exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\58exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\59exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\62exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\63exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\67exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\68exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\70exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\71exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\72exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\73exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\76exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\77exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\78exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\81exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\82exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\83exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\84exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\85exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\86exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\86exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\88exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\88exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\90exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\91exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\93exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\95exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\96exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\96exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\97exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\98exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\9exhmunmlclr11.exe Infected: SpamTool.Win32.Blen.r skipped
C:\Documents and Settings\jour\Local Settings\Temp\9exymupcnt8.exe Infected: Trojan.Win32.Zapchast.gm skipped
C:\Documents and Settings\jour\Local Settings\Temp\Perflib_Perfdata_274.dat Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\jour\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\jour\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\jour\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\jour\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\Internet Security\Trusted.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP231\A0063729.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP231\A0063730.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065083.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065084.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065085.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065086.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065087.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065088.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065089.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065090.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065091.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065092.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065093.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065094.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065095.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065096.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065097.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065098.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065099.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065100.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065101.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065102.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065103.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065104.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065105.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065106.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065107.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065108.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065109.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065110.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065111.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065112.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065113.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065114.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065115.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065116.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065117.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065118.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065119.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065120.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065121.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065122.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065123.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065124.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065125.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065126.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065127.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065128.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065129.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065130.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065131.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065132.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065133.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065134.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065135.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065136.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065137.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065138.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065139.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065140.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065141.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065142.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065143.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065144.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP232\A0065145.exe Infected: SpamTool.Win32.Blen.p skipped
C:\System Volume Information\_restore{833809C4-C6E1-4880-8E56-113637B3EC57}\RP237\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd6605.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\laurent\pcillin\tis12fr_gm_shop.exe Object is locked skipped
G:\laurent\pcillin\tis14fr_1487_shop.exe Object is locked skipped
G:\laurent\pcillin\tis15fr_1419_shop.exe Object is locked skipped
G:\laurent\pcillin\TIS3264FR.exe Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:21:39, on 17/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ngvpnmgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Pidgin\pidgin.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FAMTCDE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://2.255.255.254:455/postauth/pacs/AV1192190383555VL.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [Pidgin] C:\Program Files\Pidgin\pidgin.exe
O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_SB3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Aventail VPN Client (NgVpnMgr) - Aventail Corporation - C:\WINDOWS\system32\ngvpnmgr.exe
O23 - Service: PMounter - Unknown owner - C:\WINDOWS\system32\PMounter.exe
O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O24 - Desktop Component 0: (no name) - About:Home
A voir également:
- Deux petits virus passant par la...
- Virus mcafee - Accueil - Piratage
- Comment faire deux colonnes sur word - Guide
- Nombre de jours entre deux dates excel - Guide
- Deux ecran pc - Guide
- Deux whatsapp sur un téléphone - Guide
1 réponse
Salut,
juste pour te dire que tu n'es pas le premier à avoir ces "trojan".
voir ici
http://www.commentcamarche.net/forum/affich 6424831 virus et troyen reuni
Certains logiciiels le reconnaissent comme trojan, d'autres pas
Il s'agit peut-être de faux positifs
Va sur www.virustotal.com et scanne les fichiers infectés.
Fais-toi ta propre idée.
Au sinon, tu peux appliquer le protocole de la personne qui a eu le même souci que toi
Zor
juste pour te dire que tu n'es pas le premier à avoir ces "trojan".
voir ici
http://www.commentcamarche.net/forum/affich 6424831 virus et troyen reuni
Certains logiciiels le reconnaissent comme trojan, d'autres pas
Il s'agit peut-être de faux positifs
Va sur www.virustotal.com et scanne les fichiers infectés.
Fais-toi ta propre idée.
Au sinon, tu peux appliquer le protocole de la personne qui a eu le même souci que toi
Zor