Ecran rouge spyware ... rien ne marche !
isabret
Messages postés
53
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
J'ai un pbm de spyware .. écran rouge, texte en jaune et blanc et fenetre intempestives ... j'ai suivi les conseils des forum en utilisant SmitFraudFix v2.325 : la premiere fois en scan et la deuxieme en traitement en mode sans echec mais j'ai toujours l'écran et les fenetres ... je viens de refaire les actions pour la 2eme fois et voilà les rapport ! si quelqu'un peut m'aider à me sortir de cette M---- !
j'ai aussi fait un petit coup d'avg antispyware, et d'autres antispyware que j'ai téléchargé ... rien n'y fait !! à l'aide !
RAPPORT 1
SmitFraudFix v2.325
Rapport fait à 22:09:41,36, 16/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Power Management\PwrGui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOWNLOAD\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ISABELLE\FAVORIS
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Carte Fast Ethernet PCI de base SiS 900 #2 - Miniport d'ordonnancement de paquets
DNS Server Search Order: 195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
RAPPORT 2
SmitFraudFix v2.325
Rapport fait à 22:26:41,68, 16/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
J'ai un pbm de spyware .. écran rouge, texte en jaune et blanc et fenetre intempestives ... j'ai suivi les conseils des forum en utilisant SmitFraudFix v2.325 : la premiere fois en scan et la deuxieme en traitement en mode sans echec mais j'ai toujours l'écran et les fenetres ... je viens de refaire les actions pour la 2eme fois et voilà les rapport ! si quelqu'un peut m'aider à me sortir de cette M---- !
j'ai aussi fait un petit coup d'avg antispyware, et d'autres antispyware que j'ai téléchargé ... rien n'y fait !! à l'aide !
RAPPORT 1
SmitFraudFix v2.325
Rapport fait à 22:09:41,36, 16/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Power Management\PwrGui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOWNLOAD\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ISABELLE\FAVORIS
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Carte Fast Ethernet PCI de base SiS 900 #2 - Miniport d'ordonnancement de paquets
DNS Server Search Order: 195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
RAPPORT 2
SmitFraudFix v2.325
Rapport fait à 22:26:41,68, 16/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
A voir également:
- Ecran rouge spyware ... rien ne marche !
- Double ecran - Guide
- Capture d'écran whatsapp - Accueil - Messagerie instantanée
- Retourner ecran pc - Guide
- Mon écran se fige et plus rien ne répond - Guide
- Capture d'écran samsung - Guide
49 réponses
J'en suis là ... "Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer."
Isabelle
Isabelle
"peux tu me reposter un log smitfraud fix en mode sans echec ? j'ai un doute"
j'ai pas encore fait ! je suis avec sdfix idem pour le rapport de mbam ...
bon là sdfix affiche 75% checked ... je le laissebosser !
Isabelle
j'ai pas encore fait ! je suis avec sdfix idem pour le rapport de mbam ...
bon là sdfix affiche 75% checked ... je le laissebosser !
Isabelle
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
voilà le rapport
déjà on sent du mieux ... plus d'écran rouge et connexion via msn
le rapport :
[b]SDFix: Version 1.193 [/b]
Run by Isabelle on 17/06/2008 at 15:07
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
[b]Name [/b]:
aspimgr
[b]Path [/b]:
C:\WINDOWS\system32\aspimgr.exe
aspimgr - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default IE Settings
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\promo1.html - Deleted
C:\WINDOWS\promo2.html - Deleted
C:\WINDOWS\promo3.html - Deleted
C:\WINDOWS\promo4.html - Deleted
C:\WINDOWS\promo5.html - Deleted
C:\WINDOWS\promo6.html - Deleted
C:\WINDOWS\promogif1.gif - Deleted
C:\WINDOWS\promogif2.gif - Deleted
C:\WINDOWS\promogif3.gif - Deleted
C:\WINDOWS\homepage.html - Deleted
C:\WINDOWS\index.html - Deleted
C:\WINDOWS\system32\adult.txt - Deleted
C:\WINDOWS\system32\finance.txt - Deleted
C:\WINDOWS\system32\lt.res - Deleted
C:\WINDOWS\system32\other.txt - Deleted
C:\WINDOWS\system32\pharma.txt - Deleted
C:\WINDOWS\system32\sft.res - Deleted
C:\WINDOWS\system32\sn.txt - Deleted
C:\WINDOWS\system32\sockins32.dll - Deleted
C:\WINDOWS\ws386.ini - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 15:15:15
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Foxmail\\FoxHot.exe"="C:\\Program Files\\Foxmail\\FoxHot.exe:*:Enabled:Foxmail-Hotmail Proxy Application"
"C:\\WINDOWS\\System32\\mmc.exe"="C:\\WINDOWS\\System32\\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\\Program Files\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\LowRateVoip\\LowRateVoip.exe"="C:\\Program Files\\LowRateVoip\\LowRateVoip.exe:*:Enabled:LowRateVoip"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sun 18 May 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Fri 9 May 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 9 May 2008 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv13.bak"
Tue 6 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT4.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\585dc2612ebcefc90e7dee4c276ee95e\BIT3.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9e870549834e2bceb796e44a1e3ac6f5\BITB.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\22fb973e059470cc1b5d76c4ae605351\BITC.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT9.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT8.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT4.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\30285791903730fbf957a83562db4ff4\BIT6.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BITA.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cb8921d0c7830b2f33c00fa4c8a10d17\BIT7.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT5.tmp"
Fri 9 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 9 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 10 Apr 2008 434,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL2720.tmp"
Thu 19 May 2005 30,208 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL2284.tmp"
Thu 15 Feb 2007 1,192,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL1972.tmp"
Thu 15 Feb 2007 1,574,912 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL1584.tmp"
Tue 30 Oct 2007 89,600 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL3278.tmp"
Tue 30 Oct 2007 96,768 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL0320.tmp"
Tue 30 Oct 2007 334,848 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL3180.tmp"
Tue 30 Oct 2007 416,256 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2862.tmp"
Tue 30 Oct 2007 416,768 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL1631.tmp"
Tue 30 Oct 2007 405,504 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL3036.tmp"
Tue 30 Oct 2007 322,048 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2979.tmp"
Tue 30 Oct 2007 276,992 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2318.tmp"
Tue 30 Oct 2007 264,192 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL0539.tmp"
Tue 30 Oct 2007 236,544 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2281.tmp"
Sun 5 Aug 2007 24,576 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\d‚m‚nagement 2007 07\~WRL0130.tmp"
Sun 5 Aug 2007 24,576 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\d‚m‚nagement 2007 07\~WRL3407.tmp"
Mon 2 Apr 2007 147,456 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Anglais\~WRL2544.tmp"
Fri 18 Jan 2008 25,088 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Annonce RCI\~WRL2398.tmp"
Fri 24 Mar 2006 100,352 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Annonce RCI\~WRL2527.tmp"
Wed 3 Oct 2007 27,136 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\informatique maison\~WRL0160.tmp"
Sun 21 Oct 2007 36,864 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\La R‚union\~WRL3784.tmp"
Tue 15 Jan 2008 19,968 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\~WRL0005.tmp"
Fri 9 May 2008 401 A..H. --- "C:\Documents and Settings\Isabelle\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Fri 9 May 2008 4,348 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Tue 15 Nov 2005 400 A.SH. --- "C:\Documents and Settings\Isabelle\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Thu 29 Mar 2007 47,616 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA1 0608 Maths\~WRL2307.tmp"
Wed 11 Oct 2006 25,088 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BPREA Maths\~WRL2415.tmp"
Thu 26 Oct 2006 66,048 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BPREA Maths\~WRL3906.tmp"
Tue 9 Jan 2007 90,112 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL1984.tmp"
Tue 23 Jan 2007 93,696 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL3893.tmp"
Tue 23 Jan 2007 114,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL0387.tmp"
Tue 3 Apr 2007 104,960 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL0004.tmp"
Tue 3 Apr 2007 101,888 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL0002.tmp"
Tue 3 Apr 2007 48,128 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL2939.tmp"
Tue 29 May 2007 178,176 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0753.tmp"
Mon 4 Jun 2007 178,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3710.tmp"
Mon 4 Jun 2007 178,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2276.tmp"
Mon 4 Jun 2007 179,200 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3341.tmp"
Mon 4 Jun 2007 180,224 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3680.tmp"
Mon 4 Jun 2007 180,224 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3358.tmp"
Mon 4 Jun 2007 179,712 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0514.tmp"
Tue 5 Jun 2007 182,272 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2365.tmp"
Tue 5 Jun 2007 400,896 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1505.tmp"
Tue 5 Jun 2007 402,944 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2418.tmp"
Tue 5 Jun 2007 407,552 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3172.tmp"
Tue 5 Jun 2007 410,112 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3669.tmp"
Tue 5 Jun 2007 335,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3994.tmp"
Tue 5 Jun 2007 335,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0273.tmp"
Tue 5 Jun 2007 336,384 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2451.tmp"
Tue 5 Jun 2007 332,288 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2667.tmp"
Tue 28 Nov 2006 25,088 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0001.tmp"
Tue 5 Jun 2007 334,336 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0439.tmp"
Tue 5 Jun 2007 344,064 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2782.tmp"
Tue 5 Jun 2007 340,992 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1727.tmp"
Tue 5 Jun 2007 340,992 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1339.tmp"
Tue 5 Jun 2007 342,528 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0905.tmp"
Tue 5 Jun 2007 342,016 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1763.tmp"
Tue 6 Feb 2007 107,520 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2940.tmp"
Tue 27 Mar 2007 154,624 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1731.tmp"
Tue 5 Jun 2007 342,016 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1101.tmp"
Tue 5 Jun 2007 343,040 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0978.tmp"
Tue 27 Mar 2007 175,104 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2369.tmp"
Tue 5 Jun 2007 343,552 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2294.tmp"
Tue 5 Jun 2007 345,600 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3420.tmp"
Tue 5 Jun 2007 346,112 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0180.tmp"
Tue 5 Jun 2007 346,624 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2205.tmp"
Tue 5 Jun 2007 347,648 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1127.tmp"
Tue 5 Jun 2007 348,160 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3631.tmp"
Tue 5 Jun 2007 343,552 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2760.tmp"
Fri 25 May 2007 155,648 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0058.tmp"
Tue 29 May 2007 164,352 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3228.tmp"
Tue 29 May 2007 162,816 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3662.tmp"
Tue 29 May 2007 170,496 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1279.tmp"
Tue 29 May 2007 181,248 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3086.tmp"
Tue 29 May 2007 181,248 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2277.tmp"
Tue 28 Nov 2006 157,696 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0944.tmp"
Tue 28 Nov 2006 171,520 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1904.tmp"
Tue 28 Nov 2006 169,984 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0476.tmp"
Tue 28 Nov 2006 219,136 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1313.tmp"
Tue 28 Nov 2006 264,192 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0570.tmp"
Tue 28 Nov 2006 267,264 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1839.tmp"
Thu 24 May 2007 74,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\~WRL3168.tmp"
Thu 24 May 2007 74,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\~WRL0220.tmp"
Thu 24 May 2007 76,800 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\~WRL0978.tmp"
Fri 13 Jun 2008 1,088,512 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\~WRL1103.tmp"
Tue 17 Jun 2008 2,336,768 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\~WRL0465.tmp"
Wed 12 Dec 2007 21,504 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\travail\~WRL0862.tmp"
Wed 19 Apr 2006 163,840 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0087.tmp"
Sun 23 Dec 2007 34,304 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1618.tmp"
Sun 23 Dec 2007 32,768 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1559.tmp"
Tue 13 Nov 2007 86,016 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0092.tmp"
Tue 13 Nov 2007 107,008 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL2638.tmp"
Tue 13 Nov 2007 29,696 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL2148.tmp"
Tue 28 Nov 2006 115,712 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0624.tmp"
Fri 14 Mar 2008 145,920 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1275.tmp"
Tue 28 Nov 2006 275,968 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1124.tmp"
Mon 4 Jun 2007 392,192 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL3037.tmp"
Mon 7 Apr 2008 216,064 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL3194.tmp"
Fri 14 Mar 2008 278,528 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL3930.tmp"
Sun 16 Mar 2008 244,736 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0988.tmp"
Thu 8 Feb 2007 143,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\ccf positionnement EM\~WRL1184.tmp"
Thu 8 Feb 2007 143,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\ccf positionnement EM\~WRL2699.tmp"
Thu 7 Jun 2007 330,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL1884.tmp"
Thu 7 Jun 2007 330,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL1813.tmp"
Thu 7 Jun 2007 331,264 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL2664.tmp"
Thu 7 Jun 2007 331,776 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL3877.tmp"
Thu 7 Jun 2007 331,776 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL3641.tmp"
Thu 7 Jun 2007 331,776 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL2265.tmp"
Fri 28 Mar 2008 198,144 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL0238.tmp"
Fri 28 Mar 2008 40,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL3978.tmp"
Fri 28 Mar 2008 24,576 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL0208.tmp"
Fri 28 Mar 2008 24,064 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL1697.tmp"
Fri 28 Mar 2008 40,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL0297.tmp"
Fri 28 Mar 2008 122,880 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL3820.tmp"
Sun 20 Jan 2008 57,344 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\climat r‚union\~WRL3262.tmp"
Sun 20 Jan 2008 83,968 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\climat r‚union\~WRL3340.tmp"
Sun 20 Jan 2008 88,064 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\climat r‚union\~WRL3613.tmp"
Mon 28 Apr 2008 61,952 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL1646.tmp"
Fri 8 Jun 2007 98,816 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL4016.tmp"
Mon 28 Apr 2008 95,232 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL0288.tmp"
Mon 28 Apr 2008 95,232 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL1322.tmp"
Mon 28 Apr 2008 106,496 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL0929.tmp"
Mon 28 Apr 2008 104,960 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL2367.tmp"
Mon 28 Apr 2008 104,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL1010.tmp"
Mon 28 Apr 2008 121,856 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL3553.tmp"
Mon 28 Apr 2008 113,664 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL3277.tmp"
Thu 6 Mar 2008 517,632 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\voile\modŠles fiches cnsp\~WRL0010.tmp"
[b]Finished![/b]
Isabelle
déjà on sent du mieux ... plus d'écran rouge et connexion via msn
le rapport :
[b]SDFix: Version 1.193 [/b]
Run by Isabelle on 17/06/2008 at 15:07
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
[b]Name [/b]:
aspimgr
[b]Path [/b]:
C:\WINDOWS\system32\aspimgr.exe
aspimgr - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Restoring Default IE Settings
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\promo1.html - Deleted
C:\WINDOWS\promo2.html - Deleted
C:\WINDOWS\promo3.html - Deleted
C:\WINDOWS\promo4.html - Deleted
C:\WINDOWS\promo5.html - Deleted
C:\WINDOWS\promo6.html - Deleted
C:\WINDOWS\promogif1.gif - Deleted
C:\WINDOWS\promogif2.gif - Deleted
C:\WINDOWS\promogif3.gif - Deleted
C:\WINDOWS\homepage.html - Deleted
C:\WINDOWS\index.html - Deleted
C:\WINDOWS\system32\adult.txt - Deleted
C:\WINDOWS\system32\finance.txt - Deleted
C:\WINDOWS\system32\lt.res - Deleted
C:\WINDOWS\system32\other.txt - Deleted
C:\WINDOWS\system32\pharma.txt - Deleted
C:\WINDOWS\system32\sft.res - Deleted
C:\WINDOWS\system32\sn.txt - Deleted
C:\WINDOWS\system32\sockins32.dll - Deleted
C:\WINDOWS\ws386.ini - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-17 15:15:15
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Foxmail\\FoxHot.exe"="C:\\Program Files\\Foxmail\\FoxHot.exe:*:Enabled:Foxmail-Hotmail Proxy Application"
"C:\\WINDOWS\\System32\\mmc.exe"="C:\\WINDOWS\\System32\\mmc.exe:*:Enabled:Microsoft Management Console"
"C:\\Program Files\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\LowRateVoip\\LowRateVoip.exe"="C:\\Program Files\\LowRateVoip\\LowRateVoip.exe:*:Enabled:LowRateVoip"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sun 18 May 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Fri 9 May 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 9 May 2008 401 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv13.bak"
Tue 6 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT4.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\585dc2612ebcefc90e7dee4c276ee95e\BIT3.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9e870549834e2bceb796e44a1e3ac6f5\BITB.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\22fb973e059470cc1b5d76c4ae605351\BITC.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT9.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT8.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT4.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\30285791903730fbf957a83562db4ff4\BIT6.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BITA.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cb8921d0c7830b2f33c00fa4c8a10d17\BIT7.tmp"
Sun 24 Feb 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT5.tmp"
Fri 9 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 9 May 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Thu 10 Apr 2008 434,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL2720.tmp"
Thu 19 May 2005 30,208 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL2284.tmp"
Thu 15 Feb 2007 1,192,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL1972.tmp"
Thu 15 Feb 2007 1,574,912 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Documents administratifs\~WRL1584.tmp"
Tue 30 Oct 2007 89,600 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL3278.tmp"
Tue 30 Oct 2007 96,768 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL0320.tmp"
Tue 30 Oct 2007 334,848 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL3180.tmp"
Tue 30 Oct 2007 416,256 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2862.tmp"
Tue 30 Oct 2007 416,768 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL1631.tmp"
Tue 30 Oct 2007 405,504 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL3036.tmp"
Tue 30 Oct 2007 322,048 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2979.tmp"
Tue 30 Oct 2007 276,992 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2318.tmp"
Tue 30 Oct 2007 264,192 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL0539.tmp"
Tue 30 Oct 2007 236,544 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Comptes\~WRL2281.tmp"
Sun 5 Aug 2007 24,576 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\d‚m‚nagement 2007 07\~WRL0130.tmp"
Sun 5 Aug 2007 24,576 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\d‚m‚nagement 2007 07\~WRL3407.tmp"
Mon 2 Apr 2007 147,456 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Anglais\~WRL2544.tmp"
Fri 18 Jan 2008 25,088 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Annonce RCI\~WRL2398.tmp"
Fri 24 Mar 2006 100,352 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Annonce RCI\~WRL2527.tmp"
Wed 3 Oct 2007 27,136 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\informatique maison\~WRL0160.tmp"
Sun 21 Oct 2007 36,864 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\La R‚union\~WRL3784.tmp"
Tue 15 Jan 2008 19,968 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\~WRL0005.tmp"
Fri 9 May 2008 401 A..H. --- "C:\Documents and Settings\Isabelle\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Fri 9 May 2008 4,348 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Tue 15 Nov 2005 400 A.SH. --- "C:\Documents and Settings\Isabelle\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Thu 29 Mar 2007 47,616 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA1 0608 Maths\~WRL2307.tmp"
Wed 11 Oct 2006 25,088 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BPREA Maths\~WRL2415.tmp"
Thu 26 Oct 2006 66,048 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BPREA Maths\~WRL3906.tmp"
Tue 9 Jan 2007 90,112 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL1984.tmp"
Tue 23 Jan 2007 93,696 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL3893.tmp"
Tue 23 Jan 2007 114,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL0387.tmp"
Tue 3 Apr 2007 104,960 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL0004.tmp"
Tue 3 Apr 2007 101,888 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL0002.tmp"
Tue 3 Apr 2007 48,128 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\en cours\~WRL2939.tmp"
Tue 29 May 2007 178,176 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0753.tmp"
Mon 4 Jun 2007 178,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3710.tmp"
Mon 4 Jun 2007 178,688 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2276.tmp"
Mon 4 Jun 2007 179,200 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3341.tmp"
Mon 4 Jun 2007 180,224 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3680.tmp"
Mon 4 Jun 2007 180,224 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3358.tmp"
Mon 4 Jun 2007 179,712 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0514.tmp"
Tue 5 Jun 2007 182,272 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2365.tmp"
Tue 5 Jun 2007 400,896 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1505.tmp"
Tue 5 Jun 2007 402,944 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2418.tmp"
Tue 5 Jun 2007 407,552 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3172.tmp"
Tue 5 Jun 2007 410,112 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3669.tmp"
Tue 5 Jun 2007 335,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3994.tmp"
Tue 5 Jun 2007 335,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0273.tmp"
Tue 5 Jun 2007 336,384 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2451.tmp"
Tue 5 Jun 2007 332,288 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2667.tmp"
Tue 28 Nov 2006 25,088 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0001.tmp"
Tue 5 Jun 2007 334,336 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0439.tmp"
Tue 5 Jun 2007 344,064 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2782.tmp"
Tue 5 Jun 2007 340,992 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1727.tmp"
Tue 5 Jun 2007 340,992 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1339.tmp"
Tue 5 Jun 2007 342,528 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0905.tmp"
Tue 5 Jun 2007 342,016 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1763.tmp"
Tue 6 Feb 2007 107,520 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2940.tmp"
Tue 27 Mar 2007 154,624 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1731.tmp"
Tue 5 Jun 2007 342,016 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1101.tmp"
Tue 5 Jun 2007 343,040 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0978.tmp"
Tue 27 Mar 2007 175,104 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2369.tmp"
Tue 5 Jun 2007 343,552 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2294.tmp"
Tue 5 Jun 2007 345,600 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3420.tmp"
Tue 5 Jun 2007 346,112 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0180.tmp"
Tue 5 Jun 2007 346,624 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2205.tmp"
Tue 5 Jun 2007 347,648 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1127.tmp"
Tue 5 Jun 2007 348,160 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3631.tmp"
Tue 5 Jun 2007 343,552 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2760.tmp"
Fri 25 May 2007 155,648 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0058.tmp"
Tue 29 May 2007 164,352 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3228.tmp"
Tue 29 May 2007 162,816 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3662.tmp"
Tue 29 May 2007 170,496 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1279.tmp"
Tue 29 May 2007 181,248 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL3086.tmp"
Tue 29 May 2007 181,248 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL2277.tmp"
Tue 28 Nov 2006 157,696 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0944.tmp"
Tue 28 Nov 2006 171,520 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1904.tmp"
Tue 28 Nov 2006 169,984 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0476.tmp"
Tue 28 Nov 2006 219,136 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1313.tmp"
Tue 28 Nov 2006 264,192 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL0570.tmp"
Tue 28 Nov 2006 267,264 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\capa 2006 2008\~WRL1839.tmp"
Thu 24 May 2007 74,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\~WRL3168.tmp"
Thu 24 May 2007 74,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\~WRL0220.tmp"
Thu 24 May 2007 76,800 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\~WRL0978.tmp"
Fri 13 Jun 2008 1,088,512 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\~WRL1103.tmp"
Tue 17 Jun 2008 2,336,768 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\~WRL0465.tmp"
Wed 12 Dec 2007 21,504 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\travail\~WRL0862.tmp"
Wed 19 Apr 2006 163,840 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0087.tmp"
Sun 23 Dec 2007 34,304 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1618.tmp"
Sun 23 Dec 2007 32,768 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1559.tmp"
Tue 13 Nov 2007 86,016 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0092.tmp"
Tue 13 Nov 2007 107,008 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL2638.tmp"
Tue 13 Nov 2007 29,696 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL2148.tmp"
Tue 28 Nov 2006 115,712 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0624.tmp"
Fri 14 Mar 2008 145,920 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1275.tmp"
Tue 28 Nov 2006 275,968 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL1124.tmp"
Mon 4 Jun 2007 392,192 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL3037.tmp"
Mon 7 Apr 2008 216,064 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL3194.tmp"
Fri 14 Mar 2008 278,528 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL3930.tmp"
Sun 16 Mar 2008 244,736 ...H. --- "C:\Documents and Settings\Isabelle\Application Data\Microsoft\Word\~WRL0988.tmp"
Thu 8 Feb 2007 143,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\ccf positionnement EM\~WRL1184.tmp"
Thu 8 Feb 2007 143,872 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 ccf INFO\ccf positionnement EM\~WRL2699.tmp"
Thu 7 Jun 2007 330,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL1884.tmp"
Thu 7 Jun 2007 330,752 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL1813.tmp"
Thu 7 Jun 2007 331,264 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL2664.tmp"
Thu 7 Jun 2007 331,776 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL3877.tmp"
Thu 7 Jun 2007 331,776 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL3641.tmp"
Thu 7 Jun 2007 331,776 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0507 info\CCF BEPA 0507 Info\~WRL2265.tmp"
Fri 28 Mar 2008 198,144 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL0238.tmp"
Fri 28 Mar 2008 40,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL3978.tmp"
Fri 28 Mar 2008 24,576 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL0208.tmp"
Fri 28 Mar 2008 24,064 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL1697.tmp"
Fri 28 Mar 2008 40,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL0297.tmp"
Fri 28 Mar 2008 122,880 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\PONEY\~WRL3820.tmp"
Sun 20 Jan 2008 57,344 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\climat r‚union\~WRL3262.tmp"
Sun 20 Jan 2008 83,968 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\climat r‚union\~WRL3340.tmp"
Sun 20 Jan 2008 88,064 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\scolaire\climat r‚union\~WRL3613.tmp"
Mon 28 Apr 2008 61,952 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL1646.tmp"
Fri 8 Jun 2007 98,816 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL4016.tmp"
Mon 28 Apr 2008 95,232 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL0288.tmp"
Mon 28 Apr 2008 95,232 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL1322.tmp"
Mon 28 Apr 2008 106,496 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL0929.tmp"
Mon 28 Apr 2008 104,960 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL2367.tmp"
Mon 28 Apr 2008 104,448 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL1010.tmp"
Mon 28 Apr 2008 121,856 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL3553.tmp"
Mon 28 Apr 2008 113,664 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\isabelle.bretagne\BEPA 0608 Info\CCF\CCF lac 0608\~WRL3277.tmp"
Thu 6 Mar 2008 517,632 ...H. --- "C:\Documents and Settings\Isabelle\Mes documents\Maison 2007 2008\extrascolaire\voile\modŠles fiches cnsp\~WRL0010.tmp"
[b]Finished![/b]
Isabelle
je reviens dans 1/2 h ... enfants à aller chercher à l'école ... puis je profiter de cette 1/2 h pour faire un scan .??? ou on reprends quand je reviens ?
Isabelle
Isabelle
SmitFraudFix v2.325
Rapport fait à 15:28:39,30, 17/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Power Management\PwrGui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\DOWNLOAD\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ISABELLE\FAVORIS
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Carte Fast Ethernet PCI de base SiS 900 #2 - Miniport d'ordonnancement de paquets
DNS Server Search Order: 195.115.116.10
Description: Carte réseau Belkin 802.11g - Miniport d'ordonnancement de paquets
DNS Server Search Order: 195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Isabelle
Rapport fait à 15:28:39,30, 17/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Power Management\PwrGui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\DOWNLOAD\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ISABELLE\FAVORIS
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Carte Fast Ethernet PCI de base SiS 900 #2 - Miniport d'ordonnancement de paquets
DNS Server Search Order: 195.115.116.10
Description: Carte réseau Belkin 802.11g - Miniport d'ordonnancement de paquets
DNS Server Search Order: 195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Isabelle
peux tu me poster un nouveau rapport hijack en attendant que mbam finisse et que tu ailles chercher tes enfants ?
EDIT ok file chercher tes enfants !!!! :)
EDIT ok file chercher tes enfants !!!! :)
de retour ... mais MBAM tourne toujours (22 min) ... si il met autant de temps que la derniere fois (plus de 2h) j'ai le temps de prendre un bon gouter ! (ne vous étonnez pas pour l'heure ... je suis en avance de 2h sur vous puisqu'on habite la réunion !)
Isabelle
Isabelle
--
mbam a fini : voila le rapport
Malwarebytes' Anti-Malware 1.17
Version de la base de données: 862
16:06:57 17/06/2008
mbam-log-6-17-2008 (16-06-51).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 116825
Temps écoulé: 29 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{66186f05-bbbb-4a39-864f-72d84615c679} (Trojan.Agent) -> No action taken.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\System Volume Information\_restore{DE97CFA9-2BAA-4A60-B76D-83C2BFF40D28}\RP830\A0397968.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{DE97CFA9-2BAA-4A60-B76D-83C2BFF40D28}\RP830\A0397974.dll (Trojan.BHO) -> No action taken.
Isabelle
mbam a fini : voila le rapport
Malwarebytes' Anti-Malware 1.17
Version de la base de données: 862
16:06:57 17/06/2008
mbam-log-6-17-2008 (16-06-51).txt
Type de recherche: Examen complet (C:\|D:\|E:\|)
Eléments examinés: 116825
Temps écoulé: 29 minute(s), 15 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{66186f05-bbbb-4a39-864f-72d84615c679} (Trojan.Agent) -> No action taken.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\System Volume Information\_restore{DE97CFA9-2BAA-4A60-B76D-83C2BFF40D28}\RP830\A0397968.dll (Trojan.BHO) -> No action taken.
C:\System Volume Information\_restore{DE97CFA9-2BAA-4A60-B76D-83C2BFF40D28}\RP830\A0397974.dll (Trojan.BHO) -> No action taken.
Isabelle
et hijack (je ne l'ai pas fait en mode sans échec ? il fallait ?)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:13:25, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Power Management\PwrGui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: (no name) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - (no file)
O4 - HKLM\..\Run: [PowerManagement] C:\Program Files\Power Management\PwrGui.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [DVDBitSet] C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe /NOUI
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ne m'oublie pas !.lnk = C:\Program Files\MicroApp\Cartes d'Anniversaire\REMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {3015DB92-158E-4b77-9020-85C8E311FBB5} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (PIXACO Drag and Drop upload plugin) - https://www.snapfish.fr/2/home
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} (telechargement-photoweb) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.pixdiscount.fr/clients/uploader_v2.1.0.56.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer = 195.115.116.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer = 195.115.116.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:13:25, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Power Management\PwrGui.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP DVD\Umbrella\DVDTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: (no name) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - (no file)
O4 - HKLM\..\Run: [PowerManagement] C:\Program Files\Power Management\PwrGui.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [DVDBitSet] C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe /NOUI
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ne m'oublie pas !.lnk = C:\Program Files\MicroApp\Cartes d'Anniversaire\REMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {3015DB92-158E-4b77-9020-85C8E311FBB5} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (PIXACO Drag and Drop upload plugin) - https://www.snapfish.fr/2/home
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} (telechargement-photoweb) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.pixdiscount.fr/clients/uploader_v2.1.0.56.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer = 195.115.116.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer = 195.115.116.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
j'ai refait les scan en mode sans échec ... si ça peut servir
SmitFraudFix v2.325
Rapport fait à 16:28:10,50, 17/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\DOWNLOAD\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ISABELLE\FAVORIS
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:33:08, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: (no name) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - (no file)
O4 - HKLM\..\Run: [PowerManagement] C:\Program Files\Power Management\PwrGui.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [DVDBitSet] C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe /NOUI
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ne m'oublie pas !.lnk = C:\Program Files\MicroApp\Cartes d'Anniversaire\REMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {3015DB92-158E-4b77-9020-85C8E311FBB5} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (PIXACO Drag and Drop upload plugin) - https://www.snapfish.fr/2/home
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} (telechargement-photoweb) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.pixdiscount.fr/clients/uploader_v2.1.0.56.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer = 195.115.116.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer = 195.115.116.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
SmitFraudFix v2.325
Rapport fait à 16:28:10,50, 17/06/2008
Executé à partir de C:\DOWNLOAD\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est FAT32
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\DOWNLOAD\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Isabelle\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ISABELLE\FAVORIS
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS1\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer=195.115.116.10
HKLM\SYSTEM\CS3\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer=195.115.116.10
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:33:08, on 17/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: (no name) - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - (no file)
O4 - HKLM\..\Run: [PowerManagement] C:\Program Files\Power Management\PwrGui.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\Generic\USB Card Reader Driver v1.9\Disk_Monitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [wltray.exe] C:\WINDOWS\system32\wltray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [DVDTray] C:\Program Files\HP DVD\Umbrella\DVDTray.exe
O4 - HKLM\..\Run: [DVDBitSet] C:\Program Files\HP DVD\Umbrella\DVDBitSet.exe /NOUI
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Ne m'oublie pas !.lnk = C:\Program Files\MicroApp\Cartes d'Anniversaire\REMIND.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {3015DB92-158E-4b77-9020-85C8E311FBB5} - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} (PIXACO Drag and Drop upload plugin) - https://www.snapfish.fr/2/home
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} (telechargement-photoweb) - http://www4.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.pixdiscount.fr/clients/uploader_v2.1.0.56.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin3.valueactive.com/Register/Branding/olr3313/OCX/flashax.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{87C67166-9726-4F9B-91BA-5CAC9E94BFF0}: NameServer = 195.115.116.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5BEB46B-78E6-4EA2-BED1-6F5211FE84DC}: NameServer = 195.115.116.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe