J'ai des spams sans arrets

Résolu
norbij Messages postés 6 Statut Membre -  
ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour A tous,

J"ai un gros probleme...

EN effet, j'ai des spams sans arrets avec les pages qui s'ouvrent sur ces sites :

-hebrewonline.com
-winspyprotect.com
-hotbar.com
-snorgtees.com
-onlinecashmethod.com
-battleknight.fr
-scratchz.com

J'ai essaye AD-AWARE en mode sans échec, il trouve bien des infections mais au démarrage, ca revient...

Sinon, en mode normal, j'ai mis AD-AWARE en sous traitance qui bloque automatiquement... avec ce message, si ca peut vous aider :

THE PROCESS "EXPLORER.EXE" (3640) IS TRYING TO MODIFY (VALUE CHANGE OR ADD) THE REGISTRY
PATH : HKEY_CURRENT_USER SOFTWARE\MICROSOFT\INTERNET\EXPLORER\MAIN

Merci de votre aide et de votre marche à suivre (détaillé svp car je suis un peu paumé...)
Configuration: Windows XP
Firefox 3.0.1

44 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Un problème de spams et de redirections vers des sites indésirables se manifeste sur une configuration Windows XP avec Firefox, malgré une détection par Ad-Aware et des infections revenant au démarrage. Des conseils alternent entre HijackThis, Malwarebytes et ComboFix, l'accent étant mis sur des rapports détaillés et des mesures comme déconnecter Internet et désactiver temporairement les protections. Des instructions pas à pas pour ComboFix sont ensuite proposées, incluant la création d'un point de restauration et la génération d'un rapport; certains répondants soulignent que Malwarebytes n'a rien détecté. En complément, des éléments trouvés dans les journaux et les sections de démarrage évoquent des fichiers et scripts malveillants (X8ic4785.exe, 3W71kaDs.exe) et des tâches planifiées, indicateurs d'une infection étendue.

Bobot (l'IA à votre service)
  1. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir

    Commence par ceci

    Télécharge sur le Bureau HijackThis

    http://download.hijackthis.eu/HJTInstall.exe

    = Double-clique sur dessus pour l'installer
    = Clique sur Do a system scan and save the log
    = Colle le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    0
  2. norbij Messages postés 6 Statut Membre
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:17:03, on 22/07/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
    C:\Program Files\Cyberlink\Shared Files\brs.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\NetDrive\wdService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\X8ic4785.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\eMule\eMule.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\Documents and Settings\Julien\Bureau\HJT.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
    O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
    O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
    O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 11.0.0.1217 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [WUAppSetup] C:\Program Files\Fichiers communs\logishrd\WUApp32.exe -v 0x046d -p 0x08c1 -f video -m logitech -d 11.0.0.1217 (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\logishrd\Bluetooth\LBTServ.exe
    O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
    O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
    0
  3. norbij Messages postés 6 Statut Membre
     
    PERSONNE POUR M"AIDER ???
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. Cisco
     
    Regarde plus haut, je t'ai proposé d'utiliser un logiciel.
    0
  6. norbij Messages postés 6 Statut Membre
     
    OK JE FAIS CA TOUT DE SUITE
    0
  7. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    OK
    pour la suite

    Télécharge Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    et sauvegarde le sur ton bureau et pas ailleurs!

    => /!\déconnecte toi d'internet et ferme toutes tes applications./!\

    =>/!\ désactive tes protections (antivirus, parefeu,antispyware) provisoirement et seulement le temps de l'utilisation de ComboFix,/!\

    => Double-clic sur combofix,

    => /!\Ne touche à rien tant que le scan n'est pas terminé.Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi./!\

    => Attends que combofix ait terminé, un rapport sera créé.

    => réactive ton parefeu, ton antivirus, la garde de ton antispyware

    => copie/colle le rapport C:\ComboFix.txt

    => Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    0
  8. norbij
     
    ComboFix 08-07-21.2 - Julien 2008-07-22 23:03:26.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.465 [GMT 2:00]
    Endroit: C:\Documents and Settings\Julien\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Julien\Application Data\inst.exe

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-06-22 to 2008-07-22 ))))))))))))))))))))))))))))))))))))
    .

    2008-07-22 23:00 . 2008-07-16 23:27 0 --a------ C:\WINDOWS\system32\X8ic4785.exe.a_a
    2008-07-22 23:00 . 2008-07-14 22:27 0 --a------ C:\WINDOWS\system32\3W71kaDs.exe.a_a
    2008-07-22 22:39 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-07-22 22:38 . 2008-07-22 22:39 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-22 22:38 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-22 21:16 . 2008-07-22 21:16 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\vlc
    2008-07-22 21:10 . 2008-07-22 21:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Media Player Classic
    2008-07-22 21:10 . 2008-07-22 21:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\DivX
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-07-22 21:06 . 2007-12-15 14:31 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
    2008-07-22 21:06 . 2007-12-15 14:34 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
    2008-07-22 21:06 . 2007-12-15 14:36 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
    2008-07-22 21:06 . 2008-07-22 21:06 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-07-22 00:01 . 2008-07-22 00:01 <REP> d-------- C:\Program Files\Lavasoft
    2008-07-21 23:56 . 2008-07-21 23:56 <REP> d-------- C:\WINDOWS\[u]0[/u]E6AB9FC76C2431B9C066C1CFFFEA8EB.TMP
    2008-07-21 22:50 . 2008-07-22 00:00 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-07-21 21:00 . 2008-07-21 21:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
    2008-07-21 20:59 . 2008-07-21 20:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
    2008-07-20 02:50 . 2008-07-20 02:50 <REP> d-------- C:\Program Files\Fichiers communs\CyberLink
    2008-07-20 02:48 . 2008-07-20 02:45 29,480 --a------ C:\WINDOWS\system32\msxml3a.dll
    2008-07-20 02:42 . 2008-07-20 02:43 <REP> d-------- C:\Documents and Settings\Julien\Application Data\CyberLink
    2008-07-20 02:37 . 2008-07-20 02:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
    2008-07-20 02:35 . 2008-07-20 02:37 <REP> d-------- C:\Program Files\CyberLink
    2008-07-20 00:59 . 2008-07-22 21:46 88,723 --a------ C:\WINDOWS\system32\nvapps.xml
    2008-07-20 00:58 . 2008-07-20 10:37 <REP> d-------- C:\WINDOWS\nview
    2008-07-20 00:16 . 2008-05-19 18:16 186,407 --a------ C:\WINDOWS\system32\nvapps.nvb
    2008-07-20 00:13 . 2008-07-20 00:51 <REP> d-------- C:\NVIDIA
    2008-07-19 00:26 . 2008-07-19 00:26 <REP> d-------- C:\Documents and Settings\Julien\Application Data\Malwarebytes
    2008-07-19 00:26 . 2008-07-19 00:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-18 21:15 . 2008-07-22 19:51 35,842 --a------ C:\WINDOWS\system32\X8ic4785.exe_
    2008-07-18 21:15 . 2008-07-22 22:02 35,842 --a------ C:\WINDOWS\system32\X8ic4785.exe
    2008-07-18 13:14 . 2008-07-22 22:02 20,480 --a------ C:\WINDOWS\system32\T8ex4785.dll
    2008-07-18 00:19 . 2008-07-18 00:19 <REP> dr------- C:\Documents and Settings\NetworkService\Favoris
    2008-07-14 22:27 . 2008-07-14 22:26 29,760 --a------ C:\WINDOWS\system32\3W71kaDs.exe
    2008-06-28 11:41 . 2008-06-28 11:42 <REP> d-------- C:\Documents and Settings\Julien\Application Data\albumart
    2008-06-27 18:44 . 2008-06-27 18:44 <REP> d-------- C:\Program Files\Microsoft ActiveSync
    2008-06-24 22:00 . 2008-07-01 20:10 <REP> d-------- C:\Program Files\Windows Live Safety Center

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-07-22 19:00 --------- d-----w C:\Documents and Settings\Julien\Application Data\uTorrent
    2008-07-21 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-07-20 14:30 --------- d-----w C:\Program Files\Java
    2008-07-20 00:45 505,128 ----a-w C:\WINDOWS\system32\msvcp71.dll
    2008-07-20 00:45 353,576 ----a-w C:\WINDOWS\system32\msvcr71.dll
    2008-07-18 19:01 --------- d-----w C:\Program Files\eMule
    2008-07-13 09:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-06-26 20:06 --------- d-----w C:\Program Files\DivX
    2008-06-24 19:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-06-20 22:16 --------- d-----w C:\Program Files\So Blonde Demo
    2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-18 16:52 --------- d-----w C:\Program Files\Firefox
    2008-06-17 11:00 0 ----a-w C:\WINDOWS\system32\drivers\lvuvc.hs
    2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-13 18:21 --------- d-----w C:\Program Files\mp3DirectCut
    2008-06-12 22:29 --------- d-----w C:\Program Files\TagRename
    2008-06-12 18:17 --------- d-----w C:\Documents and Settings\Julien\Application Data\SoundSpectrum
    2008-06-12 18:15 --------- d-----w C:\Program Files\SoundSpectrum
    2008-06-12 18:12 --------- d-----w C:\Program Files\Tag Support Plugin for Media Player
    2008-06-08 12:57 --------- d-----w C:\Program Files\Yahoo!
    2008-06-08 12:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\YAHOO
    2008-06-08 09:54 --------- d-----w C:\Program Files\Fichiers communs\Ahead
    2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
    2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
    2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
    2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
    2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
    2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
    2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
    2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
    2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
    2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
    2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
    2008-05-22 22:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
    2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
    2008-05-22 22:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
    2008-05-22 22:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
    2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
    2008-05-22 22:19 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
    2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
    2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
    2008-05-16 12:01 446,464 ----a-w C:\WINDOWS\system32\nvudisp.exe
    2008-05-16 12:01 1,241,088 ----a-w C:\WINDOWS\system32\nvcuda.dll
    2008-05-16 09:48 446,464 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
    2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
    2008-04-28 17:28 47,360 ----a-w C:\Documents and Settings\Julien\Application Data\pcouffin.sys
    2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-03-30 10:37 596 ----a-w C:\Program Files\mpc1.reg
    2008-03-30 10:37 49,114 ----a-w C:\Program Files\ffdssetts.reg
    2008-03-30 10:37 4,635 ----a-w C:\Program Files\satsukidecodersettings.ini
    2008-03-30 10:37 31,754 ----a-w C:\Program Files\ffdsvsetts.reg
    2008-03-30 10:37 3,476 ----a-w C:\Program Files\mpc7.reg
    2008-03-30 10:37 3,026 ----a-w C:\Program Files\mpc3.reg
    2008-03-30 10:37 23,436 ----a-w C:\Program Files\ffdsasetts.reg
    2008-03-30 10:37 18,156 ----a-w C:\Program Files\mpc6.reg
    2008-03-30 10:37 16,150 ----a-w C:\Program Files\mpc5.reg
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
    "HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 12:24 49152]
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 16:18 241664]
    "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-11-08 02:56 188416]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 10:11 925696]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
    "TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-10-31 11:19 378784]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 13:26 7700480]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 13:26 86016]
    "RemoteControl8"="C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 20:23 83240]
    "PDVD8LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]
    "BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2008-05-19 15:24 91432]
    "AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53 88024]
    "Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2007-08-28 19:03 4579328]
    "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 16:21 61952 C:\WINDOWS\system32\HdAShCut.exe]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 17:10 110592 C:\WINDOWS\system32\bthprops.cpl]
    "nwiz"="nwiz.exe" [2007-04-19 13:26 1626112 C:\WINDOWS\system32\nwiz.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "WUAppSetup"="C:\Program Files\Fichiers communs\logishrd\WUApp32.exe" [2007-05-11 18:24 441120]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{650CA63D-4A01-4BF8-A608-9B1EBB36292E}"= "C:\WINDOWS\system32\T8ex4785.dll" [2008-07-22 22:02 20480]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2007-11-15 11:10 72208 c:\Program Files\Fichiers communs\logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\WINDOWS\\system32\\mshta.exe"=
    "C:\\Program Files\\eMule\\eMule.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl [2008-05-15 12:07]
    R2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys [2002-11-27 14:40]
    R3 Cap7134;ProVideo Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-03-24 19:35]
    R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\mbamswissarmy.sys [2008-07-20 20:21]
    R3 PhTVTune;ProVideo WDM TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-03-24 21:21]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52baa29c-c66e-11dc-b70a-00173177a6d9}]
    \Shell\Auto\command - cmd /C launch.bat
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{939167b2-cce8-11dc-b717-00173177a6d9}]
    \Shell\AutoRun\command - K:\InstallTomTomHOME.exe

    *Newly Created Service* - CATCHME
    *Newly Created Service* - MBAMSWISSARMY
    *Newly Created Service* - PROCEXP90
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2008-07-19 22:58:02 C:\WINDOWS\Tasks\At1.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-15 07:00:01 C:\WINDOWS\Tasks\At10.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-14 20:27:26 C:\WINDOWS\Tasks\At11.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-20 09:00:01 C:\WINDOWS\Tasks\At12.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-20 10:00:01 C:\WINDOWS\Tasks\At13.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-21 11:00:01 C:\WINDOWS\Tasks\At14.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 12:00:02 C:\WINDOWS\Tasks\At15.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 13:00:02 C:\WINDOWS\Tasks\At16.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 14:00:02 C:\WINDOWS\Tasks\At17.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 15:00:02 C:\WINDOWS\Tasks\At18.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 16:00:02 C:\WINDOWS\Tasks\At19.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-19 23:00:01 C:\WINDOWS\Tasks\At2.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 17:00:02 C:\WINDOWS\Tasks\At20.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 18:00:02 C:\WINDOWS\Tasks\At21.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 19:00:02 C:\WINDOWS\Tasks\At22.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 20:00:02 C:\WINDOWS\Tasks\At23.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 21:00:03 C:\WINDOWS\Tasks\At24.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-21 22:19:10 C:\WINDOWS\Tasks\At25.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 08:37:14 C:\WINDOWS\Tasks\At26.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 00:00:10 C:\WINDOWS\Tasks\At27.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 01:00:11 C:\WINDOWS\Tasks\At28.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 02:00:10 C:\WINDOWS\Tasks\At29.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 00:00:01 C:\WINDOWS\Tasks\At3.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 03:00:10 C:\WINDOWS\Tasks\At30.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 04:00:10 C:\WINDOWS\Tasks\At31.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 05:00:10 C:\WINDOWS\Tasks\At32.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 06:00:10 C:\WINDOWS\Tasks\At33.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-16 19:27:20 C:\WINDOWS\Tasks\At34.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-16 19:27:20 C:\WINDOWS\Tasks\At35.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-21 10:46:54 C:\WINDOWS\Tasks\At36.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 10:00:10 C:\WINDOWS\Tasks\At37.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-21 11:00:10 C:\WINDOWS\Tasks\At38.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 12:00:10 C:\WINDOWS\Tasks\At39.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 01:00:07 C:\WINDOWS\Tasks\At4.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 13:00:10 C:\WINDOWS\Tasks\At40.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 14:00:10 C:\WINDOWS\Tasks\At41.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 15:00:10 C:\WINDOWS\Tasks\At42.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 16:00:10 C:\WINDOWS\Tasks\At43.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 17:00:10 C:\WINDOWS\Tasks\At44.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 18:00:10 C:\WINDOWS\Tasks\At45.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 19:00:10 C:\WINDOWS\Tasks\At46.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 20:00:10 C:\WINDOWS\Tasks\At47.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 21:00:11 C:\WINDOWS\Tasks\At48.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 02:00:01 C:\WINDOWS\Tasks\At5.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 03:00:01 C:\WINDOWS\Tasks\At6.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 04:00:01 C:\WINDOWS\Tasks\At7.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 05:00:01 C:\WINDOWS\Tasks\At8.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 06:00:01 C:\WINDOWS\Tasks\At9.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    .
    .
    ------- Supplementary Scan -------
    .
    R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
    R1 -: HKCU-Internet Settings,ProxyOverride = *.local
    O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-22 23:08:56
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ad-Watch Real-Time Scanner]
    "ImagePath"="\??\C:\WINDOWS\system32\drivers\AWRTPD.sys"

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Ad-Watch Registry Filter]
    "ImagePath"="\??\C:\WINDOWS\system32\drivers\AWRTRD.sys"

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
    "ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl"
    .
    Temps d'accomplissement: 2008-07-22 23:11:01
    ComboFix-quarantined-files.txt 2008-07-22 21:10:53

    Pre-Run: 83,471,790,080 octets libres
    Post-Run: 83,585,626,112 octets libres

    305 --- E O F --- 2008-07-13 09:34:14
    0
  9. norbij
     
    POUR INFO: MALWAREBYTES N'A RIEN DETECTE !!!
    0
  10. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    J'analyse ton rapport et j'attends une confirmation car j'ai un doute
    a toutes à l'heure ;)
    0
  11. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    OKi c'est partit ;)

    selectionne ceci

    registry::

    File::
    C:\WINDOWS\system32\X8ic4785.exe.a_a
    C:\WINDOWS\system32\3W71kaDs.exe.a_a
    C:\WINDOWS\[u]0/uE6AB9FC76C2431B­9C066C1CFFFEA8EB.TMP
    C:\WINDOWS\system32\X8ic4785.exe_
    C:\WINDOWS\system32\X8ic4785.exe
    C:\WINDOWS\system32\T8ex4785.dll
    C:\WINDOWS\system32\3W71kaDs.exe
    C:\WINDOWS\system32\drivers\lvuvc.hs

    * Copie le texte sélectionné (CTRL+C).
    * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
    * Veille à ce que Retour à la ligne ne soit pas coché dans Format.
    * Colle le texte copié dans ce bloc-notes (CTRL+V).
    * Sauvegarde ce fichier sous le nom de CFScript.txt
    * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme ceci
    http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
    * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
    * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
    Ne touche à rien tant que le scan n'est pas terminé.
    * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
    * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

    Note: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
    si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

    @+
    0
  12. norbij
     
    ComboFix 08-07-21.2 - Julien 2008-07-23 13:31:36.2 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.531 [GMT 2:00]
    Endroit: C:\Documents and Settings\Julien\Bureau\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Julien\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

    FILE ::
    C:\WINDOWS\[u]0/uE6AB9FC76C2431B­9C066C1CFFFEA8EB.TMP
    C:\WINDOWS\system32\3W71kaDs.exe
    C:\WINDOWS\system32\3W71kaDs.exe.a_a
    C:\WINDOWS\system32\drivers\lvuvc.hs
    C:\WINDOWS\system32\T8ex4785.dll
    C:\WINDOWS\system32\X8ic4785.exe
    C:\WINDOWS\system32\X8ic4785.exe.a_a
    C:\WINDOWS\system32\X8ic4785.exe_
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\3W71kaDs.exe
    C:\WINDOWS\system32\3W71kaDs.exe.a_a
    C:\WINDOWS\system32\drivers\lvuvc.hs
    C:\WINDOWS\system32\T8ex4785.dll
    C:\WINDOWS\system32\X8ic4785.exe
    C:\WINDOWS\system32\X8ic4785.exe.a_a

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-06-23 to 2008-07-23 ))))))))))))))))))))))))))))))))))))
    .

    2008-07-22 22:39 . 2008-07-20 20:21 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-07-22 22:38 . 2008-07-22 22:39 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-22 22:38 . 2008-07-20 20:21 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-22 21:16 . 2008-07-22 21:16 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\vlc
    2008-07-22 21:10 . 2008-07-22 21:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Media Player Classic
    2008-07-22 21:10 . 2008-07-22 21:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\DivX
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-07-22 21:06 . 2007-12-15 14:31 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
    2008-07-22 21:06 . 2007-12-15 14:34 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
    2008-07-22 21:06 . 2007-12-15 14:26 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
    2008-07-22 21:06 . 2007-12-15 14:36 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
    2008-07-22 21:06 . 2008-07-22 21:06 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-07-22 00:01 . 2008-07-22 00:01 <REP> d-------- C:\Program Files\Lavasoft
    2008-07-21 23:56 . 2008-07-21 23:56 <REP> d-------- C:\WINDOWS\[u]0[/u]E6AB9FC76C2431B9C066C1CFFFEA8EB.TMP
    2008-07-21 22:50 . 2008-07-22 00:00 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
    2008-07-21 21:00 . 2008-07-21 21:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
    2008-07-21 20:59 . 2008-07-21 20:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NVIDIA
    2008-07-20 02:50 . 2008-07-20 02:50 <REP> d-------- C:\Program Files\Fichiers communs\CyberLink
    2008-07-20 02:48 . 2008-07-20 02:45 29,480 --a------ C:\WINDOWS\system32\msxml3a.dll
    2008-07-20 02:42 . 2008-07-20 02:43 <REP> d-------- C:\Documents and Settings\Julien\Application Data\CyberLink
    2008-07-20 02:37 . 2008-07-20 02:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
    2008-07-20 02:35 . 2008-07-20 02:37 <REP> d-------- C:\Program Files\CyberLink
    2008-07-20 00:59 . 2008-07-23 13:28 88,723 --a------ C:\WINDOWS\system32\nvapps.xml
    2008-07-20 00:58 . 2008-07-20 10:37 <REP> d-------- C:\WINDOWS\nview
    2008-07-20 00:16 . 2008-05-19 18:16 186,407 --a------ C:\WINDOWS\system32\nvapps.nvb
    2008-07-20 00:13 . 2008-07-20 00:51 <REP> d-------- C:\NVIDIA
    2008-07-19 00:26 . 2008-07-19 00:26 <REP> d-------- C:\Documents and Settings\Julien\Application Data\Malwarebytes
    2008-07-19 00:26 . 2008-07-19 00:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-18 00:19 . 2008-07-18 00:19 <REP> dr------- C:\Documents and Settings\NetworkService\Favoris
    2008-06-28 11:41 . 2008-06-28 11:42 <REP> d-------- C:\Documents and Settings\Julien\Application Data\albumart
    2008-06-27 18:44 . 2008-06-27 18:44 <REP> d-------- C:\Program Files\Microsoft ActiveSync
    2008-06-24 22:00 . 2008-07-01 20:10 <REP> d-------- C:\Program Files\Windows Live Safety Center

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-07-22 19:00 --------- d-----w C:\Documents and Settings\Julien\Application Data\uTorrent
    2008-07-21 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-07-20 14:30 --------- d-----w C:\Program Files\Java
    2008-07-20 00:45 505,128 ----a-w C:\WINDOWS\system32\msvcp71.dll
    2008-07-20 00:45 353,576 ----a-w C:\WINDOWS\system32\msvcr71.dll
    2008-07-18 19:01 --------- d-----w C:\Program Files\eMule
    2008-07-13 09:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-06-26 20:06 --------- d-----w C:\Program Files\DivX
    2008-06-24 19:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-06-20 22:16 --------- d-----w C:\Program Files\So Blonde Demo
    2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-18 16:52 --------- d-----w C:\Program Files\Firefox
    2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-13 18:21 --------- d-----w C:\Program Files\mp3DirectCut
    2008-06-12 22:29 --------- d-----w C:\Program Files\TagRename
    2008-06-12 18:17 --------- d-----w C:\Documents and Settings\Julien\Application Data\SoundSpectrum
    2008-06-12 18:15 --------- d-----w C:\Program Files\SoundSpectrum
    2008-06-12 18:12 --------- d-----w C:\Program Files\Tag Support Plugin for Media Player
    2008-06-08 12:57 --------- d-----w C:\Program Files\Yahoo!
    2008-06-08 12:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\YAHOO
    2008-06-08 09:54 --------- d-----w C:\Program Files\Fichiers communs\Ahead
    2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
    2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
    2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
    2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
    2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
    2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
    2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
    2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
    2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
    2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
    2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
    2008-05-22 22:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
    2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
    2008-05-22 22:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
    2008-05-22 22:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
    2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
    2008-05-22 22:19 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
    2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
    2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
    2008-05-16 12:01 446,464 ----a-w C:\WINDOWS\system32\nvudisp.exe
    2008-05-16 12:01 1,241,088 ----a-w C:\WINDOWS\system32\nvcuda.dll
    2008-05-16 09:48 446,464 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
    2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
    2008-04-28 17:28 47,360 ----a-w C:\Documents and Settings\Julien\Application Data\pcouffin.sys
    2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
    2008-03-30 10:37 596 ----a-w C:\Program Files\mpc1.reg
    2008-03-30 10:37 49,114 ----a-w C:\Program Files\ffdssetts.reg
    2008-03-30 10:37 4,635 ----a-w C:\Program Files\satsukidecodersettings.ini
    2008-03-30 10:37 31,754 ----a-w C:\Program Files\ffdsvsetts.reg
    2008-03-30 10:37 3,476 ----a-w C:\Program Files\mpc7.reg
    2008-03-30 10:37 3,026 ----a-w C:\Program Files\mpc3.reg
    2008-03-30 10:37 23,436 ----a-w C:\Program Files\ffdsasetts.reg
    2008-03-30 10:37 18,156 ----a-w C:\Program Files\mpc6.reg
    2008-03-30 10:37 16,150 ----a-w C:\Program Files\mpc5.reg
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
    "HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 12:24 49152]
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 16:18 241664]
    "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-11-08 02:56 188416]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 10:11 925696]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
    "TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-10-31 11:19 378784]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 13:26 7700480]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 13:26 86016]
    "RemoteControl8"="C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 20:23 83240]
    "PDVD8LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 11:36 50472]
    "BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2008-05-19 15:24 91432]
    "AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53 88024]
    "Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2007-08-28 19:03 4579328]
    "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 16:21 61952 C:\WINDOWS\system32\HdAShCut.exe]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 17:10 110592 C:\WINDOWS\system32\bthprops.cpl]
    "nwiz"="nwiz.exe" [2007-04-19 13:26 1626112 C:\WINDOWS\system32\nwiz.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "WUAppSetup"="C:\Program Files\Fichiers communs\logishrd\WUApp32.exe" [2007-05-11 18:24 441120]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
    2007-11-15 11:10 72208 c:\Program Files\Fichiers communs\logishrd\Bluetooth\LBTWLgn.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\WINDOWS\\system32\\mshta.exe"=
    "C:\\Program Files\\eMule\\eMule.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl [2008-05-15 12:07]
    R2 WebDriveFSD;WebDrive File System Driver;C:\Program Files\NetDrive\rffsd.sys [2002-11-27 14:40]
    R3 Cap7134;ProVideo Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2004-03-24 19:35]
    R3 PhTVTune;ProVideo WDM TVTuner;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2004-03-24 21:21]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52baa29c-c66e-11dc-b70a-00173177a6d9}]
    \Shell\Auto\command - cmd /C launch.bat
    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{939167b2-cce8-11dc-b717-00173177a6d9}]
    \Shell\AutoRun\command - K:\InstallTomTomHOME.exe

    *Newly Created Service* - AD-WATCH_REGISTRY_FILTER
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2008-07-19 22:58:02 C:\WINDOWS\Tasks\At1.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-15 07:00:01 C:\WINDOWS\Tasks\At10.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-14 20:27:26 C:\WINDOWS\Tasks\At11.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-20 09:00:01 C:\WINDOWS\Tasks\At12.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-20 10:00:01 C:\WINDOWS\Tasks\At13.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-21 11:00:01 C:\WINDOWS\Tasks\At14.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 12:00:02 C:\WINDOWS\Tasks\At15.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 13:00:02 C:\WINDOWS\Tasks\At16.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 14:00:02 C:\WINDOWS\Tasks\At17.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 15:00:02 C:\WINDOWS\Tasks\At18.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 16:00:02 C:\WINDOWS\Tasks\At19.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-19 23:00:01 C:\WINDOWS\Tasks\At2.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 17:00:02 C:\WINDOWS\Tasks\At20.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 18:00:02 C:\WINDOWS\Tasks\At21.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 19:00:02 C:\WINDOWS\Tasks\At22.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 20:00:02 C:\WINDOWS\Tasks\At23.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 21:00:03 C:\WINDOWS\Tasks\At24.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-21 22:19:10 C:\WINDOWS\Tasks\At25.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 08:37:14 C:\WINDOWS\Tasks\At26.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 00:00:10 C:\WINDOWS\Tasks\At27.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 01:00:11 C:\WINDOWS\Tasks\At28.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 02:00:10 C:\WINDOWS\Tasks\At29.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 00:00:01 C:\WINDOWS\Tasks\At3.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 03:00:10 C:\WINDOWS\Tasks\At30.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 04:00:10 C:\WINDOWS\Tasks\At31.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 05:00:10 C:\WINDOWS\Tasks\At32.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 06:00:10 C:\WINDOWS\Tasks\At33.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-16 19:27:20 C:\WINDOWS\Tasks\At34.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-16 19:27:20 C:\WINDOWS\Tasks\At35.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-21 10:46:54 C:\WINDOWS\Tasks\At36.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 10:00:10 C:\WINDOWS\Tasks\At37.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-21 11:00:10 C:\WINDOWS\Tasks\At38.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 12:00:10 C:\WINDOWS\Tasks\At39.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-20 01:00:07 C:\WINDOWS\Tasks\At4.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-22 13:00:10 C:\WINDOWS\Tasks\At40.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 14:00:10 C:\WINDOWS\Tasks\At41.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 15:00:10 C:\WINDOWS\Tasks\At42.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 16:00:10 C:\WINDOWS\Tasks\At43.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 17:00:10 C:\WINDOWS\Tasks\At44.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 18:00:10 C:\WINDOWS\Tasks\At45.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 19:00:10 C:\WINDOWS\Tasks\At46.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 20:00:10 C:\WINDOWS\Tasks\At47.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-22 21:00:11 C:\WINDOWS\Tasks\At48.job"
    - C:\WINDOWS\system32\X8ic4785.exe
    "2008-07-17 02:00:01 C:\WINDOWS\Tasks\At5.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 03:00:01 C:\WINDOWS\Tasks\At6.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 04:00:01 C:\WINDOWS\Tasks\At7.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 05:00:01 C:\WINDOWS\Tasks\At8.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    "2008-07-17 06:00:01 C:\WINDOWS\Tasks\At9.job"
    - C:\WINDOWS\system32\3W71kaDs.exe
    .
    - - - - ORPHANS REMOVED - - - -

    ShellExecuteHooks-{650CA63D-4A01-4BF8-A608-9B1EBB36292E} - C:\WINDOWS\system32\T8ex4785.dll

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-23 13:34:24
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
    "ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD8\[u]0[/u]00.fcl"
    .
    Temps d'accomplissement: 2008-07-23 13:35:44
    ComboFix-quarantined-files.txt 2008-07-23 11:35:32
    ComboFix2.txt 2008-07-22 21:11:02

    Pre-Run: 83,565,625,344 octets libres
    Post-Run: 83,572,412,416 octets libres

    304 --- E O F --- 2008-07-13 09:34:14
    0
  13. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir

    Désolé ABS toutes la journée

    Pour la suite
    rend toi ici C:\WINDOWS\Tasks\
    et supprime tout les At...job" que tu vois

    les points remplace le chiffre tu dois en trouver pas mal c'est pour cela que j'ai mis les points pour éviter de tous les énumérer

    @+
    0
  14. norbij
     
    Bonsoir,

    j'ai fait ce que vous m'avez dit mais je pense pas que cela va enlever mon probleme de SPAMS ???

    Merci.
    0
  15. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    alors des spams..

    Tout dépend ce que tu as fait avec ton adresse mail
    si tu la mis un peu partout tu receveras plein de saloperies
    à part en changer

    pour ton PC il étai bien infecé
    et on continu en espérant que cela joue pour tes spams

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec

    ------
    = Redémarre en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

    Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel
    -------

    = Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    = Appuie sur Y pour commencer le processus de nettoyage.
    = Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    = Appuie sur une touche pour redémarrer le PC.
    = Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    = Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    = Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    = Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    = Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse
    @+
    0
  16. norbij
     
    Oui en faite, il ne s'agit de pas de PUB sur ma boite mail...

    Mais directement de site qui s'ouvrent en page Internet Explorer...

    Je vais faire la manip...
    0
  17. norbij
     
    [b]SDFix: Version 1.207 [/b]
    Run by Administrateur on 24/07/2008 at 00:11

    Microsoft Windows XP [version 5.1.2600]
    Running From: C:\SDFix

    [b]Checking Services [/b]:

    Restoring Default Security Values
    Restoring Default Hosts File

    Rebooting

    [b]Checking Files [/b]:

    No Trojan Files Found

    Removing Temp Files

    [b]ADS Check [/b]:

    [b]Final Check [/b]:

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-24 00:20:32
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001060af9a58]
    "001783e0b8ae"=hex:b1,9d,36,f2,43,d3,b1,ca,cf,09,39,75,55,36,f8,a4
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001060af9a58]
    "001783e0b8ae"=hex:b1,9d,36,f2,43,d3,b1,ca,cf,09,39,75,55,36,f8,a4

    scanning hidden registry entries ...

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
    "TracesProcessed"=dword:0000004b
    "TracesSuccessful"=dword:00000003

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    [b]Remaining Services [/b]:

    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft (R) HTML Application host"
    "C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"

    [b]Remaining Files [/b]:

    [b]Files with Hidden Attributes [/b]:

    Tue 4 Mar 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
    Fri 16 Nov 2007 20 ...H. --- "C:\Program Files\Common Files\ServerExten\AQ@30_10.bak"
    Mon 17 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
    Thu 8 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT2.tmp"

    [b]Finished![/b]
    0
  18. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok on continu en poussant la recherche

    Télécharge DiagHelp.zip sur ton bureau http://www.malekal.com/download/DiagHelp.zip
    ==> Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
    ==> Un nouveau dossier chercher va être créé DiagHelp
    ==> Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
    ==> Une fenêtre va s'ouvrir, choisis l'option 1
    ==> L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande
    ==> Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
    ==> Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
    ==> A nouveau menu Edition / copier
    ==> Dans un nouveau message ici, faire un clic droit / coller

    ensuite

    Télécharge sur ton bureau DSS (ex Comboscan) de Deckard:

    (choisis enregistrer, puis Bureau comme emplacement)

    http://deckard.geekstogo.com/dss.exe

    Ferme toutes les applications en cours.

    Double-clic sur comboscan.exe pour lancer l'outil.

    Une fenêtre s'ouvre, invitant à fermer toutes les applications, clique sur OK.

    A la fin de l'analyse, une fenêtre s'ouvre, clique sur OK.

    Le rapport Comboscan.txt va s'afficher, copie le dans ta prochaine réponse.
    Si un rapport complémentaire a été créé, poste le aussi dans ta réponse.

    @+
    0
  19. norbij
     
    VOILA LE PREMIER DEJA :

    DiagHelp version v1.4 - http://www.malekal.com
    excute le 24/07/2008 à 0:35:10.98

    Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
    C:\WINDOWS\prefetch\WINRAR.EXE-39C6DAD9.pf -->24/07/2008 00:34:43
    C:\WINDOWS\prefetch\FIREFOX.EXE-28641590.pf -->24/07/2008 00:34:01
    C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->24/07/2008 00:33:37
    C:\WINDOWS\prefetch\MSIMN.EXE-38BA891D.pf -->24/07/2008 00:23:08
    C:\WINDOWS\prefetch\CTFMON.EXE-0E17969B.pf -->24/07/2008 00:23:08
    C:\WINDOWS\prefetch\LULNCHR.EXE-113736AD.pf -->24/07/2008 00:23:04
    C:\WINDOWS\prefetch\LOGITECHUPDATE.EXE-2F890CDB.pf -->24/07/2008 00:23:04
    C:\WINDOWS\prefetch\IMAPI.EXE-0BF740A4.pf -->24/07/2008 00:22:54
    C:\WINDOWS\prefetch\JUSCHED.EXE-27E1FBBB.pf -->24/07/2008 00:22:51
    C:\WINDOWS\prefetch\HPZTSB09.EXE-17B97A12.pf -->24/07/2008 00:22:51

    C:\WINDOWS\System32\drivers\tcpip.sys -->20/06/2008 12:45:13
    C:\WINDOWS\System32\drivers\afd.sys -->20/06/2008 12:44:38
    C:\WINDOWS\System32\drivers\tcpip6.sys -->20/06/2008 11:52:06
    C:\WINDOWS\System32\drivers\bthport.sys -->14/06/2008 19:59:52
    C:\WINDOWS\System32\drivers\rmcast.sys -->08/05/2008 14:28:49
    C:\WINDOWS\System32\drivers\pcouffin.sys -->28/04/2008 19:28:45
    C:\WINDOWS\System32\drivers\mrxdav.sys -->18/12/2007 11:51:35

    C:\WINDOWS\System32\nvapps.xml -->24/07/2008 00:22:42
    C:\WINDOWS\System32\3W71kaDs.exe -->23/07/2008 20:03:13
    C:\WINDOWS\System32\3W71kaDs.exe.a_a -->23/07/2008 13:48:09
    C:\WINDOWS\System32\wpa.dbl -->22/07/2008 13:36:40
    C:\WINDOWS\System32\jupdate-1.6.0_07-b06.log -->20/07/2008 16:30:06
    C:\WINDOWS\System32\msxml3a.dll -->20/07/2008 02:45:55
    C:\WINDOWS\System32\msvcr71.dll -->20/07/2008 02:45:54
    C:\WINDOWS\System32\msvcp71.dll -->20/07/2008 02:45:53
    C:\WINDOWS\System32\PerfStringBackup.INI -->28/06/2008 20:05:53
    C:\WINDOWS\System32\perfh00C.dat -->28/06/2008 20:05:53
    C:\WINDOWS\System32\perfh009.dat -->28/06/2008 20:05:53
    C:\WINDOWS\System32\perfc00C.dat -->28/06/2008 20:05:53
    C:\WINDOWS\System32\perfc009.dat -->28/06/2008 20:05:53
    C:\WINDOWS\System32\MRT.exe -->25/06/2008 18:15:46
    C:\WINDOWS\System32\mswsock.dll -->20/06/2008 19:41:06
    C:\WINDOWS\System32\dnsapi.dll -->20/06/2008 19:41:06
    C:\WINDOWS\System32\d3d9caps.dat -->14/06/2008 09:17:53
    C:\WINDOWS\System32\lvcoinst.log -->12/06/2008 21:46:14
    C:\WINDOWS\System32\javaws.exe -->10/06/2008 02:32:34
    C:\WINDOWS\System32\javacpl.cpl -->10/06/2008 02:32:34
    C:\WINDOWS\System32\javaw.exe -->10/06/2008 01:21:04
    C:\WINDOWS\System32\java.exe -->10/06/2008 01:21:01
    C:\WINDOWS\System32\dpufr.qm -->31/05/2008 01:23:12
    C:\WINDOWS\System32\dpuGUI10.dll -->31/05/2008 01:22:58
    C:\WINDOWS\System32\dpv11.dll -->31/05/2008 01:22:54

    C:\WINDOWS\WindowsUpdate.log -->24/07/2008 00:29:55
    C:\WINDOWS\0.log -->24/07/2008 00:18:26
    C:\WINDOWS\wiaservc.log -->24/07/2008 00:18:24
    C:\WINDOWS\wiadebug.log -->24/07/2008 00:18:24
    C:\WINDOWS\bootstat.dat -->24/07/2008 00:18:01
    C:\WINDOWS\ntbtlog.txt -->24/07/2008 00:10:13
    C:\WINDOWS\SchedLgU.Txt -->24/07/2008 00:02:05
    C:\WINDOWS\system.ini -->23/07/2008 13:34:23
    C:\WINDOWS\setupapi.log -->22/07/2008 20:44:27
    C:\WINDOWS\wmsetup.log -->20/07/2008 12:50:21
    C:\WINDOWS\setuperr.log -->20/07/2008 00:14:39
    C:\WINDOWS\setupact.log -->20/07/2008 00:14:39
    C:\WINDOWS\NeroDigital.ini -->08/06/2008 11:51:57
    C:\WINDOWS\mozver.dat -->30/12/2007 15:33:39
    C:\WINDOWS\AviSplitter.INI -->18/12/2007 21:10:50

    winlogon.exe
    Verified: Signed
    svchost.exe
    Verified: Signed
    ws2_32.dll
    Verified: Signed
    user32.dll
    Verified: Signed
    tcpip.sys
    Verified: Signed
    ndis.sys
    Verified: Signed
    null.sys
    Verified: Signed

    ListDLLs v2.25 - DLL lister for Win9x/NT
    Copyright (C) 1997-2004 Mark Russinovich
    Sysinternals - www.sysinternals.com

    ------------------------------------------------------------------------------
    explorer.exe pid: 1688
    Command line: C:\WINDOWS\Explorer.EXE

    Base Size Version Path
    0x44080000 0xd0000 7.00.6000.16674 C:\WINDOWS\system32\WININET.dll
    0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
    0x43e00000 0x45000 7.00.6000.16674 C:\WINDOWS\system32\iertutil.dll
    0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll
    0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
    0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
    0x44160000 0x127000 7.00.6000.16674 C:\WINDOWS\system32\urlmon.dll
    0x44360000 0x5cd000 7.00.6000.16674 C:\WINDOWS\system32\ieframe.dll
    0x7d200000 0x2be000 3.01.4000.4039 C:\WINDOWS\system32\msi.dll
    0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
    0x10100000 0x11000 4.24.0099.0000 C:\Program Files\Logitech\SetPoint\lgscroll.dll
    0x78130000 0x9b000 8.00.50727.0762 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
    0x7c420000 0x87000 8.00.50727.0762 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCP80.dll
    0x01ea0000 0x171000 6.14.0010.11090 C:\WINDOWS\system32\nview.dll
    0x10000000 0x50000 6.14.0010.11090 C:\WINDOWS\system32\NVWRSFR.DLL
    0x442b0000 0x3c000 7.00.6000.16674 C:\WINDOWS\system32\webcheck.dll
    0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
    0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
    0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
    0x00d30000 0x26000 1.00.0000.0001 C:\WINDOWS\system32\RFNP32.DLL
    0x015d0000 0x80000 C:\WINDOWS\system32\RFHelper.dll
    0x00d90000 0x9000 1.00.0000.0001 C:\WINDOWS\system32\rfhres.dll
    0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
    0x02450000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
    0x50640000 0x9000 7.00.6000.0381 C:\WINDOWS\system32\wups.dll
    0x024e0000 0x2e000 C:\Program Files\WinRAR\rarext.dll
    0x02510000 0x22000 C:\WINDOWS\system32\rfshext.dll
    0x02540000 0x6000 1.00.0000.0001 C:\WINDOWS\system32\rfshres.dll
    0x02d60000 0x6000 C:\Program Files\Unlocker\UnlockerCOM.dll
    0x02d80000 0x28000 3.05.0007.0019 C:\PROGRA~1\TAGREN~1\TRshell.dll
    0x02fa0000 0x10000 8.00.0000.0456 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    0x03280000 0x29000 C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll
    0x03310000 0xb000 C:\Program Files\Haali\MatroskaSplitter\mkunicode.dll
    0x03330000 0x5b000 8.01.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
    0x033a0000 0x4c000 8.00.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
    0x6bd10000 0x10000 12.00.4518.1014 C:\Program Files\Microsoft Office\Office12\msohevi.dll

    ListDLLs v2.25 - DLL lister for Win9x/NT
    Copyright (C) 1997-2004 Mark Russinovich
    Sysinternals - www.sysinternals.com

    ------------------------------------------------------------------------------
    winlogon.exe pid: 640
    Command line: winlogon.exe

    Base Size Version Path
    0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe
    0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll
    0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
    0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
    0x10000000 0x12000 4.24.0099.0000 c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
    0x01200000 0x23000 4.24.0099.0000 c:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
    0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
    0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
    0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL

    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 3C58-2F06

    Répertoire de C:\WINDOWS\system32

    19/08/2004 17:09 6 144 csrss.exe
    1 fichier(s) 6 144 octets
    0 Rép(s) 83 421 700 096 octets libres

    Contenu de Downloaded Program Files
    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 3C58-2F06

    Répertoire de C:\WINDOWS\Downloaded Program Files

    08/03/2008 15:03 <REP> .
    08/03/2008 15:03 <REP> ..
    15/12/2007 14:32 65 desktop.ini
    20/11/2007 17:04 1 523 536 FP_AX_CAB_INSTALLER.exe
    23/02/2007 00:41 304 544 MessengerStatsPAClient.dll
    20/11/2007 16:50 247 swflash.inf
    4 fichier(s) 1 828 392 octets

    Total des fichiers listés :
    4 fichier(s) 1 828 392 octets
    2 Rép(s) 83 421 700 096 octets libres

    Recherche de rootkit! (Merci S!Ri)

    Recherche d'infections connues

    Export des clefs sensibles..

    Liste des fichiers en exception sur le pare-feu XP SP2

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\WINDOWS\\system32\\mshta.exe"="C:\\WINDOWS\\system32\\mshta.exe:*:Enabled:Microsoft (R) HTML Application host"
    "C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
    "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"

    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
    "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
    "C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe"="C:\\Program Files\\CyberLink\\PowerDVD8\\PowerDVD8.exe:*:Enabled:CyberLink PowerDVD 8.0"

    Export de la clef SharedTaskScheduler

    [SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

    exports des policies
    REGEDIT4

    [system]
    "dontdisplaylastusername"=dword:00000000
    "legalnoticecaption"=""
    "legalnoticetext"=""
    "shutdownwithoutlogon"=dword:00000001
    "undockwithoutlogon"=dword:00000001
    "HideLegacyLogonScripts"=dword:00000000
    "HideLogoffScripts"=dword:00000000
    "RunLogonScriptSync"=dword:00000001
    "RunStartupScriptSync"=dword:00000000
    "HideStartupScripts"=dword:00000000

    Export des clefs sensibles..
    Rechercher adresses sensibles dans le fichier HOSTS...
    catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-07-24 00:35:50
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden services & system hive ...

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001060af9a58]
    "001783e0b8ae"=hex:b1,9d,36,f2,43,d3,b1,ca,cf,09,39,75,55,36,f8,a4
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001060af9a58]
    "001783e0b8ae"=hex:b1,9d,36,f2,43,d3,b1,ca,cf,09,39,75,55,36,f8,a4

    scanning hidden registry entries ...

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
    "TracesProcessed"=dword:000001b9

    scanning hidden files ...

    scan completed successfully
    hidden services: 0
    hidden files: 0

    KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

    Process list by traversal of KiWaitListHead

    4 - System
    260 - rundll32.exe
    616 - csrss.exe
    640 - winlogon.exe
    684 - services.exe
    696 - lsass.exe
    860 - svchost.exe
    880 - alg.exe
    928 - svchost.exe
    1024 - svchost.exe
    1080 - svchost.exe
    1224 - svchost.exe
    1280 - aawservice.exe
    1584 - mDNSResponder.e
    1688 - explorer.exe
    1904 - nvsvc32.exe
    1928 - RichVideo.exe
    1960 - rundll32.exe
    2032 - AAWTray.exe
    2044 - slserv.exe
    2412 - msimn.exe
    2536 - ctfmon.exe
    3752 - cmd.exe

    Total number of processes = 23
    NOTE: Under WinXP, this will not show all processes.

    KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

    Driver/Module list by traversal of PsLoadedModuleList

    804D7000 - \WINDOWS\system32\ntoskrnl.exe
    806FD000 - \WINDOWS\system32\hal.dll
    F7D2F000 - \WINDOWS\system32\KDCOM.DLL
    F7C3F000 - \WINDOWS\system32\BOOTVID.dll
    F77DF000 - ACPI.sys
    F7D31000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS
    F77CE000 - pci.sys
    F782F000 - isapnp.sys
    F7DF7000 - pciide.sys
    F7AAF000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
    F783F000 - MountMgr.sys
    F77AF000 - ftdisk.sys
    F7AB7000 - PartMgr.sys
    F784F000 - VolSnap.sys
    F7797000 - atapi.sys
    F785F000 - disk.sys
    F786F000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
    F7777000 - fltmgr.sys
    F7765000 - sr.sys
    F774E000 - KSecDD.sys
    F76C1000 - Ntfs.sys
    F7694000 - NDIS.sys
    F7C43000 - RecAgent.sys
    F7679000 - Mup.sys
    F7A4F000 - \SystemRoot\System32\DRIVERS\intelppm.sys
    F7263000 - \SystemRoot\system32\DRIVERS\nv4_mini.sys
    F724F000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    F722A000 - \SystemRoot\system32\DRIVERS\HDAudBus.sys
    F7B67000 - \SystemRoot\System32\DRIVERS\usbuhci.sys
    F7207000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS
    F7B6F000 - \SystemRoot\System32\DRIVERS\usbehci.sys
    F71C1000 - \SystemRoot\system32\DRIVERS\yk51x86.sys
    F716F000 - \SystemRoot\system32\DRIVERS\Cap7134.sys
    F7A7F000 - \SystemRoot\system32\DRIVERS\STREAM.SYS
    F714C000 - \SystemRoot\system32\DRIVERS\ks.sys
    F70E9000 - \SystemRoot\System32\DRIVERS\slntamr.sys
    F7D13000 - \SystemRoot\System32\DRIVERS\SlWdmSup.sys
    F70CA000 - \SystemRoot\System32\DRIVERS\Mtlmnt5.sys
    F7B77000 - \SystemRoot\System32\Drivers\Modem.SYS
    F7B7F000 - \SystemRoot\System32\DRIVERS\fdc.sys
    F70B6000 - \SystemRoot\System32\DRIVERS\parport.sys
    F70A5000 - \SystemRoot\System32\DRIVERS\serial.sys
    F7D1B000 - \SystemRoot\System32\DRIVERS\serenum.sys
    F7A8F000 - \SystemRoot\System32\DRIVERS\imapi.sys
    F7D1F000 - \SystemRoot\system32\drivers\pfc.sys
    F7A9F000 - \SystemRoot\System32\DRIVERS\cdrom.sys
    F78BF000 - \SystemRoot\System32\DRIVERS\redbook.sys
    F7EBD000 - \SystemRoot\System32\DRIVERS\audstub.sys
    F791F000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys
    F7D2B000 - \SystemRoot\System32\DRIVERS\ndistapi.sys
    F708E000 - \SystemRoot\System32\DRIVERS\ndiswan.sys
    F792F000 - \SystemRoot\System32\DRIVERS\raspppoe.sys
    F793F000 - \SystemRoot\System32\DRIVERS\raspptp.sys
    F7B87000 - \SystemRoot\System32\DRIVERS\TDI.SYS
    F707D000 - \SystemRoot\System32\DRIVERS\psched.sys
    F794F000 - \SystemRoot\System32\DRIVERS\msgpc.sys
    F7B8F000 - \SystemRoot\System32\DRIVERS\ptilink.sys
    F7B97000 - \SystemRoot\System32\DRIVERS\raspti.sys
    F795F000 - \SystemRoot\System32\Drivers\pcouffin.sys
    F796F000 - \SystemRoot\System32\DRIVERS\termdd.sys
    F7B9F000 - \SystemRoot\System32\DRIVERS\kbdclass.sys
    F7BA7000 - \SystemRoot\System32\DRIVERS\mouclass.sys
    F7D65000 - \SystemRoot\System32\DRIVERS\swenum.sys
    F7024000 - \SystemRoot\System32\DRIVERS\update.sys
    F764D000 - \SystemRoot\System32\DRIVERS\mssmbios.sys
    F797F000 - \SystemRoot\System32\Drivers\NDProxy.SYS
    F4E36000 - \SystemRoot\system32\drivers\ADIHdAud.sys
    F4E12000 - \SystemRoot\system32\drivers\portcls.sys
    F799F000 - \SystemRoot\system32\drivers\drmk.sys
    F4DF2000 - \SystemRoot\system32\drivers\AEAudio.sys
    F4D92000 - \SystemRoot\system32\drivers\Senfilt.sys
    F79CF000 - \SystemRoot\System32\DRIVERS\usbhub.sys
    F7D89000 - \SystemRoot\System32\DRIVERS\USBD.SYS
    F7BB7000 - \SystemRoot\system32\DRIVERS\PhTVTune.sys
    F7D03000 - \SystemRoot\system32\drivers\MODEMCSA.sys
    F7BBF000 - \SystemRoot\System32\DRIVERS\flpydisk.sys
    F7D99000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
    F7E44000 - \SystemRoot\System32\Drivers\Null.SYS
    F7D9B000 - \SystemRoot\System32\Drivers\Beep.SYS
    F7BCF000 - \SystemRoot\System32\DRIVERS\HIDPARSE.SYS
    F7BD7000 - \SystemRoot\System32\drivers\vga.sys
    F7D9D000 - \SystemRoot\System32\Drivers\mnmdd.SYS
    F7D9F000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
    F7BDF000 - \SystemRoot\System32\Drivers\Msfs.SYS
    F7BE7000 - \SystemRoot\System32\Drivers\Npfs.SYS
    F7D0B000 - \SystemRoot\System32\DRIVERS\rasacd.sys
    F4D37000 - \SystemRoot\System32\DRIVERS\ipsec.sys
    F4CDF000 - \SystemRoot\System32\DRIVERS\tcpip.sys
    F4CB7000 - \SystemRoot\System32\DRIVERS\netbt.sys
    F4C96000 - \SystemRoot\System32\DRIVERS\ipnat.sys
    F4C74000 - \SystemRoot\System32\drivers\afd.sys
    F7A1F000 - \SystemRoot\System32\DRIVERS\netbios.sys
    F7A2F000 - \SystemRoot\System32\DRIVERS\wanarp.sys
    F4C49000 - \SystemRoot\System32\DRIVERS\rdbss.sys
    F7BEF000 - \??\C:\WINDOWS\system32\Drivers\nvport.sys
    F4BB2000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys
    F7A6F000 - \SystemRoot\System32\Drivers\Fips.SYS
    F7BFF000 - \SystemRoot\System32\DRIVERS\usbccgp.sys
    F78CF000 - \SystemRoot\System32\Drivers\Cdfs.SYS
    F7C0F000 - \SystemRoot\System32\DRIVERS\USBSTOR.SYS
    F7645000 - \SystemRoot\System32\DRIVERS\hidusb.sys
    F78DF000 - \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
    F7C17000 - \SystemRoot\System32\Drivers\LUsbFilt.Sys
    F78EF000 - \SystemRoot\System32\Drivers\WDFLDR.SYS
    F4B37000 - \SystemRoot\system32\DRIVERS\Wdf01000.sys
    F7CBF000 - \SystemRoot\System32\DRIVERS\kbdhid.sys
    F7C1F000 - \SystemRoot\system32\DRIVERS\LHidFilt.Sys
    F7CC3000 - \SystemRoot\System32\DRIVERS\mouhid.sys
    F7C27000 - \SystemRoot\system32\DRIVERS\LMouFilt.Sys
    F4B1F000 - \SystemRoot\System32\Drivers\dump_atapi.sys
    F7DB3000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    BF800000 - \SystemRoot\System32\win32k.sys
    F4D7A000 - \SystemRoot\System32\drivers\Dxapi.sys
    F7C37000 - \SystemRoot\System32\watchdog.sys
    BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
    F7EE7000 - \SystemRoot\System32\drivers\dxgthk.sys
    BF9D5000 - \SystemRoot\System32\nv4_disp.dll
    BFFA0000 - \SystemRoot\System32\ATMFD.DLL
    BAD10000 - \SystemRoot\System32\DRIVERS\ndisuio.sys
    B998B000 - \SystemRoot\system32\drivers\wdmaud.sys
    B9AF0000 - \SystemRoot\system32\drivers\sysaudio.sys
    B9911000 - \SystemRoot\System32\DRIVERS\mrxdav.sys
    F7D63000 - \SystemRoot\System32\Drivers\ParVdm.SYS
    B97A7000 - \SystemRoot\System32\DRIVERS\srv.sys
    B9891000 - \??\C:\Program Files\NetDrive\rffsd.sys
    B966E000 - \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl
    F7BAF000 - \??\C:\DOCUME~1\Julien\LOCALS~1\Temp\catchme.sys
    B9140000 - \SystemRoot\System32\Drivers\HTTP.sys
    B92ED000 - \??\C:\WINDOWS\system32\drivers\NSDriver.sys
    F7EB3000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys

    Total number of drivers = 130

    Liste des programmes installes

    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    2007 Microsoft Office Suite Service Pack 1 (SP1)
    Ad-Aware 2007
    Ad-Aware 2007
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Color - Photoshop Specific
    Adobe Color Common Settings
    Adobe Color EU Recommended Settings
    Adobe Color JA Extra Settings
    Adobe Color NA Extra Settings
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe ExtendScript Toolkit 2
    Adobe Flash Player ActiveX
    Adobe Flash Player Plugin
    Adobe Fonts All
    Adobe Help Viewer CS3
    Adobe Linguistics CS3
    Adobe PDF Library Files
    Adobe Photoshop CS3
    Adobe Photoshop CS3
    Adobe Reader 8.1.1 - Français
    Adobe Setup
    Adobe Shockwave Player
    Adobe Stock Photos CS3
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS3
    Archiveur WinRAR
    AutoUpdate
    CamStudio
    CCleaner (remove only)
    CDDRV_Installer
    ConvertXtoDVD 2.2.3.258
    Cool Desk 3.86
    CoreAVC Pro (remove only)
    Correctif pour Lecteur Windows Media 11 (KB939683)
    Correctif pour Windows Internet Explorer 7 (KB947864)
    Correctif pour Windows XP (KB914440)
    Correctif Windows XP - KB873339
    Correctif Windows XP - KB885835
    Correctif Windows XP - KB885836
    Correctif Windows XP - KB886185
    Correctif Windows XP - KB887472
    Correctif Windows XP - KB888302
    Correctif Windows XP - KB890859
    Correctif Windows XP - KB891781
    CyberLink PowerDVD8
    CyberLink PowerDVD8
    DivX Codec
    eMule Plus 1.2d
    FLAC 1.2.1b (remove only)
    Google Earth
    Haali Media Splitter
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows XP (KB909394)
    Hotfix for Windows XP (KB915865)
    Hotfix for Windows XP (KB926239)
    hp deskjet 5100
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    KhalInstallWrapper
    La Démo de So Blonde
    Lecteur Windows Media 11
    Logitech SetPoint
    M4a/Flac/Ogg/Ape/Mpc Tag Support Plugin for Media Player v 1.1
    Media Player Classic fr
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 French Language Pack
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft ActiveSync
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Access MUI (French) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (French) 2007
    Microsoft Office Groove MUI (French) 2007
    Microsoft Office InfoPath MUI (French) 2007
    Microsoft Office Language Pack 2007 Service Pack 1 (SP1)
    Microsoft Office OneNote MUI (French) 2007
    Microsoft Office Outlook MUI (French) 2007
    Microsoft Office PowerPoint MUI (French) 2007
    Microsoft Office Proof (Arabic) 2007
    Microsoft Office Proof (Dutch) 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (German) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (French) 2007
    Microsoft Office Publisher MUI (French) 2007
    Microsoft Office Shared MUI (French) 2007
    Microsoft Office Word MUI (French) 2007
    Microsoft Software Update for Web Folders (French) 12
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
    Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)
    Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
    Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)
    Mise à jour de sécurité pour Windows XP (KB890046)
    Mise à jour de sécurité pour Windows XP (KB893756)
    Mise à jour de sécurité pour Windows XP (KB896358)
    Mise à jour de sécurité pour Windows XP (KB896423)
    Mise à jour de sécurité pour Windows XP (KB896428)
    Mise à jour de sécurité pour Windows XP (KB899587)
    Mise à jour de sécurité pour Windows XP (KB899591)
    Mise à jour de sécurité pour Windows XP (KB900725)
    Mise à jour de sécurité pour Windows XP (KB901017)
    Mise à jour de sécurité pour Windows XP (KB901214)
    Mise à jour de sécurité pour Windows XP (KB902400)
    Mise à jour de sécurité pour Windows XP (KB905414)
    Mise à jour de sécurité pour Windows XP (KB905749)
    Mise à jour de sécurité pour Windows XP (KB908519)
    Mise à jour de sécurité pour Windows XP (KB911562)
    Mise à jour de sécurité pour Windows XP (KB911927)
    Mise à jour de sécurité pour Windows XP (KB913580)
    Mise à jour de sécurité pour Windows XP (KB914388)
    Mise à jour de sécurité pour Windows XP (KB914389)
    Mise à jour de sécurité pour Windows XP (KB917953)
    Mise à jour de sécurité pour Windows XP (KB918118)
    Mise à jour de sécurité pour Windows XP (KB918439)
    Mise à jour de sécurité pour Windows XP (KB919007)
    Mise à jour de sécurité pour Windows XP (KB920213)
    Mise à jour de sécurité pour Windows XP (KB920670)
    Mise à jour de sécurité pour Windows XP (KB920683)
    Mise à jour de sécurité pour Windows XP (KB920685)
    Mise à jour de sécurité pour Windows XP (KB921503)
    Mise à jour de sécurité pour Windows XP (KB922819)
    Mise à jour de sécurité pour Windows XP (KB923191)
    Mise à jour de sécurité pour Windows XP (KB923414)
    Mise à jour de sécurité pour Windows XP (KB923789)
    Mise à jour de sécurité pour Windows XP (KB923980)
    Mise à jour de sécurité pour Windows XP (KB924270)
    Mise à jour de sécurité pour Windows XP (KB924496)
    Mise à jour de sécurité pour Windows XP (KB924667)
    Mise à jour de sécurité pour Windows XP (KB925902)
    Mise à jour de sécurité pour Windows XP (KB926255)
    Mise à jour de sécurité pour Windows XP (KB926436)
    Mise à jour de sécurité pour Windows XP (KB927779)
    Mise à jour de sécurité pour Windows XP (KB927802)
    Mise à jour de sécurité pour Windows XP (KB928255)
    Mise à jour de sécurité pour Windows XP (KB928843)
    Mise à jour de sécurité pour Windows XP (KB929123)
    Mise à jour de sécurité pour Windows XP (KB930178)
    Mise à jour de sécurité pour Windows XP (KB931261)
    Mise à jour de sécurité pour Windows XP (KB931784)
    Mise à jour de sécurité pour Windows XP (KB932168)
    Mise à jour de sécurité pour Windows XP (KB933729)
    Mise à jour de sécurité pour Windows XP (KB935839)
    Mise à jour de sécurité pour Windows XP (KB935840)
    Mise à jour de sécurité pour Windows XP (KB936021)
    Mise à jour de sécurité pour Windows XP (KB938127)
    Mise à jour de sécurité pour Windows XP (KB938829)
    Mise à jour de sécurité pour Windows XP (KB941202)
    Mise à jour de sécurité pour Windows XP (KB941568)
    Mise à jour de sécurité pour Windows XP (KB941569)
    Mise à jour de sécurité pour Windows XP (KB941644)
    Mise à jour de sécurité pour Windows XP (KB941693)
    Mise à jour de sécurité pour Windows XP (KB942615)
    Mise à jour de sécurité pour Windows XP (KB943055)
    Mise à jour de sécurité pour Windows XP (KB943460)
    Mise à jour de sécurité pour Windows XP (KB943485)
    Mise à jour de sécurité pour Windows XP (KB944653)
    Mise à jour de sécurité pour Windows XP (KB945553)
    Mise à jour de sécurité pour Windows XP (KB946026)
    Mise à jour de sécurité pour Windows XP (KB948590)
    Mise à jour de sécurité pour Windows XP (KB948881)
    Mise à jour de sécurité pour Windows XP (KB950749)
    Mise à jour de sécurité pour Windows XP (KB950760)
    Mise à jour de sécurité pour Windows XP (KB950762)
    Mise à jour de sécurité pour Windows XP (KB951376-v2)
    Mise à jour de sécurité pour Windows XP (KB951376)
    Mise à jour de sécurité pour Windows XP (KB951698)
    Mise à jour de sécurité pour Windows XP (KB951748)
    Mise à jour pour Windows XP (KB894391)
    Mise à jour pour Windows XP (KB898461)
    Mise à jour pour Windows XP (KB900485)
    Mise à jour pour Windows XP (KB904942)
    Mise à jour pour Windows XP (KB908531)
    Mise à jour pour Windows XP (KB910437)
    Mise à jour pour Windows XP (KB911280)
    Mise à jour pour Windows XP (KB916595)
    Mise à jour pour Windows XP (KB920872)
    Mise à jour pour Windows XP (KB922582)
    Mise à jour pour Windows XP (KB927891)
    Mise à jour pour Windows XP (KB930916)
    Mise à jour pour Windows XP (KB932823-v3)
    Mise à jour pour Windows XP (KB936357)
    Mise à jour pour Windows XP (KB938828)
    Mise à jour pour Windows XP (KB942763)
    Mise à jour pour Windows XP (KB942840)
    Mozilla Firefox (3.0.1)
    MSXML 4.0 SP2 (KB936181)
    neroxml
    NetDrive
    NVIDIA Drivers
    NVIDIA PureVideo Decoder
    overland
    PDF Settings
    QuickTime Alternative 2.4.0
    Satsuki Decoder Pack
    Security Update for Excel 2007 (KB946974)
    Security Update for Microsoft Office Publisher 2007 (KB950114)
    Security Update for Microsoft Office system 2007 (KB951808)
    Security Update for Microsoft Office Word 2007 (KB950113)
    Security Update for Office 2007 (KB947801)
    Security Update for Visio 2007 (KB947590)
    SoundMAX
    Tag&Rename 3.4.6
    TinyPDF
    TomTom HOME
    TomTom HOME
    Unlocker 1.8.5
    Update for Microsoft Office Outlook 2007 (KB952142)
    Update for Office 2007 (KB946691)
    Update for Outlook 2007 Junk Email Filter (kb953463)
    VideoLAN VLC media player 0.8.6f
    ViewSonic Monitor Drivers
    ViewSonic Windows XP Signed Files
    Virtual Rides - Contest Demo 1.0
    WebFldrs XP
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Installer 3.1 (KB893803)
    Windows Internet Explorer 7
    Windows Live installer
    Windows Live Messenger
    Windows Live OneCare safety scanner
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 2

    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 3C58-2F06

    Répertoire de C:\Program Files

    23/07/2008 21:54 <REP> .
    23/07/2008 21:54 <REP> ..
    23/12/2007 16:06 <REP> Adobe
    17/12/2007 01:43 <REP> Analog Devices
    23/12/2007 16:05 <REP> Bonjour
    30/03/2008 23:16 <REP> CamStudio
    26/03/2008 00:57 <REP> CCleaner
    26/03/2008 00:55 <REP> CDDC-VDesk
    16/02/2008 10:40 <REP> Common Files
    15/12/2007 14:31 <REP> ComPlus Applications
    17/12/2007 01:45 <REP> CoreCodec
    20/07/2008 02:37 <REP> CyberLink
    26/06/2008 22:06 <REP> DivX
    18/07/2008 21:01 <REP> eMule
    30/03/2008 12:37 23 436 ffdsasetts.reg
    30/03/2008 12:37 49 114 ffdssetts.reg
    30/03/2008 12:37 31 754 ffdsvsetts.reg
    21/07/2008 22:50 <REP> Fichiers communs
    18/06/2008 18:52 <REP> Firefox
    24/03/2008 20:42 <REP> FLAC
    25/03/2008 21:42 <REP> Goffi
    23/12/2007 20:14 <REP> Google
    17/12/2007 01:12 <REP> Haali
    17/12/2007 00:33 <REP> Hewlett-Packard
    17/12/2007 00:33 <REP> HP
    16/12/2007 20:21 <REP> Intel
    12/06/2008 01:28 <REP> Internet Explorer
    20/07/2008 16:30 <REP> Java
    22/07/2008 00:01 <REP> Lavasoft
    17/12/2007 19:52 <REP> Logitech
    18/12/2007 19:23 <REP> Media Player Classic
    17/12/2007 01:16 <REP> Messenger
    27/06/2008 18:44 <REP> Microsoft ActiveSync
    15/12/2007 14:36 <REP> microsoft frontpage
    22/12/2007 14:18 <REP> Microsoft Office
    22/12/2007 14:19 <REP> Microsoft Works
    22/12/2007 14:17 <REP> Microsoft.NET
    15/12/2007 15:19 <REP> Movie Maker
    24/07/2008 00:34 <REP> Mozilla Firefox
    13/06/2008 20:21 <REP> mp3DirectCut
    30/03/2008 12:37 596 mpc1.reg
    30/03/2008 12:37 3 026 mpc3.reg
    30/03/2008 12:37 16 150 mpc5.reg
    30/03/2008 12:37 18 156 mpc6.reg
    30/03/2008 12:37 3 476 mpc7.reg
    19/01/2008 11:10 <REP> MPMAN
    15/12/2007 14:31 <REP> MSN
    15/12/2007 14:31 <REP> MSN Gaming Zone
    18/12/2007 14:51 <REP> MSXML 4.0
    22/03/2008 15:52 <REP> NetDrive
    15/12/2007 15:18 <REP> NetMeeting
    17/12/2007 01:13 <REP> NVIDIA Corporation
    16/12/2007 21:52 <REP> Outlook Express
    17/12/2007 00:39 <REP> Overland
    20/02/2008 23:11 <REP> QuickTime Alternative
    18/12/2007 19:35 <REP> Satsuki Decoder Pack
    30/03/2008 12:37 4 635 satsukidecodersettings.ini
    26/03/2008 00:56 <REP> ShellToys
    21/06/2008 00:16 <REP> So Blonde Demo
    12/06/2008 20:15 <REP> SoundSpectrum
    12/06/2008 20:12 <REP> Tag Support Plugin for Media Player
    13/06/2008 00:29 <REP> TagRename
    04/03/2008 21:51 <REP> TinyPDF
    27/01/2008 17:07 <REP> TomTom HOME 2
    11/04/2008 23:24 <REP> Unlocker
    20/12/2007 00:37 <REP> uTorrent
    12/01/2008 12:50 <REP> Virtual Rides - Shake R5 Contest Demo
    17/05/2008 11:02 <REP> VLC
    28/04/2008 19:28 <REP> VSO
    23/07/2008 20:13 <REP> WinAVI MP4 Converter
    17/12/2007 00:22 <REP> Windows Live
    01/07/2008 20:10 <REP> Windows Live Safety Center
    17/12/2007 00:13 <REP> Windows Media Connect 2
    17/12/2007 00:13 <REP> Windows Media Player
    15/12/2007 15:17 <REP> Windows NT
    17/12/2007 01:10 <REP> WinRAR
    15/12/2007 14:36 <REP> xerox
    08/06/2008 14:57 <REP> Yahoo!
    9 fichier(s) 150 343 octets
    69 Rép(s) 83 410 321 408 octets libres
    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 3C58-2F06

    Répertoire de C:\Program Files\fichiers communs

    21/07/2008 22:50 <REP> .
    21/07/2008 22:50 <REP> ..
    23/12/2007 16:05 <REP> Adobe
    08/06/2008 11:54 <REP> Ahead
    20/07/2008 02:50 <REP> CyberLink
    22/12/2007 14:18 <REP> DESIGNER
    16/02/2008 10:40 <REP> InstallShield
    15/12/2007 14:34 <REP> Java
    17/12/2007 19:52 <REP> logishrd
    23/12/2007 15:56 <REP> Macrovision Shared
    20/07/2008 02:34 <REP> Microsoft Shared
    15/12/2007 14:31 <REP> MSSoap
    15/12/2007 14:26 <REP> ODBC
    15/12/2007 14:32 <REP> Services
    15/12/2007 14:26 <REP> SpeechEngines
    16/12/2007 21:52 <REP> System
    22/07/2008 00:00 <REP> Wise Installation Wizard
    0 fichier(s) 0 octets
    17 Rép(s) 83 410 321 408 octets libres
    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 3C58-2F06

    Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders

    26/04/2008 08:50 <REP> .
    26/04/2008 08:50 <REP> ..
    22/12/2007 14:15 <REP> 1036
    28/08/2007 23:55 973 168 MSONSEXT.DLL
    03/06/1999 15:09 122 937 MSOWS409.DLL
    07/03/2001 10:00 127 033 MSOWS40c.DLL
    3 fichier(s) 1 223 138 octets
    3 Rép(s) 83 410 317 312 octets libres
    Le volume dans le lecteur C n'a pas de nom.
    Le numéro de série du volume est 3C58-2F06

    Répertoire de C:\Program Files\common files

    16/02/2008 10:40 <REP> .
    16/02/2008 10:40 <REP> ..
    15/12/2007 14:34 <REP> System
    0 fichier(s) 0 octets
    3 Rép(s) 83 410 317 312 octets libres

    c:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\update\aaw2008_upd.exe
    c:\Documents and Settings\Julien\Bureau\175.19_geforce_winxp_32bit_international_whql.exe
    c:\Documents and Settings\Julien\Bureau\94.24_forceware_winxp_international_whql.exe
    c:\Documents and Settings\Julien\Bureau\BTMsimFRvista.exe
    c:\Documents and Settings\Julien\Bureau\ComboFix.exe
    c:\Documents and Settings\Julien\Bureau\guichetsvista.exe
    c:\Documents and Settings\Julien\Bureau\HJT.exe
    c:\Documents and Settings\Julien\Bureau\MP10_EnergyBlissViz.exe
    c:\Documents and Settings\Julien\Bureau\RNRCsimulationvista.exe
    c:\Documents and Settings\Julien\Bureau\SDFix.exe
    c:\Documents and Settings\Julien\Bureau\stsimvista.exe
    c:\Documents and Settings\Julien\Bureau\TagRename346.exe
    c:\Documents and Settings\Julien\Bureau\WMPTagSupport11.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\catchme.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\diff.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\dumphive.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\FilesInfoCmd.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\find2.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\Fport.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\grep.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\gzip.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\KProcCheck.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\LFiles.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\LISTDLLS.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\md5sums.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\pslist.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\sigcheck.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\streams.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\swreg.exe
    c:\Documents and Settings\Julien\Bureau\DiagHelp\tar.exe
    c:\Documents and Settings\Julien\Bureau\soblonde\setup.exe
    c:\Documents and Settings\Julien\Bureau\soblonde\Support\directX\dxsetup.exe
    c:\Documents and Settings\Julien\Mes documents\Downloads\PowerDVD\Keygen.exe
    c:\Documents and Settings\Julien\Mes documents\Downloads\PowerDVD\PowerDVD Ultra 8.0.1513.exe
    c:\Documents and Settings\Julien\Mes documents\Downloads\PowerDVD\PowerDVD Ultra 8.0.1730 update patch.exe
    c:\Documents and Settings\Julien\Mes documents\Downloads\TomTom Navigator 7.450 (9028) for Windows Mobile with keygen\tt7_keygen.exe
    c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
    c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll

    ****** Fin du rapport DiagHelp
    Veuillez svp envoyer le fichier C:\upload_moi_PC-DE-JULIEN.tar.gz a l'adresse http://upload.malekal.com
    0
  • 1
  • 2
  • 3