Bagle, sans doute ;)
Résolu
tylooo1
Messages postés
27
Statut
Membre
-
PIF -
PIF -
Bonjour,
voila j'ai un problème lié à la sécurité de mon pc,il m'est impossible d'activermon windefender ainsi que mon pare feu et tous ce qui est du domaine de protection.Lorsque j'essaie d'activer windefender j ai un bref message d erreur qui disparait quasi instantanement, impossible d'activer spyboot, ccleaner,avastet d'installer un logiciel de verification (accé refusé) ect...
J ai donc besoin de votre aide merci
voila j'ai un problème lié à la sécurité de mon pc,il m'est impossible d'activermon windefender ainsi que mon pare feu et tous ce qui est du domaine de protection.Lorsque j'essaie d'activer windefender j ai un bref message d erreur qui disparait quasi instantanement, impossible d'activer spyboot, ccleaner,avastet d'installer un logiciel de verification (accé refusé) ect...
J ai donc besoin de votre aide merci
A voir également:
- Bagle, sans doute ;)
- Mail chronopost, doute si fraude ou non - Forum Consommation & Internet
- (Faux) virus .bat et GROS DOUTE !!!!! HELP ME PLZ !!!! :( ✓ - Forum Virus
- Doute sur une transaction en mandat cash ✓ - Forum Vos droits sur internet
- Doute suppréssion Virus PUP.Optional.Legacy et PUM ✓ - Forum Virus
- Un doute sur la capacité de mémoire pc ✓ - Forum Matériel & Système
24 réponses
Salut,
Telecharge FindyKill
Fais un clic droit sur le lien, enregister sous .....sur le bureau
---> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.rar
Dezippe le sur le bureau
Entre dans le dossier FindyKill
double clic sur FindyKill.exe
choisi l option 1 (recherche)
un rapport va s ouvrir, post le dans ta prochaine réponse stp
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Telecharge FindyKill
Fais un clic droit sur le lien, enregister sous .....sur le bureau
---> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.rar
Dezippe le sur le bureau
Entre dans le dossier FindyKill
double clic sur FindyKill.exe
choisi l option 1 (recherche)
un rapport va s ouvrir, post le dans ta prochaine réponse stp
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Bonjour, voila le rapport findykill
** Rapport FindyKill **
+- Presence des fichiers dans C:
+- Presence des fichiers dans C:\Windows\Prefetch
C:\Windows\Prefetch\WINTEMS.EXE-????????.pf Present!!
C:\Windows\Prefetch\MDELK.EXE-????????.pf Present!!
C:\Windows\Prefetch\FLEC006.EXE-????????.pf Present!!
+- Presence des fichiers dans C:\Windows\system32
C:\Windows\system32\mdelk.exe Present!!
C:\Windows\system32\wintems.exe Present!!
C:\Windows\system32\ban_list.txt Present!!
+- Presence des fichiers dans C:\Windows\system32\drivers
C:\Windows\system32\drivers\mdelk.exe Present!!
C:\Windows\system32\drivers\srosa.sys Present!!
C:\Windows\system32\drivers\hldrrr.exe Present!!
C:\Windows\system32\drivers\downld Present!!
+- Presence des fichiers dans C:\Users\Cyrille\AppData\Roaming
C:\Users\Cyrille\AppData\Roaming\m\flec006.exe Present!!
C:\Users\Cyrille\AppData\Roaming\m\list.oct Present!!
C:\Users\Cyrille\AppData\Roaming\m\data.oct Present!!
C:\Users\Cyrille\AppData\Roaming\m\srvlist.oct Present!!
C:\Users\Cyrille\AppData\Roaming\m\shared Present!!
C:\Users\Cyrille\AppData\Roaming\m Present!!
+- Registre :
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
LogitechCommunicationsManager REG_SZ "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
StartCCC REG_SZ C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
TrueImageMonitor.exe REG_SZ C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
AcronisTimounterMonitor REG_SZ C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
Acronis Scheduler2 Service REG_SZ "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
RemoteControl REG_SZ "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
AVG8_TRAY REG_SZ C:\PROGRA~1\AVG\AVG8\avgtray.exe
avast! REG_SZ "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
ISUSPM Startup REG_SZ C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe -startup
mceguuo REG_SZ "c:\users\cyrille\appdata\local\mceguuo.exe" mceguuo
BitTorrent DNA REG_SZ "C:\Program Files\DNA\btdna.exe"
msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\CLSID
+- Registre, recherche Srosa :
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
NextInstance REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
NextInstance REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Type REG_DWORD 0x1
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x0
ImagePath REG_EXPAND_SZ \??\C:\Windows\system32\drivers\srosa.sys
DisplayName REG_SZ Megadrv3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Type REG_DWORD 0x1
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x0
ImagePath REG_EXPAND_SZ \??\C:\Windows\system32\drivers\srosa.sys
DisplayName REG_SZ Megadrv3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Type REG_DWORD 0x1
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x0
ImagePath REG_EXPAND_SZ \??\C:\Windows\system32\drivers\srosa.sys
DisplayName REG_SZ Megadrv3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa\Enum
HKEY_CURRENT_USER\Software\DateTime4
uid REG_SZ 93141896
port REG_DWORD 0x3ded
wdrn REG_DWORD 0x1
HKEY_CURRENT_USER\Software\FirtR
Fir076syj0Run REG_DWORD 0x1
HKEY_CURRENT_USER\Software\FirstRRRun
First12Ru123n REG_DWORD 0x1
HKEY_CURRENT_USER\Software\MuleAppData
ListTime REG_DWORD 0x1c
FileTime REG_DWORD 0x1c
ServerTime REG_DWORD 0x1c
! Recherche realisée avec success !
Recherche executée le 28/08/2008 a 12:15:00,90
dans l'attente de reponses...
** Rapport FindyKill **
+- Presence des fichiers dans C:
+- Presence des fichiers dans C:\Windows\Prefetch
C:\Windows\Prefetch\WINTEMS.EXE-????????.pf Present!!
C:\Windows\Prefetch\MDELK.EXE-????????.pf Present!!
C:\Windows\Prefetch\FLEC006.EXE-????????.pf Present!!
+- Presence des fichiers dans C:\Windows\system32
C:\Windows\system32\mdelk.exe Present!!
C:\Windows\system32\wintems.exe Present!!
C:\Windows\system32\ban_list.txt Present!!
+- Presence des fichiers dans C:\Windows\system32\drivers
C:\Windows\system32\drivers\mdelk.exe Present!!
C:\Windows\system32\drivers\srosa.sys Present!!
C:\Windows\system32\drivers\hldrrr.exe Present!!
C:\Windows\system32\drivers\downld Present!!
+- Presence des fichiers dans C:\Users\Cyrille\AppData\Roaming
C:\Users\Cyrille\AppData\Roaming\m\flec006.exe Present!!
C:\Users\Cyrille\AppData\Roaming\m\list.oct Present!!
C:\Users\Cyrille\AppData\Roaming\m\data.oct Present!!
C:\Users\Cyrille\AppData\Roaming\m\srvlist.oct Present!!
C:\Users\Cyrille\AppData\Roaming\m\shared Present!!
C:\Users\Cyrille\AppData\Roaming\m Present!!
+- Registre :
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
LogitechCommunicationsManager REG_SZ "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
LogitechQuickCamRibbon REG_SZ "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
StartCCC REG_SZ C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
TrueImageMonitor.exe REG_SZ C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
AcronisTimounterMonitor REG_SZ C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
Acronis Scheduler2 Service REG_SZ "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
RemoteControl REG_SZ "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
AVG8_TRAY REG_SZ C:\PROGRA~1\AVG\AVG8\avgtray.exe
avast! REG_SZ "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ehTray.exe REG_SZ C:\Windows\ehome\ehTray.exe
ISUSPM Startup REG_SZ C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe -startup
mceguuo REG_SZ "c:\users\cyrille\appdata\local\mceguuo.exe" mceguuo
BitTorrent DNA REG_SZ "C:\Program Files\DNA\btdna.exe"
msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\CLSID
+- Registre, recherche Srosa :
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
NextInstance REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
NextInstance REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Type REG_DWORD 0x1
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x0
ImagePath REG_EXPAND_SZ \??\C:\Windows\system32\drivers\srosa.sys
DisplayName REG_SZ Megadrv3
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Type REG_DWORD 0x1
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x0
ImagePath REG_EXPAND_SZ \??\C:\Windows\system32\drivers\srosa.sys
DisplayName REG_SZ Megadrv3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Type REG_DWORD 0x1
Start REG_DWORD 0x1
ErrorControl REG_DWORD 0x0
ImagePath REG_EXPAND_SZ \??\C:\Windows\system32\drivers\srosa.sys
DisplayName REG_SZ Megadrv3
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa\Enum
HKEY_CURRENT_USER\Software\DateTime4
uid REG_SZ 93141896
port REG_DWORD 0x3ded
wdrn REG_DWORD 0x1
HKEY_CURRENT_USER\Software\FirtR
Fir076syj0Run REG_DWORD 0x1
HKEY_CURRENT_USER\Software\FirstRRRun
First12Ru123n REG_DWORD 0x1
HKEY_CURRENT_USER\Software\MuleAppData
ListTime REG_DWORD 0x1c
FileTime REG_DWORD 0x1c
ServerTime REG_DWORD 0x1c
! Recherche realisée avec success !
Recherche executée le 28/08/2008 a 12:15:00,90
dans l'attente de reponses...
réouvre findykill,
choisi cette fois ci l option 2 (suppression)
il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"
un rapport va s ouvrir, post le dans ta prochaine réponse stp
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
choisi cette fois ci l option 2 (suppression)
il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"
un rapport va s ouvrir, post le dans ta prochaine réponse stp
Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
Voila le second rapport, merci de votre aide
/!\..Des fichiers ont été supprimé au 1er redémarrage../!\
/!\..... NETTOYAGE ...../!\
+- Suppression des fichiers dans C:
+- Suppression des fichiers dans C:\Windows\Prefetch
Supprime ! de C:\Windows\Prefetch\MDELK.EXE-????????.pf
Supprime ! de C:\Windows\Prefetch\FLEC006.EXE-????????.pf
+- Suppression des fichiers dans C:\Windows\system32
Supprime ! de C:\Windows\system32\mdelk.exe
Supprime ! de C:\Windows\system32\wintems.exe
Echec de la supression!! C:\Windows\system32\wintems.exe
Supprime ! de C:\Windows\system32\ban_list.txt
+- Suppression des fichiers dans C:\Windows\system32\drivers
Supprime ! de C:\Windows\system32\drivers\srosa.sys
Supprime ! de C:\Windows\system32\drivers\hldrrr.exe
Echec de la supression!! C:\Windows\system32\drivers\hldrrr.exe
Supprime ! de C:\Windows\system32\drivers\downld
+- Suppression des fichiers dans C:\Users\Cyrille\AppData\Roaming
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\flec006.exe
Echec de la supression!! C:\Users\Cyrille\AppData\Roaming\m\flec006.exe
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\list.oct
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\data.oct
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\srvlist.oct
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\shared
/!\..Des fichiers ont été supprimé au 1er redémarrage../!\
/!\..... NETTOYAGE ...../!\
+- Suppression des fichiers dans C:
+- Suppression des fichiers dans C:\Windows\Prefetch
Supprime ! de C:\Windows\Prefetch\MDELK.EXE-????????.pf
Supprime ! de C:\Windows\Prefetch\FLEC006.EXE-????????.pf
+- Suppression des fichiers dans C:\Windows\system32
Supprime ! de C:\Windows\system32\mdelk.exe
Supprime ! de C:\Windows\system32\wintems.exe
Echec de la supression!! C:\Windows\system32\wintems.exe
Supprime ! de C:\Windows\system32\ban_list.txt
+- Suppression des fichiers dans C:\Windows\system32\drivers
Supprime ! de C:\Windows\system32\drivers\srosa.sys
Supprime ! de C:\Windows\system32\drivers\hldrrr.exe
Echec de la supression!! C:\Windows\system32\drivers\hldrrr.exe
Supprime ! de C:\Windows\system32\drivers\downld
+- Suppression des fichiers dans C:\Users\Cyrille\AppData\Roaming
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\flec006.exe
Echec de la supression!! C:\Users\Cyrille\AppData\Roaming\m\flec006.exe
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\list.oct
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\data.oct
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\srvlist.oct
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\shared
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Il me dit que le nettoyage et effectué, qu'il va ouvrir le rapport mais rien depuis 5 minutes,c'est normal?
sinon ferme la fentre
ensuite va dans ordinateur
entre dans le disque C
post le rapport FindyKill.txt en entier stp
ensuite va dans ordinateur
entre dans le disque C
post le rapport FindyKill.txt en entier stp
** Rapport FindyKill **
/!\..Des fichiers ont été supprimé au 1er redémarrage../!\
/!\..... NETTOYAGE ...../!\
+- Suppression des fichiers dans C:
+- Suppression des fichiers dans C:\Windows\Prefetch
+- Suppression des fichiers dans C:\Windows\system32
Supprime ! de C:\Windows\system32\wintems.exe
+- Suppression des fichiers dans C:\Windows\system32\drivers
Supprime ! de C:\Windows\system32\drivers\hldrrr.exe
+- Suppression des fichiers dans C:\Users\Cyrille\AppData\Roaming
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\flec006.exe
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m
+- Suppression des clefs du registre..
+- Suppression des clefs du registre effectuée !
/!\..... vERIFICATION...../!\
+- Recherche des fichiers dans C:
+- Recherche des fichiers dans C:\Windows\Prefetch
+- Recherche des fichiers dans C:\Windows\system32
+- Recherche des fichiers dans C:\Windows\system32\drivers
+- Recherche des fichiers dans C:\Users\Cyrille\AppData\Roaming
+- Affichage des dosiers cachés réparé
+- Service de sécurité Windows redémarré
! Nettoyage realisé avec succès !
Suppression executée le 28/08/2008 a 13:04:34,10
/!\..Des fichiers ont été supprimé au 1er redémarrage../!\
/!\..... NETTOYAGE ...../!\
+- Suppression des fichiers dans C:
+- Suppression des fichiers dans C:\Windows\Prefetch
+- Suppression des fichiers dans C:\Windows\system32
Supprime ! de C:\Windows\system32\wintems.exe
+- Suppression des fichiers dans C:\Windows\system32\drivers
Supprime ! de C:\Windows\system32\drivers\hldrrr.exe
+- Suppression des fichiers dans C:\Users\Cyrille\AppData\Roaming
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m\flec006.exe
Supprime ! de C:\Users\Cyrille\AppData\Roaming\m
+- Suppression des clefs du registre..
+- Suppression des clefs du registre effectuée !
/!\..... vERIFICATION...../!\
+- Recherche des fichiers dans C:
+- Recherche des fichiers dans C:\Windows\Prefetch
+- Recherche des fichiers dans C:\Windows\system32
+- Recherche des fichiers dans C:\Windows\system32\drivers
+- Recherche des fichiers dans C:\Users\Cyrille\AppData\Roaming
+- Affichage des dosiers cachés réparé
+- Service de sécurité Windows redémarré
! Nettoyage realisé avec succès !
Suppression executée le 28/08/2008 a 13:04:34,10
ok parfait
Télécharge HijackThis ici :
-> Fais un clic droit sur un des liens et choisi enregistrer la cible sous .... le bureau
-> http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
-> ftp://ftp.commentcamarche.com/download/HJTInstall.exe
-> Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
-> Clique sur Install ensuite sur I Accept
-> Clique sur Do a scan system and save log file
-> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse
apres on fait le point sur le pc , regarde si ton antivirus est ok ou pas et dis moi
Télécharge HijackThis ici :
-> Fais un clic droit sur un des liens et choisi enregistrer la cible sous .... le bureau
-> http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
-> ftp://ftp.commentcamarche.com/download/HJTInstall.exe
-> Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
-> Clique sur Install ensuite sur I Accept
-> Clique sur Do a scan system and save log file
-> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse
apres on fait le point sur le pc , regarde si ton antivirus est ok ou pas et dis moi
Voila
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:23:28, on 28/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.ustart.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {00BC28D1-8F23-451B-AB95-7D976C608277} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {61D1EA3E-A930-4BEB-B16B-D7212B5C5A4C} - (no file)
O3 - Toolbar: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
O3 - Toolbar: MEDIADICO Familial - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - C:\Program Files\LAventure\MDToolbar\MdToolbar.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4797] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC863] cmd /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6041] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe -startup
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB8401] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3974] cmd /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7775] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC3A7D37-FB8A-4489-B41A-F3E0A7E8E038}: NameServer = 89.2.0.1,89.2.0.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O21 - SSODL: okmdepgb - {CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:23:28, on 28/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.ustart.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {00BC28D1-8F23-451B-AB95-7D976C608277} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {61D1EA3E-A930-4BEB-B16B-D7212B5C5A4C} - (no file)
O3 - Toolbar: securedie Toolbar - {cd36797a-70f3-4acd-8825-623d3b896881} - C:\Program Files\securedie\tbsecu.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll (file missing)
O3 - Toolbar: MEDIADICO Familial - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - C:\Program Files\LAventure\MDToolbar\MdToolbar.dll (file missing)
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\avgtoolbar.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4797] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC863] cmd /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6041] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe -startup
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB8401] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3974] cmd /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7775] command /c del "C:\Users\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\Documents and Settings\Cyrille\Desktop\Windows.old\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{EC3A7D37-FB8A-4489-B41A-F3E0A7E8E038}: NameServer = 89.2.0.1,89.2.0.2
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (file missing)
O21 - SSODL: okmdepgb - {CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
ok
voila le suite :
1) désinstal spybot, tu le réinstallera apres désinfection
2) instal un antivirus , je te conseil antivir , gratuit en anglais mais simple
Telecharge et instales l'antivirus Antivir Personal Edition Classic :
->https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html
tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/
tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59
3) redémarre les services :
Démarrer >accesoire puis executer > tape : services.msc
- double Clic sur le service cité - windows defender
type de démarrge le mettre en automatique
clic sur appliquer
en haut a gauche clic sur demarrer le service
idem pour parefeu windows, windows upadate et centre de securité
ensuite :
Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique sur combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
voila le suite :
1) désinstal spybot, tu le réinstallera apres désinfection
2) instal un antivirus , je te conseil antivir , gratuit en anglais mais simple
Telecharge et instales l'antivirus Antivir Personal Edition Classic :
->https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html
tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/
tuto : http://www.swl1f.net/viewtopic.php?f=14&t=59
3) redémarre les services :
Démarrer >accesoire puis executer > tape : services.msc
- double Clic sur le service cité - windows defender
type de démarrge le mettre en automatique
clic sur appliquer
en haut a gauche clic sur demarrer le service
idem pour parefeu windows, windows upadate et centre de securité
ensuite :
Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique sur combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
Voila le rapport, c'etait pas trop long pour toi j'espère
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2093 [GMT 2:00]
Endroit: C:\Users\Cyrille\Downloads\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\0.exe
C:\Program Files\PCHealthCenter\0.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Users\Cyrille\AppData\Local\mceguuo.dat
C:\Users\Cyrille\AppData\Local\mceguuo.exe
C:\Users\Cyrille\AppData\Local\mceguuo_nav.dat
C:\Users\Cyrille\AppData\Local\mceguuo_navps.dat
C:\Windows\eqbx.exe
C:\Windows\system32\aeeadae7_z.dll
C:\Windows\system32\bfbnsdpi.ini
C:\Windows\system32\fwcomgif.ini
C:\Windows\system32\gddgsxkd.ini
C:\Windows\system32\lirkwkmf.ini
C:\Windows\system32\olvhpmng.ini
C:\Windows\system32\rtl60.bpl
C:\Windows\system32\vnplpiey.ini
C:\Windows\system32\xxxnphmn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 12:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\DNA
2008-08-28 11:33 --------- d-----w C:\ProgramData\Avira
2008-08-28 11:33 --------- d-----w C:\Program Files\Avira
2008-08-28 11:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-28 11:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-28 11:22 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 05:32 --------- d-----w C:\ProgramData\Google Updater
2008-08-28 00:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-28 00:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-28 00:44 --------- d-----w C:\Program Files\Rockstar Games
2008-08-27 23:23 --------- d-----w C:\ProgramData\Lavasoft
2008-08-26 19:30 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Azureus
2008-08-25 22:03 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-08-25 22:01 --------- d-----w C:\ProgramData\avg8
2008-08-25 21:57 --------- d-----w C:\Program Files\eChanblard
2008-08-24 14:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 14:38 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InstallShield
2008-08-23 10:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BitTorrent
2008-08-22 21:02 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 22:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 15:23 --------- d-----w C:\Program Files\BitTorrent
2008-08-14 15:22 --------- d-----w C:\Program Files\DNA
2008-08-13 10:01 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 08:47 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-11 20:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\PeerNetworking
2008-08-09 22:11 --------- d-----w C:\ProgramData\Downloaded Installations
2008-08-09 09:07 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-09 00:02 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-07 22:55 --------- d-----w C:\Program Files\Runtime Software
2008-08-07 19:26 --------- d-----w C:\Program Files\Google
2008-08-06 11:56 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-05 10:30 --------- d-----w C:\Program Files\CyberLink
2008-08-03 10:34 --------- d-----w C:\Program Files\Ubisoft
2008-08-01 15:10 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-29 15:57 --------- d-----w C:\Program Files\FTPExpert
2008-07-28 00:32 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-07-28 00:13 --------- d-----w C:\Users\Cyrille\AppData\Roaming\STOIK
2008-07-25 22:21 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Acronis
2008-07-25 13:31 --------- d-----w C:\ProgramData\Acronis
2008-07-25 13:30 441,760 ----a-w C:\Windows\system32\drivers\timntr.sys
2008-07-25 13:30 44,384 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
2008-07-25 13:30 368,480 ----a-w C:\Windows\system32\drivers\tdrpman.sys
2008-07-25 13:30 132,224 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-07-25 13:30 --------- d-----w C:\Program Files\Common Files\Acronis
2008-07-25 13:30 --------- d-----w C:\Program Files\Acronis
2008-07-25 13:25 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-23 13:27 --------- d-----w C:\Program Files\SoftwarePassport
2008-07-23 13:26 --------- d-----w C:\Program Files\Mindscape
2008-07-22 11:34 --------- d-----w C:\Program Files\IZArc
2008-07-22 11:09 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-07-21 18:08 --------- d-----w C:\ProgramData\InstallShield
2008-07-21 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 23:50 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-19 23:49 --------- d-----w C:\Program Files\Java
2008-07-19 23:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\LimeWire
2008-07-18 23:47 --------- d-----w C:\Program Files\Common Files\Java
2008-07-18 18:39 587,264 ---ha-w C:\Windows\WLXPGSS.SCR
2008-07-15 10:43 --------- d-----w C:\Program Files\SlySoft
2008-07-14 14:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\GRETECH
2008-07-14 14:48 --------- d-----w C:\ProgramData\GRETECH
2008-07-14 14:47 --------- d-----w C:\Program Files\GRETECH
2008-07-12 20:38 --------- d-----w C:\Program Files\Creative
2008-07-12 20:37 --------- d-----w C:\Program Files\Mafia
2008-07-11 22:13 --------- d-----w C:\Program Files\Piratrax
2008-07-11 18:02 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-11 18:02 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-07-11 17:41 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer
2008-07-11 17:31 --------- d-----w C:\Program Files\Registry Easy
2008-07-11 15:31 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-11 14:39 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer Pro
2008-07-10 23:37 --------- d-----w C:\Users\Cyrille\AppData\Roaming\fltk.org
2008-07-10 22:35 --------- d-----w C:\Program Files\RomStation
2008-07-10 09:16 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InterTrust
2008-07-10 09:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 18:08 --------- d-----w C:\ProgramData\Ubisoft
2008-07-09 11:27 --------- d-----w C:\Program Files\MSBuild
2008-07-09 11:27 --------- d-----w C:\Program Files\Microsoft Works
2008-07-09 11:26 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-09 00:17 --------- d-----w C:\ProgramData\Symantec
2008-07-08 16:30 --------- d-----w C:\Program Files\FolderSize
2008-07-08 12:32 --------- d-----w C:\Program Files\Defraggler
2008-07-07 23:16 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-07 23:12 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 23:00 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Auslogics
2008-07-07 23:00 --------- d-----w C:\Program Files\Auslogics
2008-07-07 21:47 --------- d-----w C:\Program Files\Project64 1.6
2008-07-07 18:23 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Download Manager
2008-07-05 09:26 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Uniblue
2008-07-03 18:29 --------- d-----w C:\Program Files\KONAMI
2008-07-03 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ESTsoft
2008-07-03 14:04 --------- d-----w C:\Program Files\ESTsoft
2008-07-02 16:22 --------- d-----w C:\Program Files\securedie
2008-07-02 15:45 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ImgBurn
2008-07-02 11:02 2,560 ---ha-w C:\Windows\_MSRSTRT.EXE
2008-07-02 11:01 --------- d-----w C:\Program Files\Secured eMule
2008-07-02 10:56 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ErrorSmart
2008-07-02 10:43 --------- d-----w C:\Program Files\Azureus
2008-07-02 08:34 --------- d-----w C:\Program Files\Common Files\Logitech
2008-07-02 08:01 --------- d-----w C:\ProgramData\PC Drivers HeadQuarters
2008-07-02 07:32 --------- d-----w C:\Program Files\Conduit
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
2007-09-06 12:28 1453080 -ra------ C:\Program Files\securedie\tbsecu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe" [2004-08-09 06:03 221184]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-14 17:22 341824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB8401"="command" [X]
"SpybotDeletingD3974"="del" [X]
"SpybotDeletingB7775"="command" [X]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-23 01:52 2616512]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-22 22:02 909096]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-22 19:26 136472]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-08-28 12:42 75392]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA4797"="command" [X]
"SpybotDeletingC863"="del" [X]
"SpybotDeletingA6041"="command" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2583701152-1007577926-4045379130-1000]
"EnableNotificationsRef"=dword:00000005
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{43D61948-2FC2-452E-838C-C25AAE296EC1}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= UDP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"UDP Query User{2342DF4A-153D-4830-9C23-0C3C4645E7A4}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= TCP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"{7079FD9A-53B0-4EA8-B925-4E1A3A992DD6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{62A2CDC3-7680-44CD-BB01-E95B2A5D6588}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9C6DA761-0EB3-4810-B019-01E03B5725E4}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{0D43D2C3-E070-42B7-9AC7-E5032EB92840}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{E10AE7DB-CA15-4A3C-ACE1-FC43B85C0FB5}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"{7B128BC2-3370-4EE9-8A83-EFFFBB69D5B3}"= UDP:443:TCP port 443 ooVoo
"{F7156248-62DA-4ED5-BB7B-CEACAC555968}"= TCP:443:UDP port 443 ooVoo
"{56144CB5-78C5-4244-8D6A-B1D8572E18BB}"= UDP:37674:TCP port 37674 ooVoo
"{5E17F1AE-ABE1-4605-9F88-BC5E204052E1}"= TCP:37674:UDP port 37674 ooVoo
"{DC1748BA-253F-4712-AA6A-BBE29F948CD6}"= TCP:37675:UDP port 37675 ooVoo
"TCP Query User{54CF68EC-BBD5-4934-ABDA-5B2F46C14945}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{59DC3A1F-E9ED-4A07-8FC8-F51AE997B755}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe:ooVoo
"TCP Query User{A833043F-809A-4EA7-A161-364CF42D3F38}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F54341D5-414A-481E-BA1A-4614A7C7F54A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{56C5105B-0218-4F53-9C09-1CE3CCAC1985}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{533237A3-47BB-4BA7-9F17-DACE5A4858DD}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{EC19D54E-7FBD-4F60-A93F-F6E44C23095A}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E9A6FC66-8627-498F-B919-06EC708C0CA9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E152F4BB-2D84-41E9-9839-E11C643BD5A3}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= UDP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5414075E-02BB-4EEE-AD54-93EFC6C2E07B}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= TCP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"{EF3DC8C4-97DA-406F-B03B-FECFDE85339B}"= UDP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{9F6B3A59-7009-4043-8144-3266EBB3C92B}"= TCP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{8B2BCDC4-6CEF-465B-B84A-7220170199D1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A3215C7B-3E1D-4C62-A655-17F002FFF498}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5E356094-14A8-49E8-8ABC-C8B2F40ADF55}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C3A23C3B-4971-411E-9BBD-AA6B41E04A12}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{776116FA-A024-4AA7-9F66-8C236BAFB58F}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{A39051B9-2DE9-4144-B971-DD0C66A89475}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"TCP Query User{39EBCCC4-9CE8-4A93-9013-CF1C387629BC}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= UDP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{A235952F-1E04-4DE8-AB59-74BC28E8DC9B}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= TCP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"{E5769D4F-0E2B-4322-895A-1157D46E4F36}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E4C6AA67-AF67-4F26-8FCE-6E1368E040C9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FCE88D98-9C06-4116-BEB9-F41580EA5D3A}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{C91B18AF-60AB-4054-AD66-F704FE73B35B}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{1B5AD8FD-D1EF-486F-8DCB-1AF27C1BC9EE}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{421C8B02-767B-48FF-AF09-14E63734AEF0}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{40737326-508B-40B2-A9CA-B2D38F7E2CF3}"= UDP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
"{650F0099-5465-410D-9B77-D0ECC8D809F7}"= TCP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-07-25 15:30]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-04-30 17:39]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-23 02:22]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-27 04:00]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8ebe45-5394-11dd-aa14-001d60b428b0}]
\shell\AutoRun\command - K:\autorun.exe
*Newly Created Service* - SSMDRV
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-21 C:\Windows\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-07-03 C:\Windows\Tasks\Schedule Task Weekly.job
- C:\Program Files\Registry Easy\RE.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-mceguuo - c:\users\cyrille\appdata\local\mceguuo.exe
HKLM-Run-AVG8_TRAY - C:\PROGRA~1\AVG\AVG8\avgtray.exe
SSODL-okmdepgb-{CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Cyrille\AppData\Roaming\Mozilla\Firefox\Profiles\4y7i5rfg.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1396957&SearchSource=3&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.ustart.org
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1249.1854\npCIDetect11.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
.:\\\(0!\|0\\0\)
C:\\Windows\\system32\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\config\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\csrss.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\drivers\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\hal.dll\\\(0!\|0\\0\)
C:\\Windows\\system32\\lsass.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\ntdll.dll\\\(0!\|0\\0\)
C:\\Windows\\system32\\services.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\smss.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\svchost.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\userinit.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\wbem\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\winlogon.exe\\\(0!\|0\\0\)
C:\\boot.ini\\\(0!\|0\\0\)
C:\\ntdetect.com\\\(0!\|0\\0\)
C:\\ntldr\\\(0!\|0\\0\)
C:\\Windows\\\(\\\|0!\|0\\0\)
C:\\Windows\\explorer.exe\\\(0!\|0\\0\)
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2093 [GMT 2:00]
Endroit: C:\Users\Cyrille\Downloads\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\0.exe
C:\Program Files\PCHealthCenter\0.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Users\Cyrille\AppData\Local\mceguuo.dat
C:\Users\Cyrille\AppData\Local\mceguuo.exe
C:\Users\Cyrille\AppData\Local\mceguuo_nav.dat
C:\Users\Cyrille\AppData\Local\mceguuo_navps.dat
C:\Windows\eqbx.exe
C:\Windows\system32\aeeadae7_z.dll
C:\Windows\system32\bfbnsdpi.ini
C:\Windows\system32\fwcomgif.ini
C:\Windows\system32\gddgsxkd.ini
C:\Windows\system32\lirkwkmf.ini
C:\Windows\system32\olvhpmng.ini
C:\Windows\system32\rtl60.bpl
C:\Windows\system32\vnplpiey.ini
C:\Windows\system32\xxxnphmn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 12:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\DNA
2008-08-28 11:33 --------- d-----w C:\ProgramData\Avira
2008-08-28 11:33 --------- d-----w C:\Program Files\Avira
2008-08-28 11:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-28 11:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-28 11:22 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 05:32 --------- d-----w C:\ProgramData\Google Updater
2008-08-28 00:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-28 00:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-28 00:44 --------- d-----w C:\Program Files\Rockstar Games
2008-08-27 23:23 --------- d-----w C:\ProgramData\Lavasoft
2008-08-26 19:30 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Azureus
2008-08-25 22:03 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-08-25 22:01 --------- d-----w C:\ProgramData\avg8
2008-08-25 21:57 --------- d-----w C:\Program Files\eChanblard
2008-08-24 14:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 14:38 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InstallShield
2008-08-23 10:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BitTorrent
2008-08-22 21:02 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 22:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 15:23 --------- d-----w C:\Program Files\BitTorrent
2008-08-14 15:22 --------- d-----w C:\Program Files\DNA
2008-08-13 10:01 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 08:47 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-11 20:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\PeerNetworking
2008-08-09 22:11 --------- d-----w C:\ProgramData\Downloaded Installations
2008-08-09 09:07 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-09 00:02 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-07 22:55 --------- d-----w C:\Program Files\Runtime Software
2008-08-07 19:26 --------- d-----w C:\Program Files\Google
2008-08-06 11:56 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-05 10:30 --------- d-----w C:\Program Files\CyberLink
2008-08-03 10:34 --------- d-----w C:\Program Files\Ubisoft
2008-08-01 15:10 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-29 15:57 --------- d-----w C:\Program Files\FTPExpert
2008-07-28 00:32 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-07-28 00:13 --------- d-----w C:\Users\Cyrille\AppData\Roaming\STOIK
2008-07-25 22:21 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Acronis
2008-07-25 13:31 --------- d-----w C:\ProgramData\Acronis
2008-07-25 13:30 441,760 ----a-w C:\Windows\system32\drivers\timntr.sys
2008-07-25 13:30 44,384 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
2008-07-25 13:30 368,480 ----a-w C:\Windows\system32\drivers\tdrpman.sys
2008-07-25 13:30 132,224 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-07-25 13:30 --------- d-----w C:\Program Files\Common Files\Acronis
2008-07-25 13:30 --------- d-----w C:\Program Files\Acronis
2008-07-25 13:25 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-23 13:27 --------- d-----w C:\Program Files\SoftwarePassport
2008-07-23 13:26 --------- d-----w C:\Program Files\Mindscape
2008-07-22 11:34 --------- d-----w C:\Program Files\IZArc
2008-07-22 11:09 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-07-21 18:08 --------- d-----w C:\ProgramData\InstallShield
2008-07-21 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 23:50 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-19 23:49 --------- d-----w C:\Program Files\Java
2008-07-19 23:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\LimeWire
2008-07-18 23:47 --------- d-----w C:\Program Files\Common Files\Java
2008-07-18 18:39 587,264 ---ha-w C:\Windows\WLXPGSS.SCR
2008-07-15 10:43 --------- d-----w C:\Program Files\SlySoft
2008-07-14 14:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\GRETECH
2008-07-14 14:48 --------- d-----w C:\ProgramData\GRETECH
2008-07-14 14:47 --------- d-----w C:\Program Files\GRETECH
2008-07-12 20:38 --------- d-----w C:\Program Files\Creative
2008-07-12 20:37 --------- d-----w C:\Program Files\Mafia
2008-07-11 22:13 --------- d-----w C:\Program Files\Piratrax
2008-07-11 18:02 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-11 18:02 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-07-11 17:41 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer
2008-07-11 17:31 --------- d-----w C:\Program Files\Registry Easy
2008-07-11 15:31 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-11 14:39 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer Pro
2008-07-10 23:37 --------- d-----w C:\Users\Cyrille\AppData\Roaming\fltk.org
2008-07-10 22:35 --------- d-----w C:\Program Files\RomStation
2008-07-10 09:16 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InterTrust
2008-07-10 09:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 18:08 --------- d-----w C:\ProgramData\Ubisoft
2008-07-09 11:27 --------- d-----w C:\Program Files\MSBuild
2008-07-09 11:27 --------- d-----w C:\Program Files\Microsoft Works
2008-07-09 11:26 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-09 00:17 --------- d-----w C:\ProgramData\Symantec
2008-07-08 16:30 --------- d-----w C:\Program Files\FolderSize
2008-07-08 12:32 --------- d-----w C:\Program Files\Defraggler
2008-07-07 23:16 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-07 23:12 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 23:00 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Auslogics
2008-07-07 23:00 --------- d-----w C:\Program Files\Auslogics
2008-07-07 21:47 --------- d-----w C:\Program Files\Project64 1.6
2008-07-07 18:23 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Download Manager
2008-07-05 09:26 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Uniblue
2008-07-03 18:29 --------- d-----w C:\Program Files\KONAMI
2008-07-03 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ESTsoft
2008-07-03 14:04 --------- d-----w C:\Program Files\ESTsoft
2008-07-02 16:22 --------- d-----w C:\Program Files\securedie
2008-07-02 15:45 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ImgBurn
2008-07-02 11:02 2,560 ---ha-w C:\Windows\_MSRSTRT.EXE
2008-07-02 11:01 --------- d-----w C:\Program Files\Secured eMule
2008-07-02 10:56 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ErrorSmart
2008-07-02 10:43 --------- d-----w C:\Program Files\Azureus
2008-07-02 08:34 --------- d-----w C:\Program Files\Common Files\Logitech
2008-07-02 08:01 --------- d-----w C:\ProgramData\PC Drivers HeadQuarters
2008-07-02 07:32 --------- d-----w C:\Program Files\Conduit
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
2007-09-06 12:28 1453080 -ra------ C:\Program Files\securedie\tbsecu.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd36797a-70f3-4acd-8825-623d3b896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"= "C:\Program Files\securedie\tbsecu.dll" [2007-09-06 12:28 1453080]
[HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe" [2004-08-09 06:03 221184]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-14 17:22 341824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB8401"="command" [X]
"SpybotDeletingD3974"="del" [X]
"SpybotDeletingB7775"="command" [X]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-23 01:52 2616512]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-22 22:02 909096]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-22 19:26 136472]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-08-28 12:42 75392]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA4797"="command" [X]
"SpybotDeletingC863"="del" [X]
"SpybotDeletingA6041"="command" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2583701152-1007577926-4045379130-1000]
"EnableNotificationsRef"=dword:00000005
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{43D61948-2FC2-452E-838C-C25AAE296EC1}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= UDP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"UDP Query User{2342DF4A-153D-4830-9C23-0C3C4645E7A4}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= TCP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"{7079FD9A-53B0-4EA8-B925-4E1A3A992DD6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{62A2CDC3-7680-44CD-BB01-E95B2A5D6588}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9C6DA761-0EB3-4810-B019-01E03B5725E4}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{0D43D2C3-E070-42B7-9AC7-E5032EB92840}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{E10AE7DB-CA15-4A3C-ACE1-FC43B85C0FB5}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"{7B128BC2-3370-4EE9-8A83-EFFFBB69D5B3}"= UDP:443:TCP port 443 ooVoo
"{F7156248-62DA-4ED5-BB7B-CEACAC555968}"= TCP:443:UDP port 443 ooVoo
"{56144CB5-78C5-4244-8D6A-B1D8572E18BB}"= UDP:37674:TCP port 37674 ooVoo
"{5E17F1AE-ABE1-4605-9F88-BC5E204052E1}"= TCP:37674:UDP port 37674 ooVoo
"{DC1748BA-253F-4712-AA6A-BBE29F948CD6}"= TCP:37675:UDP port 37675 ooVoo
"TCP Query User{54CF68EC-BBD5-4934-ABDA-5B2F46C14945}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{59DC3A1F-E9ED-4A07-8FC8-F51AE997B755}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe:ooVoo
"TCP Query User{A833043F-809A-4EA7-A161-364CF42D3F38}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F54341D5-414A-481E-BA1A-4614A7C7F54A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{56C5105B-0218-4F53-9C09-1CE3CCAC1985}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{533237A3-47BB-4BA7-9F17-DACE5A4858DD}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{EC19D54E-7FBD-4F60-A93F-F6E44C23095A}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E9A6FC66-8627-498F-B919-06EC708C0CA9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E152F4BB-2D84-41E9-9839-E11C643BD5A3}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= UDP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5414075E-02BB-4EEE-AD54-93EFC6C2E07B}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= TCP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"{EF3DC8C4-97DA-406F-B03B-FECFDE85339B}"= UDP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{9F6B3A59-7009-4043-8144-3266EBB3C92B}"= TCP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{8B2BCDC4-6CEF-465B-B84A-7220170199D1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A3215C7B-3E1D-4C62-A655-17F002FFF498}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5E356094-14A8-49E8-8ABC-C8B2F40ADF55}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C3A23C3B-4971-411E-9BBD-AA6B41E04A12}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{776116FA-A024-4AA7-9F66-8C236BAFB58F}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{A39051B9-2DE9-4144-B971-DD0C66A89475}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"TCP Query User{39EBCCC4-9CE8-4A93-9013-CF1C387629BC}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= UDP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{A235952F-1E04-4DE8-AB59-74BC28E8DC9B}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= TCP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"{E5769D4F-0E2B-4322-895A-1157D46E4F36}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E4C6AA67-AF67-4F26-8FCE-6E1368E040C9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FCE88D98-9C06-4116-BEB9-F41580EA5D3A}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{C91B18AF-60AB-4054-AD66-F704FE73B35B}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{1B5AD8FD-D1EF-486F-8DCB-1AF27C1BC9EE}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{421C8B02-767B-48FF-AF09-14E63734AEF0}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{40737326-508B-40B2-A9CA-B2D38F7E2CF3}"= UDP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
"{650F0099-5465-410D-9B77-D0ECC8D809F7}"= TCP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-07-25 15:30]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-04-30 17:39]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-23 02:22]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-27 04:00]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8ebe45-5394-11dd-aa14-001d60b428b0}]
\shell\AutoRun\command - K:\autorun.exe
*Newly Created Service* - SSMDRV
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-21 C:\Windows\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-07-03 C:\Windows\Tasks\Schedule Task Weekly.job
- C:\Program Files\Registry Easy\RE.exe []
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-mceguuo - c:\users\cyrille\appdata\local\mceguuo.exe
HKLM-Run-AVG8_TRAY - C:\PROGRA~1\AVG\AVG8\avgtray.exe
SSODL-okmdepgb-{CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\Cyrille\AppData\Roaming\Mozilla\Firefox\Profiles\4y7i5rfg.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1396957&SearchSource=3&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.ustart.org
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1249.1854\npCIDetect11.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
.:\\\(0!\|0\\0\)
C:\\Windows\\system32\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\config\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\csrss.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\drivers\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\hal.dll\\\(0!\|0\\0\)
C:\\Windows\\system32\\lsass.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\ntdll.dll\\\(0!\|0\\0\)
C:\\Windows\\system32\\services.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\smss.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\svchost.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\userinit.exe\\\(0!\|0\\0\)
C:\\Windows\\system32\\wbem\\\(\\\|0!\|0\\0\)
C:\\Windows\\system32\\winlogon.exe\\\(0!\|0\\0\)
C:\\boot.ini\\\(0!\|0\\0\)
C:\\ntdetect.com\\\(0!\|0\\0\)
C:\\ntldr\\\(0!\|0\\0\)
C:\\Windows\\\(\\\|0!\|0\\0\)
C:\\Windows\\explorer.exe\\\(0!\|0\\0\)
Copie le texte ci-dessous :
File::
C:\Windows\_MSRSTRT.EXE
C:\ntdetect.com
Folder::
C:\Program Files\securedie
C:\Program Files\Conduit
C:\Program Files\Secured eMule
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd36797a-70f3-4acd-8825-623d3b896881}"=-
[-HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd36797a-70f3-4acd-8825-623d3b896881}"=-
[-HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"=-
[-HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB8401"=-
"SpybotDeletingD3974"=-
"SpybotDeletingB7775"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA4797"=-
"SpybotDeletingC863"=-
"SpybotDeletingA6041"=-
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
File::
C:\Windows\_MSRSTRT.EXE
C:\ntdetect.com
Folder::
C:\Program Files\securedie
C:\Program Files\Conduit
C:\Program Files\Secured eMule
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{cd36797a-70f3-4acd-8825-623d3b896881}"=-
[-HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd36797a-70f3-4acd-8825-623d3b896881}"=-
[-HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CD36797A-70F3-4ACD-8825-623D3B896881}"=-
[-HKEY_CLASSES_ROOT\clsid\{cd36797a-70f3-4acd-8825-623d3b896881}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingB8401"=-
"SpybotDeletingD3974"=-
"SpybotDeletingB7775"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA4797"=-
"SpybotDeletingC863"=-
"SpybotDeletingA6041"=-
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
ComboFix 08-08-27.05 - Cyrille 2008-08-28 15:11:19.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2200 [GMT 2:00]
Endroit: C:\Users\Cyrille\Downloads\ComboFix.exe
Command switches used :: C:\Users\Cyrille\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Windows\_MSRSTRT.EXE
C:\ntdetect.com :#:
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts\Alert.dll
C:\Program Files\Secured eMule
C:\Program Files\Secured eMule\secp.exe
C:\Program Files\securedie
C:\Program Files\securedie\INSTALL.LOG
C:\Program Files\securedie\tbsecu.dll
C:\Program Files\securedie\toolbar.cfg
C:\Program Files\securedie\UNWISE.EXE
C:\Windows\_MSRSTRT.EXE
.
---- Previous Run -------
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\[u]0/u.exe
C:\Program Files\PCHealthCenter\[u]0/u.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Users\Cyrille\AppData\Local\mceguuo.dat
C:\Users\Cyrille\AppData\Local\mceguuo.exe
C:\Users\Cyrille\AppData\Local\mceguuo_nav.dat
C:\Users\Cyrille\AppData\Local\mceguuo_navps.dat
C:\Windows\eqbx.exe
C:\Windows\system32\aeeadae7_z.dll
C:\Windows\system32\bfbnsdpi.ini
C:\Windows\system32\fwcomgif.ini
C:\Windows\system32\gddgsxkd.ini
C:\Windows\system32\lirkwkmf.ini
C:\Windows\system32\olvhpmng.ini
C:\Windows\system32\rtl60.bpl
C:\Windows\system32\vnplpiey.ini
C:\Windows\system32\xxxnphmn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\DNA
2008-08-28 12:51 --------- d-----w C:\Program Files\CCleaner
2008-08-28 11:33 --------- d-----w C:\ProgramData\Avira
2008-08-28 11:33 --------- d-----w C:\Program Files\Avira
2008-08-28 11:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-28 11:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-28 11:22 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 05:32 --------- d-----w C:\ProgramData\Google Updater
2008-08-28 00:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-28 00:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-28 00:44 --------- d-----w C:\Program Files\Rockstar Games
2008-08-27 23:23 --------- d-----w C:\ProgramData\Lavasoft
2008-08-26 19:30 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Azureus
2008-08-25 22:03 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-08-25 22:01 --------- d-----w C:\ProgramData\avg8
2008-08-25 21:57 --------- d-----w C:\Program Files\eChanblard
2008-08-24 14:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 14:38 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InstallShield
2008-08-23 10:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BitTorrent
2008-08-22 21:02 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 22:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 15:23 --------- d-----w C:\Program Files\BitTorrent
2008-08-14 15:22 --------- d-----w C:\Program Files\DNA
2008-08-13 10:01 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 08:47 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-11 20:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\PeerNetworking
2008-08-09 22:11 --------- d-----w C:\ProgramData\Downloaded Installations
2008-08-09 09:07 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-09 00:02 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-07 22:55 --------- d-----w C:\Program Files\Runtime Software
2008-08-07 19:26 --------- d-----w C:\Program Files\Google
2008-08-06 11:56 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-05 10:30 --------- d-----w C:\Program Files\CyberLink
2008-08-03 10:34 --------- d-----w C:\Program Files\Ubisoft
2008-08-01 15:10 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-29 15:57 --------- d-----w C:\Program Files\FTPExpert
2008-07-28 00:32 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-07-28 00:13 --------- d-----w C:\Users\Cyrille\AppData\Roaming\STOIK
2008-07-25 22:21 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Acronis
2008-07-25 13:31 --------- d-----w C:\ProgramData\Acronis
2008-07-25 13:30 441,760 ----a-w C:\Windows\system32\drivers\timntr.sys
2008-07-25 13:30 44,384 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
2008-07-25 13:30 368,480 ----a-w C:\Windows\system32\drivers\tdrpman.sys
2008-07-25 13:30 132,224 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-07-25 13:30 --------- d-----w C:\Program Files\Common Files\Acronis
2008-07-25 13:30 --------- d-----w C:\Program Files\Acronis
2008-07-25 13:25 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-23 13:27 --------- d-----w C:\Program Files\SoftwarePassport
2008-07-23 13:26 --------- d-----w C:\Program Files\Mindscape
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMSB1.BIN
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMS.BIN
2008-07-22 11:34 --------- d-----w C:\Program Files\IZArc
2008-07-22 11:09 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-07-21 18:08 --------- d-----w C:\ProgramData\InstallShield
2008-07-21 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 23:50 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-19 23:49 --------- d-----w C:\Program Files\Java
2008-07-19 23:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\LimeWire
2008-07-18 23:47 --------- d-----w C:\Program Files\Common Files\Java
2008-07-18 18:39 587,264 ---ha-w C:\Windows\WLXPGSS.SCR
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-07-15 10:43 --------- d-----w C:\Program Files\SlySoft
2008-07-14 14:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\GRETECH
2008-07-14 14:48 --------- d-----w C:\ProgramData\GRETECH
2008-07-14 14:47 --------- d-----w C:\Program Files\GRETECH
2008-07-12 20:38 --------- d-----w C:\Program Files\Creative
2008-07-12 20:37 --------- d-----w C:\Program Files\Mafia
2008-07-11 22:13 --------- d-----w C:\Program Files\Piratrax
2008-07-11 18:02 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-11 18:02 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-07-11 17:41 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer
2008-07-11 17:31 --------- d-----w C:\Program Files\Registry Easy
2008-07-11 15:31 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-11 14:39 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer Pro
2008-07-10 23:37 --------- d-----w C:\Users\Cyrille\AppData\Roaming\fltk.org
2008-07-10 22:35 --------- d-----w C:\Program Files\RomStation
2008-07-10 09:16 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InterTrust
2008-07-10 09:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 18:08 --------- d-----w C:\ProgramData\Ubisoft
2008-07-09 11:27 --------- d-----w C:\Program Files\MSBuild
2008-07-09 11:27 --------- d-----w C:\Program Files\Microsoft Works
2008-07-09 11:26 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-09 00:17 --------- d-----w C:\ProgramData\Symantec
2008-07-08 16:30 --------- d-----w C:\Program Files\FolderSize
2008-07-08 12:32 --------- d-----w C:\Program Files\Defraggler
2008-07-07 23:16 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-07 23:12 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 23:00 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Auslogics
2008-07-07 23:00 --------- d-----w C:\Program Files\Auslogics
2008-07-07 21:47 --------- d-----w C:\Program Files\Project64 1.6
2008-07-07 18:23 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Download Manager
2008-07-05 09:26 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Uniblue
2008-07-03 18:47 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-07-03 18:29 --------- d-----w C:\Program Files\KONAMI
2008-07-03 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ESTsoft
2008-07-03 14:04 --------- d-----w C:\Program Files\ESTsoft
2008-07-02 15:45 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ImgBurn
2008-07-02 10:56 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ErrorSmart
2008-07-02 10:43 --------- d-----w C:\Program Files\Azureus
2008-07-02 08:34 --------- d-----w C:\Program Files\Common Files\Logitech
.
((((((((((((((((((((((((((((( snapshot@2008-08-28_14.26.40.11 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-28 11:07:50 101,052 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-08-28 14:13:45 101,052 ----a-w C:\Windows\System32\perfc009.dat
- 2008-08-28 11:07:50 123,350 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-08-28 14:13:45 123,350 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-08-28 11:07:50 586,980 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-08-28 14:13:45 586,980 ----a-w C:\Windows\System32\perfh009.dat
- 2008-08-28 11:07:50 669,328 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-08-28 14:13:45 669,328 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-08-28 10:21:50 8,706 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
+ 2008-08-28 13:03:04 8,918 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
- 2008-08-28 11:05:16 69,916 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 70,358 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-28 11:05:11 49,026 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 49,830 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe" [2004-08-09 06:03 221184]
"mceguuo"="c:\users\cyrille\appdata\local\mceguuo.exe" [BU]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-14 17:22 341824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-23 01:52 2616512]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-22 22:02 909096]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-22 19:26 136472]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [BU]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-08-28 12:42 75392]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2583701152-1007577926-4045379130-1000]
"EnableNotificationsRef"=dword:00000005
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{43D61948-2FC2-452E-838C-C25AAE296EC1}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= UDP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"UDP Query User{2342DF4A-153D-4830-9C23-0C3C4645E7A4}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= TCP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"{7079FD9A-53B0-4EA8-B925-4E1A3A992DD6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{62A2CDC3-7680-44CD-BB01-E95B2A5D6588}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9C6DA761-0EB3-4810-B019-01E03B5725E4}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{0D43D2C3-E070-42B7-9AC7-E5032EB92840}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{E10AE7DB-CA15-4A3C-ACE1-FC43B85C0FB5}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"{7B128BC2-3370-4EE9-8A83-EFFFBB69D5B3}"= UDP:443:TCP port 443 ooVoo
"{F7156248-62DA-4ED5-BB7B-CEACAC555968}"= TCP:443:UDP port 443 ooVoo
"{56144CB5-78C5-4244-8D6A-B1D8572E18BB}"= UDP:37674:TCP port 37674 ooVoo
"{5E17F1AE-ABE1-4605-9F88-BC5E204052E1}"= TCP:37674:UDP port 37674 ooVoo
"{DC1748BA-253F-4712-AA6A-BBE29F948CD6}"= TCP:37675:UDP port 37675 ooVoo
"TCP Query User{54CF68EC-BBD5-4934-ABDA-5B2F46C14945}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{59DC3A1F-E9ED-4A07-8FC8-F51AE997B755}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe:ooVoo
"TCP Query User{A833043F-809A-4EA7-A161-364CF42D3F38}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F54341D5-414A-481E-BA1A-4614A7C7F54A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{56C5105B-0218-4F53-9C09-1CE3CCAC1985}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{533237A3-47BB-4BA7-9F17-DACE5A4858DD}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{EC19D54E-7FBD-4F60-A93F-F6E44C23095A}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E9A6FC66-8627-498F-B919-06EC708C0CA9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E152F4BB-2D84-41E9-9839-E11C643BD5A3}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= UDP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5414075E-02BB-4EEE-AD54-93EFC6C2E07B}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= TCP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"{EF3DC8C4-97DA-406F-B03B-FECFDE85339B}"= UDP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{9F6B3A59-7009-4043-8144-3266EBB3C92B}"= TCP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{8B2BCDC4-6CEF-465B-B84A-7220170199D1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A3215C7B-3E1D-4C62-A655-17F002FFF498}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5E356094-14A8-49E8-8ABC-C8B2F40ADF55}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C3A23C3B-4971-411E-9BBD-AA6B41E04A12}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{776116FA-A024-4AA7-9F66-8C236BAFB58F}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{A39051B9-2DE9-4144-B971-DD0C66A89475}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"TCP Query User{39EBCCC4-9CE8-4A93-9013-CF1C387629BC}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= UDP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{A235952F-1E04-4DE8-AB59-74BC28E8DC9B}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= TCP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"{E5769D4F-0E2B-4322-895A-1157D46E4F36}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E4C6AA67-AF67-4F26-8FCE-6E1368E040C9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FCE88D98-9C06-4116-BEB9-F41580EA5D3A}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{C91B18AF-60AB-4054-AD66-F704FE73B35B}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{1B5AD8FD-D1EF-486F-8DCB-1AF27C1BC9EE}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{421C8B02-767B-48FF-AF09-14E63734AEF0}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{40737326-508B-40B2-A9CA-B2D38F7E2CF3}"= UDP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
"{650F0099-5465-410D-9B77-D0ECC8D809F7}"= TCP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-07-25 15:30]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-04-30 17:39]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-23 02:22]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-27 04:00]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8ebe45-5394-11dd-aa14-001d60b428b0}]
\shell\AutoRun\command - K:\autorun.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-21 C:\Windows\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-07-03 C:\Windows\Tasks\Schedule Task Weekly.job
- C:\Program Files\Registry Easy\RE.exe []
.
- - - - ORPHANS REMOVED - - - -
SSODL-okmdepgb-{CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 17:03:57
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog02.sqm 472 bytes
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog03.sqm 472 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-28 17:06:05 - machine was rebooted [Cyrille]
ComboFix-quarantined-files.txt 2008-08-28 15:06:00
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 277,661,507,584 octets libres
318 --- E O F --- 2008-08-23 23:09:01
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2200 [GMT 2:00]
Endroit: C:\Users\Cyrille\Downloads\ComboFix.exe
Command switches used :: C:\Users\Cyrille\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Windows\_MSRSTRT.EXE
C:\ntdetect.com :#:
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts\Alert.dll
C:\Program Files\Secured eMule
C:\Program Files\Secured eMule\secp.exe
C:\Program Files\securedie
C:\Program Files\securedie\INSTALL.LOG
C:\Program Files\securedie\tbsecu.dll
C:\Program Files\securedie\toolbar.cfg
C:\Program Files\securedie\UNWISE.EXE
C:\Windows\_MSRSTRT.EXE
.
---- Previous Run -------
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\[u]0/u.exe
C:\Program Files\PCHealthCenter\[u]0/u.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Users\Cyrille\AppData\Local\mceguuo.dat
C:\Users\Cyrille\AppData\Local\mceguuo.exe
C:\Users\Cyrille\AppData\Local\mceguuo_nav.dat
C:\Users\Cyrille\AppData\Local\mceguuo_navps.dat
C:\Windows\eqbx.exe
C:\Windows\system32\aeeadae7_z.dll
C:\Windows\system32\bfbnsdpi.ini
C:\Windows\system32\fwcomgif.ini
C:\Windows\system32\gddgsxkd.ini
C:\Windows\system32\lirkwkmf.ini
C:\Windows\system32\olvhpmng.ini
C:\Windows\system32\rtl60.bpl
C:\Windows\system32\vnplpiey.ini
C:\Windows\system32\xxxnphmn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\DNA
2008-08-28 12:51 --------- d-----w C:\Program Files\CCleaner
2008-08-28 11:33 --------- d-----w C:\ProgramData\Avira
2008-08-28 11:33 --------- d-----w C:\Program Files\Avira
2008-08-28 11:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-28 11:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-28 11:22 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 05:32 --------- d-----w C:\ProgramData\Google Updater
2008-08-28 00:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-28 00:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-28 00:44 --------- d-----w C:\Program Files\Rockstar Games
2008-08-27 23:23 --------- d-----w C:\ProgramData\Lavasoft
2008-08-26 19:30 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Azureus
2008-08-25 22:03 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-08-25 22:01 --------- d-----w C:\ProgramData\avg8
2008-08-25 21:57 --------- d-----w C:\Program Files\eChanblard
2008-08-24 14:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 14:38 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InstallShield
2008-08-23 10:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BitTorrent
2008-08-22 21:02 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 22:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 15:23 --------- d-----w C:\Program Files\BitTorrent
2008-08-14 15:22 --------- d-----w C:\Program Files\DNA
2008-08-13 10:01 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 08:47 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-11 20:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\PeerNetworking
2008-08-09 22:11 --------- d-----w C:\ProgramData\Downloaded Installations
2008-08-09 09:07 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-09 00:02 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-07 22:55 --------- d-----w C:\Program Files\Runtime Software
2008-08-07 19:26 --------- d-----w C:\Program Files\Google
2008-08-06 11:56 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-05 10:30 --------- d-----w C:\Program Files\CyberLink
2008-08-03 10:34 --------- d-----w C:\Program Files\Ubisoft
2008-08-01 15:10 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-29 15:57 --------- d-----w C:\Program Files\FTPExpert
2008-07-28 00:32 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-07-28 00:13 --------- d-----w C:\Users\Cyrille\AppData\Roaming\STOIK
2008-07-25 22:21 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Acronis
2008-07-25 13:31 --------- d-----w C:\ProgramData\Acronis
2008-07-25 13:30 441,760 ----a-w C:\Windows\system32\drivers\timntr.sys
2008-07-25 13:30 44,384 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
2008-07-25 13:30 368,480 ----a-w C:\Windows\system32\drivers\tdrpman.sys
2008-07-25 13:30 132,224 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-07-25 13:30 --------- d-----w C:\Program Files\Common Files\Acronis
2008-07-25 13:30 --------- d-----w C:\Program Files\Acronis
2008-07-25 13:25 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-23 13:27 --------- d-----w C:\Program Files\SoftwarePassport
2008-07-23 13:26 --------- d-----w C:\Program Files\Mindscape
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMSB1.BIN
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMS.BIN
2008-07-22 11:34 --------- d-----w C:\Program Files\IZArc
2008-07-22 11:09 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-07-21 18:08 --------- d-----w C:\ProgramData\InstallShield
2008-07-21 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 23:50 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-19 23:49 --------- d-----w C:\Program Files\Java
2008-07-19 23:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\LimeWire
2008-07-18 23:47 --------- d-----w C:\Program Files\Common Files\Java
2008-07-18 18:39 587,264 ---ha-w C:\Windows\WLXPGSS.SCR
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-07-15 10:43 --------- d-----w C:\Program Files\SlySoft
2008-07-14 14:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\GRETECH
2008-07-14 14:48 --------- d-----w C:\ProgramData\GRETECH
2008-07-14 14:47 --------- d-----w C:\Program Files\GRETECH
2008-07-12 20:38 --------- d-----w C:\Program Files\Creative
2008-07-12 20:37 --------- d-----w C:\Program Files\Mafia
2008-07-11 22:13 --------- d-----w C:\Program Files\Piratrax
2008-07-11 18:02 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-11 18:02 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-07-11 17:41 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer
2008-07-11 17:31 --------- d-----w C:\Program Files\Registry Easy
2008-07-11 15:31 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-11 14:39 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer Pro
2008-07-10 23:37 --------- d-----w C:\Users\Cyrille\AppData\Roaming\fltk.org
2008-07-10 22:35 --------- d-----w C:\Program Files\RomStation
2008-07-10 09:16 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InterTrust
2008-07-10 09:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 18:08 --------- d-----w C:\ProgramData\Ubisoft
2008-07-09 11:27 --------- d-----w C:\Program Files\MSBuild
2008-07-09 11:27 --------- d-----w C:\Program Files\Microsoft Works
2008-07-09 11:26 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-09 00:17 --------- d-----w C:\ProgramData\Symantec
2008-07-08 16:30 --------- d-----w C:\Program Files\FolderSize
2008-07-08 12:32 --------- d-----w C:\Program Files\Defraggler
2008-07-07 23:16 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-07 23:12 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 23:00 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Auslogics
2008-07-07 23:00 --------- d-----w C:\Program Files\Auslogics
2008-07-07 21:47 --------- d-----w C:\Program Files\Project64 1.6
2008-07-07 18:23 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Download Manager
2008-07-05 09:26 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Uniblue
2008-07-03 18:47 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-07-03 18:29 --------- d-----w C:\Program Files\KONAMI
2008-07-03 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ESTsoft
2008-07-03 14:04 --------- d-----w C:\Program Files\ESTsoft
2008-07-02 15:45 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ImgBurn
2008-07-02 10:56 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ErrorSmart
2008-07-02 10:43 --------- d-----w C:\Program Files\Azureus
2008-07-02 08:34 --------- d-----w C:\Program Files\Common Files\Logitech
.
((((((((((((((((((((((((((((( snapshot@2008-08-28_14.26.40.11 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-28 11:07:50 101,052 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-08-28 14:13:45 101,052 ----a-w C:\Windows\System32\perfc009.dat
- 2008-08-28 11:07:50 123,350 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-08-28 14:13:45 123,350 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-08-28 11:07:50 586,980 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-08-28 14:13:45 586,980 ----a-w C:\Windows\System32\perfh009.dat
- 2008-08-28 11:07:50 669,328 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-08-28 14:13:45 669,328 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-08-28 10:21:50 8,706 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
+ 2008-08-28 13:03:04 8,918 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
- 2008-08-28 11:05:16 69,916 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 70,358 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-28 11:05:11 49,026 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 49,830 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe" [2004-08-09 06:03 221184]
"mceguuo"="c:\users\cyrille\appdata\local\mceguuo.exe" [BU]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-14 17:22 341824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-23 01:52 2616512]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-22 22:02 909096]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-22 19:26 136472]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [BU]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-08-28 12:42 75392]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2583701152-1007577926-4045379130-1000]
"EnableNotificationsRef"=dword:00000005
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{43D61948-2FC2-452E-838C-C25AAE296EC1}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= UDP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"UDP Query User{2342DF4A-153D-4830-9C23-0C3C4645E7A4}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= TCP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"{7079FD9A-53B0-4EA8-B925-4E1A3A992DD6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{62A2CDC3-7680-44CD-BB01-E95B2A5D6588}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9C6DA761-0EB3-4810-B019-01E03B5725E4}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{0D43D2C3-E070-42B7-9AC7-E5032EB92840}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{E10AE7DB-CA15-4A3C-ACE1-FC43B85C0FB5}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"{7B128BC2-3370-4EE9-8A83-EFFFBB69D5B3}"= UDP:443:TCP port 443 ooVoo
"{F7156248-62DA-4ED5-BB7B-CEACAC555968}"= TCP:443:UDP port 443 ooVoo
"{56144CB5-78C5-4244-8D6A-B1D8572E18BB}"= UDP:37674:TCP port 37674 ooVoo
"{5E17F1AE-ABE1-4605-9F88-BC5E204052E1}"= TCP:37674:UDP port 37674 ooVoo
"{DC1748BA-253F-4712-AA6A-BBE29F948CD6}"= TCP:37675:UDP port 37675 ooVoo
"TCP Query User{54CF68EC-BBD5-4934-ABDA-5B2F46C14945}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{59DC3A1F-E9ED-4A07-8FC8-F51AE997B755}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe:ooVoo
"TCP Query User{A833043F-809A-4EA7-A161-364CF42D3F38}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F54341D5-414A-481E-BA1A-4614A7C7F54A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{56C5105B-0218-4F53-9C09-1CE3CCAC1985}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{533237A3-47BB-4BA7-9F17-DACE5A4858DD}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{EC19D54E-7FBD-4F60-A93F-F6E44C23095A}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E9A6FC66-8627-498F-B919-06EC708C0CA9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E152F4BB-2D84-41E9-9839-E11C643BD5A3}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= UDP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5414075E-02BB-4EEE-AD54-93EFC6C2E07B}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= TCP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"{EF3DC8C4-97DA-406F-B03B-FECFDE85339B}"= UDP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{9F6B3A59-7009-4043-8144-3266EBB3C92B}"= TCP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{8B2BCDC4-6CEF-465B-B84A-7220170199D1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A3215C7B-3E1D-4C62-A655-17F002FFF498}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5E356094-14A8-49E8-8ABC-C8B2F40ADF55}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C3A23C3B-4971-411E-9BBD-AA6B41E04A12}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{776116FA-A024-4AA7-9F66-8C236BAFB58F}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{A39051B9-2DE9-4144-B971-DD0C66A89475}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"TCP Query User{39EBCCC4-9CE8-4A93-9013-CF1C387629BC}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= UDP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{A235952F-1E04-4DE8-AB59-74BC28E8DC9B}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= TCP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"{E5769D4F-0E2B-4322-895A-1157D46E4F36}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E4C6AA67-AF67-4F26-8FCE-6E1368E040C9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FCE88D98-9C06-4116-BEB9-F41580EA5D3A}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{C91B18AF-60AB-4054-AD66-F704FE73B35B}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{1B5AD8FD-D1EF-486F-8DCB-1AF27C1BC9EE}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{421C8B02-767B-48FF-AF09-14E63734AEF0}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{40737326-508B-40B2-A9CA-B2D38F7E2CF3}"= UDP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
"{650F0099-5465-410D-9B77-D0ECC8D809F7}"= TCP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-07-25 15:30]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-04-30 17:39]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-23 02:22]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-27 04:00]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8ebe45-5394-11dd-aa14-001d60b428b0}]
\shell\AutoRun\command - K:\autorun.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-21 C:\Windows\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-07-03 C:\Windows\Tasks\Schedule Task Weekly.job
- C:\Program Files\Registry Easy\RE.exe []
.
- - - - ORPHANS REMOVED - - - -
SSODL-okmdepgb-{CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 17:03:57
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog02.sqm 472 bytes
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog03.sqm 472 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-28 17:06:05 - machine was rebooted [Cyrille]
ComboFix-quarantined-files.txt 2008-08-28 15:06:00
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 277,661,507,584 octets libres
318 --- E O F --- 2008-08-23 23:09:01
Telecharge malwarebytes
-> http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
-> http://www.malwarebytes.org/mbam/program/mbam-setup.exe
Tu l´instale; le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
Malwarebytes' Anti-Malware 1.25
Version de la base de données: 1092
Windows 6.0.6001 Service Pack 1
19:10:36 28/08/2008
mbam-log-08-28-2008 (19-10-36).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 102474
Temps écoulé: 34 minute(s), 27 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\QooBox\Quarantine\C\Windows\eqbx.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Version de la base de données: 1092
Windows 6.0.6001 Service Pack 1
19:10:36 28/08/2008
mbam-log-08-28-2008 (19-10-36).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 102474
Temps écoulé: 34 minute(s), 27 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\QooBox\Quarantine\C\Windows\eqbx.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:02:49, on 28/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DNA\btdna.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\Explorer.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Azureus\Azureus.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.ustart.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - (no file)
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe -startup
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
Scan saved at 20:02:49, on 28/08/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DNA\btdna.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Windows\Explorer.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Azureus\Azureus.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.ustart.org
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - (no file)
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe -startup
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
fais un clic droit sur hijackthis
choisi executer en tant qu admistrateur
fais scan only
coches ces ligne :
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: (no name) - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - (no file)
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
Tu les coches et tu clic sur fix checked
ensuite tu as des traces d avast :
Pour désinstaller Avast telecharge cet outil
https://www.avast.com/fr-fr/uninstall-utility
ensuite :
Démarrer > Accessoire > executer > tape : services.msc
- Clic droit sur le service cité - AVG Free8 WatchDog
- propriétés
- et dans "type de démarrage" et mets le sur « désactivé ».
- Ensuite si le "Status du service" est sur "Démarré" faire : « arrêté »
Tutorial : https://www.zebulon.fr/dossiers/windows/31-services.html
ensuite désinstal adobe reader car pas a jours et telecharge et instal cette version :
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.0/fra/AdbeRdr90_fr_FR.exe
ensuite :
-> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):
http://download.piriform.com/ccsetup210.exe
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
-> Tuto : https://www.malekal.com/tutoriel-ccleaner/
ensuite :
* pour supprimer les outils/fix utilisés :
Télécharge ToolsCleaner sur ton bureau.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Fais un clic droit sur toolcleaner
# Choisi executer en tant qu administrateur
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
choisi executer en tant qu admistrateur
fais scan only
coches ces ligne :
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O3 - Toolbar: (no name) - {CEDDA62B-5FBE-4AB2-AE2E-5E069F444444} - (no file)
O3 - Toolbar: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
Tu les coches et tu clic sur fix checked
ensuite tu as des traces d avast :
Pour désinstaller Avast telecharge cet outil
https://www.avast.com/fr-fr/uninstall-utility
ensuite :
Démarrer > Accessoire > executer > tape : services.msc
- Clic droit sur le service cité - AVG Free8 WatchDog
- propriétés
- et dans "type de démarrage" et mets le sur « désactivé ».
- Ensuite si le "Status du service" est sur "Démarré" faire : « arrêté »
Tutorial : https://www.zebulon.fr/dossiers/windows/31-services.html
ensuite désinstal adobe reader car pas a jours et telecharge et instal cette version :
http://ardownload.adobe.com/pub/adobe/reader/win/9.x/9.0/fra/AdbeRdr90_fr_FR.exe
ensuite :
-> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):
http://download.piriform.com/ccsetup210.exe
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
-> Tuto : https://www.malekal.com/tutoriel-ccleaner/
ensuite :
* pour supprimer les outils/fix utilisés :
Télécharge ToolsCleaner sur ton bureau.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/
# Fais un clic droit sur toolcleaner
# Choisi executer en tant qu administrateur
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
J'ai suivi tes conseils et voici le rapport
Merci de ton aide
----------------- FindyKill V4.710 ------------------
* User : ISAMAN - PC-DE-ISAMAN
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 21/12/08 par Chiquitine29
* Recherche effectuée à 23:34:13 le 30/12/2008
* Windows Vista - Internet Explorer 7.0.6001.18000
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX3000.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\TotalReduc\TotalReduc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Windows\system32\svchost.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\iashost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\taskeng.exe
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans C:
»»»» Presence des fichiers dans C:\Windows
»»»» Presence des fichiers dans C:\Windows\Prefetch
Found ! - C:\Windows\prefetch\113833.EXE-3B7A0812.pf
Found ! - C:\Windows\prefetch\139854.EXE-D0642569.pf
Found ! - C:\Windows\prefetch\14761657.EXE-7AAD3854.pf
Found ! - C:\Windows\prefetch\14821576.EXE-459E7E1D.pf
Found ! - C:\Windows\prefetch\155205.EXE-36BF9695.pf
Found ! - C:\Windows\prefetch\166187.EXE-B60D21A4.pf
Found ! - C:\Windows\prefetch\170883.EXE-BF3F7C5A.pf
Found ! - C:\Windows\prefetch\174783.EXE-98D336D9.pf
Found ! - C:\Windows\prefetch\188605.EXE-44E8255F.pf
Found ! - C:\Windows\prefetch\29451350.EXE-D884480C.pf
Found ! - C:\Windows\prefetch\43555.EXE-95F94A91.pf
Found ! - C:\Windows\prefetch\63133.EXE-4F3D4803.pf
Found ! - C:\Windows\prefetch\69514.EXE-A3894B70.pf
Found ! - C:\Windows\prefetch\79030.EXE-7382C0B2.pf
Found ! - C:\Windows\prefetch\FLEC006.EXE-3C137E03.pf
Found ! - C:\Windows\prefetch\WINTEMS.EXE-85AF748B.pf
Found ! - C:\Windows\Prefetch\CRAC.EXE-62F13AA9.pf
»»»» Presence des fichiers dans C:\Windows\system32
Found ! [30/12/2008 23:18] - C:\Windows\system32\mdelk.exe
Found ! [30/12/2008 23:18] - C:\Windows\system32\wintems.exe
Found ! [30/12/2008 23:18] - C:\Windows\system32\ban_list.txt
»»»» Presence des fichiers dans C:\Windows\system32\config\systemprofile\AppData\Roaming
»»»» Presence des fichiers dans C:\Windows\system32\drivers
Found ! [30/12/2008 23:17] - C:\Windows\system32\drivers\srosa.sys
Found ! [30/12/2008 23:17] - C:\Windows\system32\drivers\srosa2.sys
Found ! [09/01/2004 06:07] - C:\Windows\system32\drivers\winfilse.exe
Found ! [30/12/2008 23:21] - "C:\Windows\system32\drivers\downld"
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\100948.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\101416.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\101743.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\101962.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102180.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102797670.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102804.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102842535.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102847247.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102862207.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102867605.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102896933.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102947352.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102985011.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\102991797.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\103032217.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\103052887.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\103210.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\104926.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\105378.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\105675.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\105877.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\106096.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\106143.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\106798.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\106829.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\106860.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107141.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107172.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107188.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107609.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107703.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107765.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107859.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\107874.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\108155.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\108280.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\109060.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\110043.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\110682.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\111431.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\111540.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\111571.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\111587.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\112507.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\112773.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\113209.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\113833.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\113865.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\115269.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\115456.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\115939.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\115986.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\116470.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\116548.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\116610.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117203.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117482106.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117510623.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117515.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117609684.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117614504.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117629090.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117629527.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117643161.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117671.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117677887.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117770396.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117816323.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\117842219.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\118186.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\118248.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\118888.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\119184.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\119340.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\119871.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\120432.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\120463.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\121384.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\121415.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\123318.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\123381.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\123505.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\123973.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\124239.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\124707.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\124832.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\124847.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\125658.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\125955.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\125970.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\126002.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\126906.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\128108.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\128123.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\128248.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\128732.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129075.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129090.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129168.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129480.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129574.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129605.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\129699.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\130541.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\130713.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\131165.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132291967.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132304432.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132374024.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132379609.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132398812.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132417486.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132432321.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132444.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132459871.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132494425.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132528512.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132539666.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132585.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132587324.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132608353.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\132616.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\133131.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\133989.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\134098.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\134332.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\134862.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\135003.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\135174.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\135346.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\135440.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\136251.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\136454.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\136610.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\136641.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\136937.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\136984.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\137468.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\137826.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\138092.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\138170.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\138357.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\139152.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\139308.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\139823.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\139854.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\140088.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\140260.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\140525.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\140666.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\141477.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\141898.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\141976.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\142023.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\142085.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\142116.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\142990.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\143006.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\143442.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\145502.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\145564.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14598214.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14633221.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14635779.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14637168.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14637917.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14641817.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14643252.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14646263.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14648244.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14649804.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14650100.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14650256.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14650303.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14653938.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14654016.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14654343.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14654952.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14656340.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14657214.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14657479.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14657557.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14657744.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14660147.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14660521.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\146609.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14661129.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14661473.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14662315.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14663579.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14663594.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14663875.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14664437.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14666324.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14667838.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14668056.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14673001.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14674577.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14674982.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14675388.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14676964.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14677900.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14678960.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14681082.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14681441.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14682034.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14682049.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14685824.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14688445.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14688695.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14689069.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14690395.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14691940.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14693656.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14693890.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14694295.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14694716.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14695309.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14697244.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14699116.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14699568.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14700691.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14702548.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14702875.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147041675.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147064529.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147068117.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14707399.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147075823.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14708289.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147086697.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147108.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147110643.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14711721.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14713452.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147141188.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14715995.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14716432.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14716525.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14717056.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147172747.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14717945.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147179548.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14719895.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14721159.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14722001.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147224336.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14725246.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\147255271.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14727118.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14728381.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14731330.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14733998.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14735807.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14736556.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14738069.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14738943.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14741376.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14741985.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14742531.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14744216.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14744543.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14745698.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14751984.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14754028.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14755058.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14758692.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14760955.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14761657.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14763591.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14764761.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14767351.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14767943.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14768567.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14769878.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14771781.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14774199.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14776867.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14778115.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14778333.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14782670.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14785088.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14786133.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14787334.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14789159.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14790158.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14790735.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14794604.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14799066.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14804853.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14805836.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14806866.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14810844.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14811967.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14812045.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14813808.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14814307.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14814432.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14816257.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14818425.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14819034.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14821576.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14822840.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14824977.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14827427.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14828331.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14830843.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14832263.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14832918.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14835507.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14838768.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14845304.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14851965.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14854290.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14858252.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14862262.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14862917.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14868439.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14875724.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14876239.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14877128.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14881512.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14886567.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14895693.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14906082.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14915115.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14922384.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14940309.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14942259.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14948593.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14950870.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14956814.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14990214.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\14997062.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\149979.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\15003193.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\15014862.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\15016406.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\150275.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\150712.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\152693.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\152974.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\153036.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\153177.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\153988.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\154394.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\155049.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\155688.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\156250.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\156609.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\156921.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\157451.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\157467.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\157826.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\158169.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\158309.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\159417.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\160275.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\160384.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\160603.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\160743.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\160852.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\162443.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\162506.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\162553.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\163691.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\164113.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\164565.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\164971.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\165002.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\165626.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\165673.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\166187.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\166390.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\167108.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\167451.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\167482.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\168013.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\168106.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\168293.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\168808.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\168871.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\169495.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\169573.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\169775.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\170306.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\170321.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\170883.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\171211.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\171835.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\172022.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\172287.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\173332.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\173426.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\174206.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\174783.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\175313.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\176405.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\176639.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\176749.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\176811.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\177045.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\177497.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\177638.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\177794.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\177856.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\178137.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\179432.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\180025.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\180259.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\181070.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\181163.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\181195.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\181787.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\181865.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\183347.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\183862.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\184424.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\184580.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\186093.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\187669.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\188262.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\188511.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\188605.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\189151.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\189307.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\189697.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\190383.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\190570.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\190851.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\191460.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\191959.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\192474.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\192505.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\192848.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\193410.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\193971.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\196171.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\196670.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\196966.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\197450.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\197715.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\198495.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\198542.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\198885.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\199494.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\199977.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\200336.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\201943.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\202036.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\202348.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\203175.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\203253.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\203378.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\204127.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\204314.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\204517.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\204704.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\205188.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\205219.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\205375.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\206670.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\206685.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\207528.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\208105.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\208214.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\209306.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\209478.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\209774.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\209790.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\210039.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\210585.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\210960.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\211303.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\211537.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\211911.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\211927.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\212005.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\212223.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\212442.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\212785.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\212832.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\212925.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\213034.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\213081.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\213097.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\213705.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\213814.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\214376.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\214392.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\215328.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\216030.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\217090.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\217434.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\217761.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\218182.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\218479.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\218541.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\218619.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\219321.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\219524.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\219618.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\220725.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\221381.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\222597.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\222722.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\223518.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\223970.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\225374.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\226076.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\226326.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\227121.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\227449.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\227589.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\228213.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\230522.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\230678.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\230881.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\231021.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\231396.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\232691.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\232862.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\232925.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\234001.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\234344.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\235764.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\236778.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\237043.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\237183.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\237277.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\237480.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\237714.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\238712.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\239336.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\239430.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\240413.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\241536.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\241848.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\241895.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\243080.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\243829.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\244593.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\244687.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\245467.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\246169.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\246902.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\246949.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\247261.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\247713.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\249227.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\249273.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\249429.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\249617.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\250927.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\252347.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\252534.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\252628.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\252955.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\253049.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\253595.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\253610.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\255545.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\256637.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\257323.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\257620.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\257994.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\258212.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\258431.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\259492.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\260100.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\261988.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\262456.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\263345.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\264530.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\264733.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\265076.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\266028.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\266262.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\269101.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\270053.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\273204.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\274795.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\274998.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\276402.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\277088.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\277182.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\279740.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\280583.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\280942.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\282985.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29191312.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29196289.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29207630.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29211343.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29212528.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29212887.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29214073.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29218160.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29222341.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29227567.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29230094.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29234431.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29237754.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29238175.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29239672.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29241014.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29241248.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29244103.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29244368.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29244774.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29246599.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29249563.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29253697.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29254118.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29254149.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29254430.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29257379.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29259906.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29261996.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29267316.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29268470.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29274710.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\292751.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29278111.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29286130.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29287502.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29287736.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29288033.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29289328.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29289780.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29292151.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29294834.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\292954.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29297736.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29299046.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29299280.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29300185.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29300232.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29302900.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29303181.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29303555.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29304975.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29312213.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29312463.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29313040.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29314132.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29317533.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29318188.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29321479.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29321838.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29322790.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29322977.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29325629.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29330449.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29331885.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29333257.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29333351.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29334131.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29334209.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29334490.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29335223.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29338218.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29339139.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29339482.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29345784.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29346252.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29347329.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29347610.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29353475.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29355191.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29358342.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29362055.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29362289.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29365191.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29365784.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29371010.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29375471.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29377811.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29378248.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29379621.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29380651.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29382304.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29382460.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29383178.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29383490.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29386922.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29389184.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29391134.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29391758.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29392663.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29392678.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29392803.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29396641.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29397296.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29397468.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29397858.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29399667.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29400010.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29400697.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\294046.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29405221.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29408481.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29409651.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29414862.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29418465.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29422318.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29424066.exe
Found ! [30/12/2008 23:21] - C:\Windows\system32\drivers\downld\29429479.exe
Fou