Ordi rempli de virus
Fermé
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
-
12 sept. 2008 à 03:37
olivier_123 Messages postés 290 Date d'inscription jeudi 4 janvier 2007 Statut Membre Dernière intervention 16 mai 2009 - 4 oct. 2008 à 19:15
olivier_123 Messages postés 290 Date d'inscription jeudi 4 janvier 2007 Statut Membre Dernière intervention 16 mai 2009 - 4 oct. 2008 à 19:15
A voir également:
- Ordi rempli de virus
- Mon ordi rame que faire - Guide
- Comment reinitialiser un ordi - Guide
- Ordi scrabble - Télécharger - Jeux vidéo
- Youtu.be virus - Accueil - Guide virus
- Document rempli - Guide
107 réponses
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
12 sept. 2008 à 03:39
12 sept. 2008 à 03:39
Salut,
- Redémarre ton ordinateur en mode sans échec :
https://blog.sosordi.net/
- Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée
- Réponds O(oui) à ces deux questions si elles te sont posées
Voulez-vous nettoyer le registre ?
Corriger le fichier infecté ?
- Un rapport sera généré, sauvegarde-le sur le bureau
- Redémarre en mode normal
- Poste le rapport SmitfraudFix
- Redémarre ton ordinateur en mode sans échec :
https://blog.sosordi.net/
- Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée
- Réponds O(oui) à ces deux questions si elles te sont posées
Voulez-vous nettoyer le registre ?
Corriger le fichier infecté ?
- Un rapport sera généré, sauvegarde-le sur le bureau
- Redémarre en mode normal
- Poste le rapport SmitfraudFix
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
13 sept. 2008 à 19:04
13 sept. 2008 à 19:04
Voila le rapport Smitfraudfix:
SmitFraudFix v2.346
Rapport fait à 12:56:21,71, 2008-09-13
Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
C:\WINDOWS\system32\1.ico supprimé
C:\WINDOWS\system32\2.ico supprimé
C:\Program Files\PCHealthCenter\ supprimé
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
»»»»»»»»»»»»»»»»»»»»»»»» DNS
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
SmitFraudFix v2.346
Rapport fait à 12:56:21,71, 2008-09-13
Executé à partir de C:\Documents and Settings\Administrateur\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
C:\WINDOWS\system32\1.ico supprimé
C:\WINDOWS\system32\2.ico supprimé
C:\Program Files\PCHealthCenter\ supprimé
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
»»»»»»»»»»»»»»»»»»»»»»»» DNS
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
13 sept. 2008 à 19:08
13 sept. 2008 à 19:08
---> Supprime SmitFraudFix
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
- Clique sur Install ensuite sur I Accept
- Clique sur Do a scan system and save log file
- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
- Clique sur Install ensuite sur I Accept
- Clique sur Do a scan system and save log file
- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
13 sept. 2008 à 20:29
13 sept. 2008 à 20:29
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:27: VIRUS ALERT!, on 2008-09-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Downloads\uTorrent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Spyware Terminator\SpywareTerminator.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [\YUR34.exe] C:\Windows\system32\YUR34.exe
O4 - HKLM\..\Run: [4c81d226] rundll32.exe "C:\WINDOWS\system32\dcuvyuxd.dll",b
O4 - HKCU\..\Run: [uTorrent] "C:\Downloads\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YURE.exe] C:\Windows\system32\YURE.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YURD.exe] C:\Windows\system32\YURD.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YURF.exe] C:\Windows\system32\YURF.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR10.exe] C:\Windows\system32\YUR10.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR11.exe] C:\Windows\system32\YUR11.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR19.exe] C:\Windows\system32\YUR19.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1A.exe] C:\Windows\system32\YUR1A.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1B.exe] C:\Windows\system32\YUR1B.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1C.exe] C:\Windows\system32\YUR1C.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1D.exe] C:\Windows\system32\YUR1D.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrateur')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: zufueu.dll yukanx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
Scan saved at 14:27: VIRUS ALERT!, on 2008-09-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Downloads\uTorrent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Spyware Terminator\SpywareTerminator.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: NetXfer - {C16CBAAC-A75C-4DB5-A0DD-CDF5CAFCDD3A} - C:\Program Files\Xi\NetXfer\NXToolBar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [PC Booster] C:\Program Files\inKline Global\PC Booster\pcbooster.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [\YUR34.exe] C:\Windows\system32\YUR34.exe
O4 - HKLM\..\Run: [4c81d226] rundll32.exe "C:\WINDOWS\system32\dcuvyuxd.dll",b
O4 - HKCU\..\Run: [uTorrent] "C:\Downloads\uTorrent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YURE.exe] C:\Windows\system32\YURE.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YURD.exe] C:\Windows\system32\YURD.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YURF.exe] C:\Windows\system32\YURF.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR10.exe] C:\Windows\system32\YUR10.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR11.exe] C:\Windows\system32\YUR11.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR19.exe] C:\Windows\system32\YUR19.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1A.exe] C:\Windows\system32\YUR1A.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1B.exe] C:\Windows\system32\YUR1B.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1C.exe] C:\Windows\system32\YUR1C.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-1007\..\Run: [\YUR1D.exe] C:\Windows\system32\YUR1D.exe (User 'Simon')
O4 - HKUS\S-1-5-21-3689773760-372661124-4031406792-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrateur')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\nwprovau.dll' missing
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: zufueu.dll yukanx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
13 sept. 2008 à 20:32
13 sept. 2008 à 20:32
---> Fais un scan rapide avec MBAM, supprime tout ce qu'il trouve et poste le rapport :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
13 sept. 2008 à 22:03
13 sept. 2008 à 22:03
Bonjour, j'ai fait le scan et puis jai cliquez sur supprimez les élements. Il a commencer a supprimer la moitié puis le programme a planté en disant: Mémoire insuffisante.
Voici le rapport:
Malwarebytes' Anti-Malware 1.28
Version de la base de données: 1145
Windows 5.1.2600 Service Pack 2
2008-09-13 15:59:04
mbam-log-2008-09-13 (15-58-59).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 212021
Temps écoulé: 48 minute(s), 55 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 5
Clé(s) du Registre infectée(s): 26
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 17
Dossier(s) infecté(s): 14
Fichier(s) infecté(s): 128
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\dcuvyuxd.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\urqOGxUO.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMfDWml.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\zufueu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yukanx.dll (Trojan.Vundo) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03fc422d-1adc-401e-8ccc-ec96d0966496} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{03fc422d-1adc-401e-8ccc-ec96d0966496} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6afb6f98-289c-442e-b577-5e5125c742e2} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomfdwml (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6afb6f98-289c-442e-b577-5e5125c742e2} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{913a109f-fdb1-432e-b9aa-19263773876f} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{913a109f-fdb1-432e-b9aa-19263773876f} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{59baf55f-18de-48e6-94ca-8b0980c4b1ef} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\RegistrySmart (Rogue.RegistrySmart) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{fae0f23d-b54e-4e92-8575-018fde63ef76} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{0955bcf0-2db3-4926-b985-1ed8f0894d73} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{279fb82e-05b3-4c47-ba77-05d0da7f5703} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{94e952a4-fae1-40e5-bbe1-8199d8cf7fd0} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{bc54ab1a-deb5-442e-8f55-05b748408c09} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\fqbewlna.bldx (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\fqbewlna.toolbar.1 (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4c81d226 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6afb6f98-289c-442e-b577-5e5125c742e2} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur34.exe (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0\source (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> No action taken.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\urqogxuo -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\urqogxuo -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (HH:mm:ss) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
Dossier(s) infecté(s):
C:\Program Files\MicroAV (Rogue.MicroAntivirus) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\RegistrySmart (Rogue.RegistrySmart) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\RegistrySmart\Log (Rogue.RegistrySmart) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397 (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Packages (Rogue.Multiple) -> No action taken.
Fichier(s) infecté(s):
C:\WINDOWS\system32\yukanx.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMfDWml.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\urqOGxUO.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\OUxGOqru.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\OUxGOqru.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\dcuvyuxd.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\dxuyvucd.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\nnnllkIA.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\AIkllnnn.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\AIkllnnn.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\spksrrel.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\lerrskps.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vmycfliv.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vilfcymv.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\wkoohdbc.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\cbdhookw.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\zufueu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\YUR34.exe (Trojan.FakeAlert) -> No action taken.
C:\x (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\3L5BNG4Z\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\PU58JEZ6\nd82m0[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\PU58JEZ6\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\XIQUMPLW\nd82m0[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\0UENKCHY\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\GB1DBBVB\cntr[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\X75M9QBI\nd82m0[1] (Trojan.Vundo) -> No action taken.
C:\Program Files\PremierOpinion\pmls.dll (Adware.RK) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP1\A0000015.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP1\A0000037.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001315.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001316.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001317.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001318.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001319.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001320.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001321.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001322.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001323.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001324.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001325.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001326.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002316.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002317.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002318.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002319.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002320.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002321.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002322.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002323.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002324.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002325.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002326.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002327.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002328.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002329.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003318.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003319.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003320.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003321.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003322.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003323.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003324.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003325.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003326.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003327.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003328.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003329.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003330.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003331.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\emnf.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\awtsPGvT.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\bnrwriej.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\efcyyYSm.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\gzmxue.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\imoqopdy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ljJDUllM.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pmnnNdAq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pnvssfsh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tdpmma.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wlmngtnr.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wvUMghIX.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\YUR11.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR1C.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR1D.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR2.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR3.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR5F5B.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR5FA1.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR5FE5.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR75.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURAD5.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURC.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURD.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURF.exe (Trojan.FakeAlert) -> No action taken.
C:\Program Files\MicroAV\MicroAV.cpl (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV.exe (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV.ooo (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV0.dat (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV1.dat (Rogue.MicroAntivirus) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\RegistrySmart\Log\2008 Sep 11 - 12_59_07 AM_859.log (Rogue.RegistrySmart) -> No action taken.
C:\Program Files\MSA\msa0.dat (Rogue.MSAntivirus) -> No action taken.
C:\Program Files\MSA\msa1.dat (Rogue.MSAntivirus) -> No action taken.
C:\Program Files\MSA\MSA.cpl (Rogue.MSAntivirus) -> No action taken.
C:\Program Files\MSA\MSA.ooo (Rogue.MSAntivirus) -> No action taken.
C:\WINDOWS\system32\MSa.cpl (Rogue.MSAntivirus) -> No action taken.
C:\WINDOWS\system32\1.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\2.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\ (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\casino1.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\casino2.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\casino3.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssl.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdsslog.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\tdssserv.sys (Trojan.Agent) -> No action taken.
C:\A2.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\dtseqrxk.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\fqbewlna.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\mgxfebsq.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\mqgldfvo.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Bureau\ErrorDoctorSetup.exe (Rogue.ErrorDoctor) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\TmpRecentIcons\MS Antivirus.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\TmpRecentIcons\antivirus-2008pro.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\Simon\Bureau\BEST ZOO PORN.url (Rogue.Link) -> No action taken.
C:\Documents and Settings\Simon\Bureau\QUALITY PORN.url (Rogue.Link) -> No action taken.
Voici le rapport:
Malwarebytes' Anti-Malware 1.28
Version de la base de données: 1145
Windows 5.1.2600 Service Pack 2
2008-09-13 15:59:04
mbam-log-2008-09-13 (15-58-59).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 212021
Temps écoulé: 48 minute(s), 55 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 5
Clé(s) du Registre infectée(s): 26
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 17
Dossier(s) infecté(s): 14
Fichier(s) infecté(s): 128
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:\WINDOWS\system32\dcuvyuxd.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\urqOGxUO.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMfDWml.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\zufueu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yukanx.dll (Trojan.Vundo) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03fc422d-1adc-401e-8ccc-ec96d0966496} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{03fc422d-1adc-401e-8ccc-ec96d0966496} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6afb6f98-289c-442e-b577-5e5125c742e2} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomfdwml (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{6afb6f98-289c-442e-b577-5e5125c742e2} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{913a109f-fdb1-432e-b9aa-19263773876f} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{913a109f-fdb1-432e-b9aa-19263773876f} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{59baf55f-18de-48e6-94ca-8b0980c4b1ef} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\RegistrySmart (Rogue.RegistrySmart) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{fae0f23d-b54e-4e92-8575-018fde63ef76} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{0955bcf0-2db3-4926-b985-1ed8f0894d73} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{279fb82e-05b3-4c47-ba77-05d0da7f5703} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{94e952a4-fae1-40e5-bbe1-8199d8cf7fd0} (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{bc54ab1a-deb5-442e-8f55-05b748408c09} (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\fqbewlna.bldx (Trojan.FakeAlert) -> No action taken.
HKEY_CLASSES_ROOT\fqbewlna.toolbar.1 (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4c81d226 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6afb6f98-289c-442e-b577-5e5125c742e2} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur34.exe (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0\source (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> No action taken.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\urqogxuo -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\urqogxuo -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (HH:mm:ss) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives (Hijack.Drives) -> Bad: (12) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
Dossier(s) infecté(s):
C:\Program Files\MicroAV (Rogue.MicroAntivirus) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\RegistrySmart (Rogue.RegistrySmart) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\RegistrySmart\Log (Rogue.RegistrySmart) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397 (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKCU (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKLM (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\BrowserObjects (Rogue.Multiple) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\rhcl90j0e397\Quarantine\Packages (Rogue.Multiple) -> No action taken.
Fichier(s) infecté(s):
C:\WINDOWS\system32\yukanx.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\qoMfDWml.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\urqOGxUO.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\OUxGOqru.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\OUxGOqru.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\dcuvyuxd.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\dxuyvucd.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\nnnllkIA.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\AIkllnnn.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\AIkllnnn.ini2 (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\spksrrel.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\lerrskps.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vmycfliv.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\vilfcymv.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\wkoohdbc.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\cbdhookw.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\zufueu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\YUR34.exe (Trojan.FakeAlert) -> No action taken.
C:\x (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\3L5BNG4Z\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\PU58JEZ6\nd82m0[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\PU58JEZ6\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Local Settings\Temporary Internet Files\Content.IE5\XIQUMPLW\nd82m0[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\0UENKCHY\upd105320[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\GB1DBBVB\cntr[1] (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\X75M9QBI\nd82m0[1] (Trojan.Vundo) -> No action taken.
C:\Program Files\PremierOpinion\pmls.dll (Adware.RK) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP1\A0000015.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP1\A0000037.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001315.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001316.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001317.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001318.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001319.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001320.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001321.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001322.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001323.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001324.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001325.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP13\A0001326.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002316.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002317.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002318.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002319.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002320.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002321.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002322.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002323.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002324.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002325.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002326.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002327.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002328.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP15\A0002329.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003318.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003319.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003320.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003321.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003322.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003323.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003324.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003325.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003326.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003327.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003328.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003329.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003330.exe (Trojan.FakeAlert) -> No action taken.
C:\System Volume Information\_restore{19B36CF1-12AA-4058-8328-3769885FB8AB}\RP16\A0003331.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\emnf.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\awtsPGvT.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\bnrwriej.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\efcyyYSm.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\gzmxue.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\imoqopdy.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\ljJDUllM.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pmnnNdAq.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pnvssfsh.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\tdpmma.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wlmngtnr.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\wvUMghIX.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\YUR11.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR1C.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR1D.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR2.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR3.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR5F5B.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR5FA1.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR5FE5.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YUR75.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURAD5.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURC.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURD.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\YURF.exe (Trojan.FakeAlert) -> No action taken.
C:\Program Files\MicroAV\MicroAV.cpl (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV.exe (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV.ooo (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV0.dat (Rogue.MicroAntivirus) -> No action taken.
C:\Program Files\MicroAV\MicroAV1.dat (Rogue.MicroAntivirus) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\RegistrySmart\Log\2008 Sep 11 - 12_59_07 AM_859.log (Rogue.RegistrySmart) -> No action taken.
C:\Program Files\MSA\msa0.dat (Rogue.MSAntivirus) -> No action taken.
C:\Program Files\MSA\msa1.dat (Rogue.MSAntivirus) -> No action taken.
C:\Program Files\MSA\MSA.cpl (Rogue.MSAntivirus) -> No action taken.
C:\Program Files\MSA\MSA.ooo (Rogue.MSAntivirus) -> No action taken.
C:\WINDOWS\system32\MSa.cpl (Rogue.MSAntivirus) -> No action taken.
C:\WINDOWS\system32\1.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\2.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\ (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\casino1.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\casino2.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\casino3.ico (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\tdssadw.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssl.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssmain.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdsslog.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\drivers\tdssserv.sys (Trojan.Agent) -> No action taken.
C:\A2.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\dtseqrxk.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\fqbewlna.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\mgxfebsq.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\mqgldfvo.exe (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Bureau\ErrorDoctorSetup.exe (Rogue.ErrorDoctor) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\TmpRecentIcons\MS Antivirus.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\Owner.Olivier\Application Data\TmpRecentIcons\antivirus-2008pro.lnk (Rogue.Link) -> No action taken.
C:\Documents and Settings\Simon\Bureau\BEST ZOO PORN.url (Rogue.Link) -> No action taken.
C:\Documents and Settings\Simon\Bureau\QUALITY PORN.url (Rogue.Link) -> No action taken.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
13 sept. 2008 à 22:06
13 sept. 2008 à 22:06
Wahoo les infections.
Beh supprime petit à petit alors en faisant plusieurs scans à la suite.
Beh supprime petit à petit alors en faisant plusieurs scans à la suite.
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
13 sept. 2008 à 22:18
13 sept. 2008 à 22:18
Ouais je sais, mon ordinateur est rempli de virus, en plus je mit connait beacoup en ordinateur et j'ai de la difficulté a les enlever ;). C'est pourquoi je suis venu ici.
Donc, je vais faire plusieurs scans ! @+
Donc, je vais faire plusieurs scans ! @+
babs26
Messages postés
89
Date d'inscription
samedi 13 septembre 2008
Statut
Membre
Dernière intervention
17 mars 2011
7
13 sept. 2008 à 23:04
13 sept. 2008 à 23:04
Bonjour
Pour suivre ...
merci
Pour suivre ...
merci
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
14 sept. 2008 à 00:53
14 sept. 2008 à 00:53
J'ai effacer le plus possible , le reste ne veux pas supprimer. Que faire maitenant?
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
14 sept. 2008 à 00:54
14 sept. 2008 à 00:54
* Télécharge SDFix (par Andy Manchesta) et sauvegarde-le sur ton bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
* Double-clique sur SDFix.exe et choisis Install pour l'extraire dans son dossier sur le bureau.
* Redémarre le PC en mode sans échec :
https://www.malekal.com/demarrer-windows-mode-sans-echec/
* Choisis ton compte.
Déroule la liste des instructions ci-dessous :
* Ouvre le dossier SDFix qui vient d'être créé sur le bureau et double-clique sur RunThis.bat pour lancer le script.
* Appuie sur Y pour commencer le nettoyage.
* Quand il te le demandera, appuie sur une touche pour redémarrer le PC.
* Ton système sera plus long à redémarrer car l'outil va continuer à s'exécuter et supprimer des fichiers.
* Après le chargement du bureau, l'outil aura terminé et affichera Finished.
* Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton bureau.
* Le rapport SDFix s'ouvrira et il sera enregistré dans le dossier SDFix sous le nom Report.txt.
* Enfin, copie/colle le rapport du fichier Report.txt.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
* Double-clique sur SDFix.exe et choisis Install pour l'extraire dans son dossier sur le bureau.
* Redémarre le PC en mode sans échec :
https://www.malekal.com/demarrer-windows-mode-sans-echec/
* Choisis ton compte.
Déroule la liste des instructions ci-dessous :
* Ouvre le dossier SDFix qui vient d'être créé sur le bureau et double-clique sur RunThis.bat pour lancer le script.
* Appuie sur Y pour commencer le nettoyage.
* Quand il te le demandera, appuie sur une touche pour redémarrer le PC.
* Ton système sera plus long à redémarrer car l'outil va continuer à s'exécuter et supprimer des fichiers.
* Après le chargement du bureau, l'outil aura terminé et affichera Finished.
* Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton bureau.
* Le rapport SDFix s'ouvrira et il sera enregistré dans le dossier SDFix sous le nom Report.txt.
* Enfin, copie/colle le rapport du fichier Report.txt.
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
14 sept. 2008 à 01:33
14 sept. 2008 à 01:33
Voici le rapport:
[b]SDFix: Version 1.222 [/b]
Run by Administrateur on 2008-09-13 at 19:15
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Owner.Olivier\Mes documents\Autres\Virus Cleaner\SDFix
[b]Checking Services [/b]:
[b]Rootkit[/b]:
C:\WINDOWS\system32\drivers\tdssserv.sys - [B]Rootkit.Win32.Agent.cku[/B]
[b]Name [/b]:
tdssserv
[b]Path [/b]:
\systemroot\system32\drivers\TDSSserv.sys
tdssserv - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\drivers\tdssserv.sys - Deleted
C:\WINDOWS\system32\tdssadw.dll - Deleted
C:\WINDOWS\system32\tdssinit.dll - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdsslog.dll - Deleted
C:\WINDOWS\system32\tdssmain.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-13 19:29:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:fe,1e,5b,81,f5,f4,a5,aa,90,5a,93,d3,40,5d,26,12,11,ef,bf,27,97,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c7,cd,f3,13,1c,3f,37,1e,9b,d7,13,ed,59,3d,2b,f6,99,..
"khjeh"=hex:76,d7,52,86,bf,5c,e2,e3,27,8d,d5,83,e7,46,29,22,c8,ca,f1,3f,bc,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:88,47,c9,49,0b,5a,0e,c8,b1,30,1d,6b,51,44,9f,07,25,76,ca,58,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:fe,1e,5b,81,f5,f4,a5,aa,90,5a,93,d3,40,5d,26,12,11,ef,bf,27,97,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c7,cd,f3,13,1c,3f,37,1e,9b,d7,13,ed,59,3d,2b,f6,99,..
"khjeh"=hex:76,d7,52,86,bf,5c,e2,e3,27,8d,d5,83,e7,46,29,22,c8,ca,f1,3f,bc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:88,47,c9,49,0b,5a,0e,c8,b1,30,1d,6b,51,44,9f,07,25,76,ca,58,f1,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG10.00.00.01WORKSTATION"="666851D80C2D0EF6C7F2A7FC9C3070015518D5639632ADB8A848E4026B6235E7A79DA20AB20FE123199A720244CE0B9B4C3EA1BE6C71A9AF5054D69EA6C48656392B89176E2F01DA770C8C9F1A0A60DF3F8AA856CD5C343AF91C4B89F661C89BD38B3A825C57AA064EAC6229BBA8B59AE671B1F2F7DABC2B4E4201A4D959B4AB312A0EE05C09FEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D6794A9C6AECB7A5D14075D575E7D6A3B9808033F70C505EBCF81B26F93F03004D82AC47ED42190C5D3419A286D61412615AACEC05B50B3E3A017277F039AC0DB38C9BE5234050761C2E69E477208A12F7EDB07008F771FE707CC243A1FBED9A3AA96FE652CAD150B8DE748C9C7CE6F0A9E5C73BEE5D3208EDBB11A718D9089D1E68B373B4C841C3C6846B2058C77025148D53345A9A023322E3B4B7EE4E2F122D707F1DB9B1813B13CE8C853536A45E38159365D9BBD27F1C1414E3D3530C7961D4709569319046D2399CB11A43038E28158C4546DB043B20B800F8B7E9354F10CF3AC38A2DD0CB3F00851A0F87AECB4B72CF600C91F9D19B599CACE34CF74BCAA1560992BE1DE0E29C441E7439A0D04458FBA344CD672139F9015EC4149994235197D8F82C0C24A834757506286D1BD80A1D2CC83C593CC5CCCD4530287CA159952AD3AF2BD91786C6A2648B05B8B94F0E554287402E3BC331DC4EFC7B99D077DF3F2B73BBEB86E056B12BFF6D61DFED544A9A918415B979BAF7238572FC2B038191F2D8C4CBCC4226DD32EF5DB7DB71F078E3658618758C69A4322E95D7AEED2BDD9448C16B159CB76788BDF7139BB745E173A176109C016D4EBAAAB5D19E010C42129D66DC24CBE716057DAC2EDCDADDD282327651150203C7751BE6B09EBE0F2428B76C7AE836BACBF11031ECF73D9FB7BE4D135EB513010459838E9C638EE70E3A1F13F472975599F40677626F7B7159F75D13CF34DC374070AA05B64B094CC7A23BA12F128B710DD6E8A644B69BF69744F578A98150F73452FF3E90606617854CC3EA12AB33C492AA76420B0981B1A327086D4DF39F577591925E367AC99C80FDFD8F37D3FC4E40A7E5E0B571CA530E0DDF8F1E092155172DA9937525CB277A0205C338F05C5245509D8A5D7CFF116DE1C38DEC8BBBAB7938C27FAAA925B214F56102D1581682E39E027185DCE459C5D36C63B579468C092499DE7E48D70C7B74FACD4D9F6878C38A20E2EA67E19F4E3BA16C9DF3F55681C323EDA8AD107D0C9DC62BDB9E8B5AE23F14BD587831BB8C9BC8F734C24EB112D68BB53B728E586C8D1CF24292235E6A6F28C2166C62E62BED2904519ECCBFD991541F71F1D0894CB088D63ADAF806A3E4F75C83F7865D1C398E56C540AC5D787"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\ehome\\ehshell.exe"="C:\\WINDOWS\\ehome\\ehshell.exe:LocalSubNet:Enabled:Media Center"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Documents and Settings\\Owner.Olivier\\Local Settings\\Temp\\nso16F.tmp\\utorrent.exe"="C:\\Documents and Settings\\Owner.Olivier\\Local Settings\\Temp\\nso16F.tmp\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"="C:\\Program Files\\Sierra\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\WINDOWS\\system32\\scvhost32.exe"="C:\\WINDOWS\\system32\\scvhost32.exe:*:Disabled:scvhost32"
"C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"="C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe:*:Enabled:CyberLink PowerCinema NE for Everio"
"C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"="C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe:*:Enabled:CyberLink PowerCinema NE for Everio Resident Program"
"C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe"="C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe:*:Enabled:CyberLink PowerDirector Express"
"C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\ACSPMonitor\\ASMonitor.exe"="C:\\Program Files\\ACSPMonitor\\ASMonitor.exe:*:Enabled:System"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
"c:\\program files\\premieropinion\\pmropn.exe"="c:\\program files\\premieropinion\\pmropn.exe:*:Enabled:pmropn.exe"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Downloads\\uTorrent.exe"="C:\\Downloads\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\OWNER~1.OLI\MESDOC~1\Autres\VIRUSC~1\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Wed 22 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 12 Oct 2007 145,920 ..SHR --- "C:\Program Files\BillP Studios\WinPatrol\Setup.exe"
Sun 22 Apr 2007 15,872 A.SHR --- "C:\Program Files\BillP Studios\WinPatrol\_Setup.dll"
Fri 17 Aug 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 19 Dec 2007 73,216 ...H. --- "C:\Documents and Settings\Owner.Olivier\Bureau\Max\~WRL0001.tmp"
[b]Finished![/b]
[b]SDFix: Version 1.222 [/b]
Run by Administrateur on 2008-09-13 at 19:15
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Owner.Olivier\Mes documents\Autres\Virus Cleaner\SDFix
[b]Checking Services [/b]:
[b]Rootkit[/b]:
C:\WINDOWS\system32\drivers\tdssserv.sys - [B]Rootkit.Win32.Agent.cku[/B]
[b]Name [/b]:
tdssserv
[b]Path [/b]:
\systemroot\system32\drivers\TDSSserv.sys
tdssserv - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\system32\drivers\tdssserv.sys - Deleted
C:\WINDOWS\system32\tdssadw.dll - Deleted
C:\WINDOWS\system32\tdssinit.dll - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdsslog.dll - Deleted
C:\WINDOWS\system32\tdssmain.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-13 19:29:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:fe,1e,5b,81,f5,f4,a5,aa,90,5a,93,d3,40,5d,26,12,11,ef,bf,27,97,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c7,cd,f3,13,1c,3f,37,1e,9b,d7,13,ed,59,3d,2b,f6,99,..
"khjeh"=hex:76,d7,52,86,bf,5c,e2,e3,27,8d,d5,83,e7,46,29,22,c8,ca,f1,3f,bc,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:88,47,c9,49,0b,5a,0e,c8,b1,30,1d,6b,51,44,9f,07,25,76,ca,58,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:fe,1e,5b,81,f5,f4,a5,aa,90,5a,93,d3,40,5d,26,12,11,ef,bf,27,97,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c7,cd,f3,13,1c,3f,37,1e,9b,d7,13,ed,59,3d,2b,f6,99,..
"khjeh"=hex:76,d7,52,86,bf,5c,e2,e3,27,8d,d5,83,e7,46,29,22,c8,ca,f1,3f,bc,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:88,47,c9,49,0b,5a,0e,c8,b1,30,1d,6b,51,44,9f,07,25,76,ca,58,f1,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG10.00.00.01WORKSTATION"="666851D80C2D0EF6C7F2A7FC9C3070015518D5639632ADB8A848E4026B6235E7A79DA20AB20FE123199A720244CE0B9B4C3EA1BE6C71A9AF5054D69EA6C48656392B89176E2F01DA770C8C9F1A0A60DF3F8AA856CD5C343AF91C4B89F661C89BD38B3A825C57AA064EAC6229BBA8B59AE671B1F2F7DABC2B4E4201A4D959B4AB312A0EE05C09FEFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933BA7FD869164D6794A9C6AECB7A5D14075D575E7D6A3B9808033F70C505EBCF81B26F93F03004D82AC47ED42190C5D3419A286D61412615AACEC05B50B3E3A017277F039AC0DB38C9BE5234050761C2E69E477208A12F7EDB07008F771FE707CC243A1FBED9A3AA96FE652CAD150B8DE748C9C7CE6F0A9E5C73BEE5D3208EDBB11A718D9089D1E68B373B4C841C3C6846B2058C77025148D53345A9A023322E3B4B7EE4E2F122D707F1DB9B1813B13CE8C853536A45E38159365D9BBD27F1C1414E3D3530C7961D4709569319046D2399CB11A43038E28158C4546DB043B20B800F8B7E9354F10CF3AC38A2DD0CB3F00851A0F87AECB4B72CF600C91F9D19B599CACE34CF74BCAA1560992BE1DE0E29C441E7439A0D04458FBA344CD672139F9015EC4149994235197D8F82C0C24A834757506286D1BD80A1D2CC83C593CC5CCCD4530287CA159952AD3AF2BD91786C6A2648B05B8B94F0E554287402E3BC331DC4EFC7B99D077DF3F2B73BBEB86E056B12BFF6D61DFED544A9A918415B979BAF7238572FC2B038191F2D8C4CBCC4226DD32EF5DB7DB71F078E3658618758C69A4322E95D7AEED2BDD9448C16B159CB76788BDF7139BB745E173A176109C016D4EBAAAB5D19E010C42129D66DC24CBE716057DAC2EDCDADDD282327651150203C7751BE6B09EBE0F2428B76C7AE836BACBF11031ECF73D9FB7BE4D135EB513010459838E9C638EE70E3A1F13F472975599F40677626F7B7159F75D13CF34DC374070AA05B64B094CC7A23BA12F128B710DD6E8A644B69BF69744F578A98150F73452FF3E90606617854CC3EA12AB33C492AA76420B0981B1A327086D4DF39F577591925E367AC99C80FDFD8F37D3FC4E40A7E5E0B571CA530E0DDF8F1E092155172DA9937525CB277A0205C338F05C5245509D8A5D7CFF116DE1C38DEC8BBBAB7938C27FAAA925B214F56102D1581682E39E027185DCE459C5D36C63B579468C092499DE7E48D70C7B74FACD4D9F6878C38A20E2EA67E19F4E3BA16C9DF3F55681C323EDA8AD107D0C9DC62BDB9E8B5AE23F14BD587831BB8C9BC8F734C24EB112D68BB53B728E586C8D1CF24292235E6A6F28C2166C62E62BED2904519ECCBFD991541F71F1D0894CB088D63ADAF806A3E4F75C83F7865D1C398E56C540AC5D787"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\ehome\\ehshell.exe"="C:\\WINDOWS\\ehome\\ehshell.exe:LocalSubNet:Enabled:Media Center"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Documents and Settings\\Owner.Olivier\\Local Settings\\Temp\\nso16F.tmp\\utorrent.exe"="C:\\Documents and Settings\\Owner.Olivier\\Local Settings\\Temp\\nso16F.tmp\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"="C:\\Program Files\\Sierra\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\WINDOWS\\system32\\scvhost32.exe"="C:\\WINDOWS\\system32\\scvhost32.exe:*:Disabled:scvhost32"
"C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"="C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe:*:Enabled:CyberLink PowerCinema NE for Everio"
"C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"="C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe:*:Enabled:CyberLink PowerCinema NE for Everio Resident Program"
"C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe"="C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe:*:Enabled:CyberLink PowerDirector Express"
"C:\\Program Files\\FrostWire\\FrostWire.exe"="C:\\Program Files\\FrostWire\\FrostWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\ACSPMonitor\\ASMonitor.exe"="C:\\Program Files\\ACSPMonitor\\ASMonitor.exe:*:Enabled:System"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
"c:\\program files\\premieropinion\\pmropn.exe"="c:\\program files\\premieropinion\\pmropn.exe:*:Enabled:pmropn.exe"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Downloads\\uTorrent.exe"="C:\\Downloads\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\OWNER~1.OLI\MESDOC~1\Autres\VIRUSC~1\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Wed 22 Aug 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 12 Oct 2007 145,920 ..SHR --- "C:\Program Files\BillP Studios\WinPatrol\Setup.exe"
Sun 22 Apr 2007 15,872 A.SHR --- "C:\Program Files\BillP Studios\WinPatrol\_Setup.dll"
Fri 17 Aug 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 19 Dec 2007 73,216 ...H. --- "C:\Documents and Settings\Owner.Olivier\Bureau\Max\~WRL0001.tmp"
[b]Finished![/b]
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
14 sept. 2008 à 01:35
14 sept. 2008 à 01:35
---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\
---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\ComboFix.txt
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\
---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\ComboFix.txt
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
14 sept. 2008 à 01:54
14 sept. 2008 à 01:54
ComboFix 08-09-13.03 - Owner 2008-09-13 19:46:56.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1336 [GMT -4:00]
Lancé depuis: C:\Documents and Settings\Owner.Olivier\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MCX1\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Owner.Olivier\Application Data\inst.exe
C:\Documents and Settings\Simon\Cookies\simon@mediaarea[2].txt
C:\Program Files\messenger\msnmsgr.exe
C:\WINDOWS\system32\ieirlruc.ini
C:\WINDOWS\system32\tdpmma.dll
C:\WINDOWS\system32\tdsspopup.dll
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
C:\WINDOWS\system32\url(3).dll
C:\WINDOWS\system32\XHjSvyay.ini
C:\WINDOWS\system32\XHjSvyay.ini2
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-13 au 2008-09-13 ))))))))))))))))))))))))))))))))))))
.
2015-03-12 21:41 . 2007-09-06 21:59 <REP> d-------- C:\Program Files\Rapidown
2015-03-12 21:41 . 2015-03-12 21:41 754 --a--c--- C:\WINDOWS\WORDPAD.INI
2008-09-13 14:47 . 2008-09-13 14:47 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-13 14:47 . 2008-09-13 14:47 <REP> d-------- C:\Documents and Settings\Owner.Olivier\Application Data\Malwarebytes
2008-09-13 14:47 . 2008-09-13 14:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-13 14:47 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-13 14:47 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-13 14:27 . 2008-09-13 14:27 <REP> d-------- C:\Program Files\Trend Micro
2008-09-13 13:05 . 2008-09-13 13:06 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Spyware Terminator
2008-09-11 18:02 . 2008-09-11 18:02 244 --ah----- C:\sqmnoopt06.sqm
2008-09-11 18:02 . 2008-09-11 18:02 244 --ah----- C:\sqmdata06.sqm
2008-09-11 17:46 . 2008-09-13 14:10 1,187,359 --a------ C:\empa.exe
2008-09-11 17:45 . 2008-09-11 17:45 <REP> d-------- C:\Program Files\ESET
2008-09-11 17:45 . 2008-09-11 17:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-09-11 01:24 . 2008-09-13 18:08 <REP> d-------- C:\Program Files\MSA
2008-09-11 01:24 . 2008-09-10 23:40 368,640 --a------ C:\WINDOWS\dtseqrxk.dll
2008-09-11 01:24 . 2008-09-10 23:40 204,800 --a------ C:\WINDOWS\mgxfebsq.dll
2008-09-11 01:24 . 2008-09-10 23:40 192,512 --a------ C:\WINDOWS\fqbewlna.dll
2008-09-11 01:24 . 2008-09-10 23:40 94,208 --a------ C:\WINDOWS\mqgldfvo.exe
2008-09-11 00:18 . 2008-09-11 00:18 <REP> d-------- C:\Program Files\Rundll Errors Fix Wizard
2008-09-11 00:18 . 2005-10-11 15:40 356,352 --a------ C:\WINDOWS\eSellerateEngine.dll
2008-09-11 00:18 . 2003-06-06 12:21 81,920 --a------ C:\WINDOWS\eSellerateControl350.dll
2008-09-11 00:02 . 2008-09-11 00:09 <REP> d-------- C:\Documents and Settings\Owner.Olivier\Application Data\ErrorSmart
2008-09-09 20:15 . 2008-09-09 20:15 <REP> d-------- C:\Program Files\Minimath
2008-09-09 19:46 . 2008-09-09 19:46 <REP> d-------- C:\Program Files\inKline Global
2008-09-08 22:31 . 2008-09-08 22:31 355,584 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-09-08 22:31 . 2008-05-29 09:28 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-09-08 22:30 . 2008-09-08 22:31 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-09-08 21:58 . 2008-09-08 21:58 <REP> d-------- C:\Program Files\MSN Messenger
2008-09-07 21:32 . 2008-09-07 21:32 <REP> d-------- C:\WINDOWS\ERUNT
2008-09-07 21:17 . 2008-09-07 04:40 <REP> d-------- C:\SDFix
2008-09-07 17:22 . 2008-09-07 17:22 <REP> d---s---- C:\Documents and Settings\LocalService\Favoris
2008-09-07 03:33 . 2008-09-02 23:58 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-09-06 11:47 . 2008-09-06 11:47 98 --a------ C:\WINDOWS\wininit.ini
2008-09-04 03:54 . 2008-09-07 21:56 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-30 00:03 . 2008-08-30 00:14 <REP> d-------- C:\Program Files\Cheat Engine
2008-08-30 00:03 . 2007-12-26 17:30 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-08-30 00:03 . 2007-12-26 17:30 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 23:45 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\uTorrent
2008-09-13 23:44 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-13 23:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-13 22:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-13 18:39 --------- d-----w C:\Program Files\Dealio
2008-09-13 18:38 --------- d-----w C:\Program Files\Frets on Fire
2008-09-13 18:22 --------- d-----w C:\Program Files\Spyware Terminator
2008-09-13 18:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-09-13 18:18 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\Spyware Terminator
2008-09-13 16:58 15,762 ----a-w C:\WINDOWS\system32\tmp.reg
2008-09-13 01:14 --------- d-----w C:\Documents and Settings\Simon\Application Data\Spyware Terminator
2008-09-11 23:08 --------- d-----w C:\Program Files\PremierOpinion
2008-09-11 05:24 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\Vso
2008-09-11 03:03 --------- d-----w C:\Program Files\FrostWire
2008-09-10 16:10 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-09-09 02:30 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-09 02:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-09-08 02:03 --------- d-----w C:\Program Files\SpywareBlaster
2008-09-06 15:46 --------- d-----w C:\Program Files\AKProg
2008-09-05 23:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-03 20:25 --------- d-----w C:\Program Files\ACSPMonitor
2008-08-31 18:45 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\dvdcss
2008-08-18 22:44 --------- d-----w C:\Documents and Settings\Simon\Application Data\Audacity
2008-08-11 17:04 --------- d-----w C:\Documents and Settings\Simon\Application Data\LimeWire
2008-08-06 07:02 --------- d-----w C:\Program Files\Windows Live
2008-08-05 19:37 --------- d-----w C:\Documents and Settings\Simon\Application Data\FrostWire
2008-08-04 16:47 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-08-02 03:22 --------- d-----w C:\Program Files\iTunes
2008-08-02 03:22 --------- d-----w C:\Program Files\iPod
2008-07-31 07:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-30 16:05 --------- d-----w C:\Program Files\Search Settings
2008-07-30 16:05 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\Search Settings
2008-07-29 23:59 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\ImgBurn
2008-07-28 15:30 --------- d-----w C:\Documents and Settings\Simon\Application Data\Dealio
2008-07-28 15:25 --------- d-----w C:\Program Files\YouTUBE (TM) movie downloader
2008-07-25 15:35 --------- d-----w C:\Program Files\QuickTime
2008-07-25 15:30 --------- d-----w C:\Program Files\Safari
2008-07-23 17:37 --------- d-----w C:\Program Files\Diablo II
2008-07-21 22:40 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Lavasoft
2008-07-21 02:50 --------- d-----w C:\Program Files\PDM
2008-07-21 02:38 --------- d-----w C:\Program Files\HTV
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 23:29 --------- d-----w C:\Program Files\Warcraft III
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-17 21:27 --------- d-----w C:\Program Files\FlashGet
2008-07-17 06:53 --------- d-----w C:\Program Files\EssNetTools
2008-07-17 05:34 271,872 ----a-w C:\WINDOWS\system32\upx.exe
2008-07-16 21:42 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\FileZilla
2008-07-16 21:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-16 21:36 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-16 21:28 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
2008-07-16 16:03 --------- d-----w C:\Documents and Settings\Simon\Application Data\TmpRecentIcons
2008-07-16 03:41 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\AdobeUM
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2007-09-13 01:02 47,360 ----a-w C:\Documents and Settings\Owner.Olivier\Application Data\pcouffin.sys
.
------- Sigcheck -------
2007-06-13 09:22 2716160 6f341b3ca16af1e82d1fd2a54177e997 C:\WINDOWS\explorer.exe
2007-06-13 09:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 15:00 1884672 90e794c5d2d368686fe71b4a0354462c C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 22:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\explorer.exe
2007-06-13 09:22 2716160 6f341b3ca16af1e82d1fd2a54177e997 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Downloads\uTorrent.exe" [2008-08-27 267056]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-09-10 1783808]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=zufueu.dll yukanx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BigFix.lnk]
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.Olivier^Menu Démarrer^Programmes^Démarrage^Rapidown.lnk]
backup=C:\WINDOWS\pss\Rapidown.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.Olivier^Menu Démarrer^Programmes^Démarrage^Y'z Toolbar.lnk]
backup=C:\WINDOWS\pss\Y'z Toolbar.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 05:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 15:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-10 15:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-03 18:29 165784 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a--c--- 2005-08-05 23:34 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-07-23 03:14 1994800 C:\PROGRA~1\FlashGet\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-07-10 03:01 169984 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 14:44 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 15:24 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 15:14 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2005-07-12 21:05 1117184 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-06-29 00:01 2512128 C:\WINDOWS\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-08-06 20:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
--a------ 2005-12-09 20:44 139264 C:\Program Files\Digital Media Reader\readericon45G.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-03-28 19:58 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-10 14:30 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Transcode360]
--a------ 2006-05-02 13:01 192512 C:\Program Files\Transcode360\Transcode360Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
--a------ 2008-08-17 15:38 267056 C:\Program Files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
--a------ 2007-02-12 17:21 734624 c:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-09-17 01:07 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PrismXL"=2 (0x2)
"NVSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"AVG Anti-Spyware Guard"=2 (0x2)
"RemoteRegistry"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"idsvc"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"=
"C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Downloads\\uTorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Service de Media Center Extender
"3390:TCP"= 3390:TCP:Services Media Center à distance
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-09-10 141312]
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 28160]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
R3 AmdTools;AMD Special Tools Driver;C:\WINDOWS\system32\DRIVERS\AmdTools.sys [2006-06-27 31744]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-08 355584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{7287293E-B0BE-4A31-B52B-EA15F57679E3} - (no file)
ShellExecuteHooks-{935FA400-243D-11D3-B06E-857B2AE2BE64} - (no file)
MSConfigStartUp-COMODO Firewall Pro - C:\Program Files\Comodo\Firewall\cfp.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Owner.Olivier\Application Data\Mozilla\Firefox\Profiles\vs0r0ilf.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Download Manager\npfpdlm.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-13 19:48:07
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-09-13 19:50:26
ComboFix-quarantined-files.txt 2008-09-13 23:50:02
Avant-CF: 29,962,620,928 octets libres
AprŠs-CF: 30,272,950,272 octets libres
311 --- E O F --- 2008-09-08 01:56:10
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1336 [GMT -4:00]
Lancé depuis: C:\Documents and Settings\Owner.Olivier\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MCX1\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Documents and Settings\Owner.Olivier\Application Data\inst.exe
C:\Documents and Settings\Simon\Cookies\simon@mediaarea[2].txt
C:\Program Files\messenger\msnmsgr.exe
C:\WINDOWS\system32\ieirlruc.ini
C:\WINDOWS\system32\tdpmma.dll
C:\WINDOWS\system32\tdsspopup.dll
C:\WINDOWS\system32\tdsspopup1.url
C:\WINDOWS\system32\tdsspopup2.url
C:\WINDOWS\system32\tdsspopup3.url
C:\WINDOWS\system32\url(3).dll
C:\WINDOWS\system32\XHjSvyay.ini
C:\WINDOWS\system32\XHjSvyay.ini2
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-13 au 2008-09-13 ))))))))))))))))))))))))))))))))))))
.
2015-03-12 21:41 . 2007-09-06 21:59 <REP> d-------- C:\Program Files\Rapidown
2015-03-12 21:41 . 2015-03-12 21:41 754 --a--c--- C:\WINDOWS\WORDPAD.INI
2008-09-13 14:47 . 2008-09-13 14:47 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-13 14:47 . 2008-09-13 14:47 <REP> d-------- C:\Documents and Settings\Owner.Olivier\Application Data\Malwarebytes
2008-09-13 14:47 . 2008-09-13 14:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-13 14:47 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-13 14:47 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-13 14:27 . 2008-09-13 14:27 <REP> d-------- C:\Program Files\Trend Micro
2008-09-13 13:05 . 2008-09-13 13:06 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Spyware Terminator
2008-09-11 18:02 . 2008-09-11 18:02 244 --ah----- C:\sqmnoopt06.sqm
2008-09-11 18:02 . 2008-09-11 18:02 244 --ah----- C:\sqmdata06.sqm
2008-09-11 17:46 . 2008-09-13 14:10 1,187,359 --a------ C:\empa.exe
2008-09-11 17:45 . 2008-09-11 17:45 <REP> d-------- C:\Program Files\ESET
2008-09-11 17:45 . 2008-09-11 17:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-09-11 01:24 . 2008-09-13 18:08 <REP> d-------- C:\Program Files\MSA
2008-09-11 01:24 . 2008-09-10 23:40 368,640 --a------ C:\WINDOWS\dtseqrxk.dll
2008-09-11 01:24 . 2008-09-10 23:40 204,800 --a------ C:\WINDOWS\mgxfebsq.dll
2008-09-11 01:24 . 2008-09-10 23:40 192,512 --a------ C:\WINDOWS\fqbewlna.dll
2008-09-11 01:24 . 2008-09-10 23:40 94,208 --a------ C:\WINDOWS\mqgldfvo.exe
2008-09-11 00:18 . 2008-09-11 00:18 <REP> d-------- C:\Program Files\Rundll Errors Fix Wizard
2008-09-11 00:18 . 2005-10-11 15:40 356,352 --a------ C:\WINDOWS\eSellerateEngine.dll
2008-09-11 00:18 . 2003-06-06 12:21 81,920 --a------ C:\WINDOWS\eSellerateControl350.dll
2008-09-11 00:02 . 2008-09-11 00:09 <REP> d-------- C:\Documents and Settings\Owner.Olivier\Application Data\ErrorSmart
2008-09-09 20:15 . 2008-09-09 20:15 <REP> d-------- C:\Program Files\Minimath
2008-09-09 19:46 . 2008-09-09 19:46 <REP> d-------- C:\Program Files\inKline Global
2008-09-08 22:31 . 2008-09-08 22:31 355,584 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-09-08 22:31 . 2008-05-29 09:28 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-09-08 22:30 . 2008-09-08 22:31 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-09-08 21:58 . 2008-09-08 21:58 <REP> d-------- C:\Program Files\MSN Messenger
2008-09-07 21:32 . 2008-09-07 21:32 <REP> d-------- C:\WINDOWS\ERUNT
2008-09-07 21:17 . 2008-09-07 04:40 <REP> d-------- C:\SDFix
2008-09-07 17:22 . 2008-09-07 17:22 <REP> d---s---- C:\Documents and Settings\LocalService\Favoris
2008-09-07 03:33 . 2008-09-02 23:58 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-09-06 11:47 . 2008-09-06 11:47 98 --a------ C:\WINDOWS\wininit.ini
2008-09-04 03:54 . 2008-09-07 21:56 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-30 00:03 . 2008-08-30 00:14 <REP> d-------- C:\Program Files\Cheat Engine
2008-08-30 00:03 . 2007-12-26 17:30 1,970,176 --a------ C:\WINDOWS\system32\d3dx9.dll
2008-08-30 00:03 . 2007-12-26 17:30 679,936 --a------ C:\WINDOWS\system32\D3DX81ab.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-13 23:45 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\uTorrent
2008-09-13 23:44 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-13 23:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-13 22:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-13 18:39 --------- d-----w C:\Program Files\Dealio
2008-09-13 18:38 --------- d-----w C:\Program Files\Frets on Fire
2008-09-13 18:22 --------- d-----w C:\Program Files\Spyware Terminator
2008-09-13 18:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-09-13 18:18 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\Spyware Terminator
2008-09-13 16:58 15,762 ----a-w C:\WINDOWS\system32\tmp.reg
2008-09-13 01:14 --------- d-----w C:\Documents and Settings\Simon\Application Data\Spyware Terminator
2008-09-11 23:08 --------- d-----w C:\Program Files\PremierOpinion
2008-09-11 05:24 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\Vso
2008-09-11 03:03 --------- d-----w C:\Program Files\FrostWire
2008-09-10 16:10 141,312 ----a-w C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-09-09 02:30 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-09 02:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-09-08 02:03 --------- d-----w C:\Program Files\SpywareBlaster
2008-09-06 15:46 --------- d-----w C:\Program Files\AKProg
2008-09-05 23:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-03 20:25 --------- d-----w C:\Program Files\ACSPMonitor
2008-08-31 18:45 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\dvdcss
2008-08-18 22:44 --------- d-----w C:\Documents and Settings\Simon\Application Data\Audacity
2008-08-11 17:04 --------- d-----w C:\Documents and Settings\Simon\Application Data\LimeWire
2008-08-06 07:02 --------- d-----w C:\Program Files\Windows Live
2008-08-05 19:37 --------- d-----w C:\Documents and Settings\Simon\Application Data\FrostWire
2008-08-04 16:47 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-08-02 03:22 --------- d-----w C:\Program Files\iTunes
2008-08-02 03:22 --------- d-----w C:\Program Files\iPod
2008-07-31 07:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-30 16:05 --------- d-----w C:\Program Files\Search Settings
2008-07-30 16:05 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\Search Settings
2008-07-29 23:59 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\ImgBurn
2008-07-28 15:30 --------- d-----w C:\Documents and Settings\Simon\Application Data\Dealio
2008-07-28 15:25 --------- d-----w C:\Program Files\YouTUBE (TM) movie downloader
2008-07-25 15:35 --------- d-----w C:\Program Files\QuickTime
2008-07-25 15:30 --------- d-----w C:\Program Files\Safari
2008-07-23 17:37 --------- d-----w C:\Program Files\Diablo II
2008-07-21 22:40 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Lavasoft
2008-07-21 02:50 --------- d-----w C:\Program Files\PDM
2008-07-21 02:38 --------- d-----w C:\Program Files\HTV
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 23:29 --------- d-----w C:\Program Files\Warcraft III
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-17 21:27 --------- d-----w C:\Program Files\FlashGet
2008-07-17 06:53 --------- d-----w C:\Program Files\EssNetTools
2008-07-17 05:34 271,872 ----a-w C:\WINDOWS\system32\upx.exe
2008-07-16 21:42 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\FileZilla
2008-07-16 21:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-16 21:36 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-16 21:28 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
2008-07-16 16:03 --------- d-----w C:\Documents and Settings\Simon\Application Data\TmpRecentIcons
2008-07-16 03:41 --------- d-----w C:\Documents and Settings\Owner.Olivier\Application Data\AdobeUM
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2007-09-13 01:02 47,360 ----a-w C:\Documents and Settings\Owner.Olivier\Application Data\pcouffin.sys
.
------- Sigcheck -------
2007-06-13 09:22 2716160 6f341b3ca16af1e82d1fd2a54177e997 C:\WINDOWS\explorer.exe
2007-06-13 09:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 15:00 1884672 90e794c5d2d368686fe71b4a0354462c C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2008-04-13 22:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd C:\WINDOWS\SoftwareDistribution\Download\23ec66f2314a80d718b5483ab6e865af\explorer.exe
2007-06-13 09:22 2716160 6f341b3ca16af1e82d1fd2a54177e997 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="C:\Downloads\uTorrent.exe" [2008-08-27 267056]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"RegistryMechanic"="C:\Program Files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-09-10 1783808]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=zufueu.dll yukanx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BigFix.lnk]
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.Olivier^Menu Démarrer^Programmes^Démarrage^Rapidown.lnk]
backup=C:\WINDOWS\pss\Rapidown.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.Olivier^Menu Démarrer^Programmes^Démarrage^Y'z Toolbar.lnk]
backup=C:\WINDOWS\pss\Y'z Toolbar.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 05:25 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 15:21 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-10 15:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2007-04-03 18:29 165784 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--a--c--- 2005-08-05 23:34 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-07-23 03:14 1994800 C:\PROGRA~1\FlashGet\flashget.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-07-10 03:01 169984 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-06-08 14:44 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-06-08 15:24 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-06-08 15:14 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
--a------ 2005-07-12 21:05 1117184 C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
--a------ 2007-06-29 00:01 2512128 C:\WINDOWS\system32\oodtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2007-08-06 20:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\readericon]
--a------ 2005-12-09 20:44 139264 C:\Program Files\Digital Media Reader\readericon45G.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-03-28 19:58 1271032 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-07-10 14:30 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Transcode360]
--a------ 2006-05-02 13:01 192512 C:\Program Files\Transcode360\Transcode360Tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
--a------ 2008-08-17 15:38 267056 C:\Program Files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
--a------ 2007-02-12 17:21 734624 c:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-09-17 01:07 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PrismXL"=2 (0x2)
"NVSvc"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"AVG Anti-Spyware Guard"=2 (0x2)
"RemoteRegistry"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"idsvc"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\CyberLink\\PCM4Everio\\PCM4Everio.exe"=
"C:\\Program Files\\CyberLink\\PCM4Everio\\EverioService.exe"=
"C:\\Program Files\\CyberLink\\PowerDirector Express\\PDX.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Downloads\\uTorrent.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Service de Media Center Extender
"3390:TCP"= 3390:TCP:Services Media Center à distance
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-07-01 34312]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-09-10 141312]
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 28160]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
R3 AmdTools;AMD Special Tools Driver;C:\WINDOWS\system32\DRIVERS\AmdTools.sys [2006-06-27 31744]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-08 355584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{7287293E-B0BE-4A31-B52B-EA15F57679E3} - (no file)
ShellExecuteHooks-{935FA400-243D-11D3-B06E-857B2AE2BE64} - (no file)
MSConfigStartUp-COMODO Firewall Pro - C:\Program Files\Comodo\Firewall\cfp.exe
MSConfigStartUp-Uniblue RegistryBooster 2 - C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Owner.Olivier\Application Data\Mozilla\Firefox\Profiles\vs0r0ilf.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Download Manager\npfpdlm.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-13 19:48:07
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-09-13 19:50:26
ComboFix-quarantined-files.txt 2008-09-13 23:50:02
Avant-CF: 29,962,620,928 octets libres
AprŠs-CF: 30,272,950,272 octets libres
311 --- E O F --- 2008-09-08 01:56:10
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
14 sept. 2008 à 01:57
14 sept. 2008 à 01:57
Refais le scan avec MBAM en mode sans échec cette fois-ci.
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
14 sept. 2008 à 02:00
14 sept. 2008 à 02:00
Je vais faire sa demain. Merci ! @+
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 295
14 sept. 2008 à 02:00
14 sept. 2008 à 02:00
Ok, bonne nuit.
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
14 sept. 2008 à 02:13
14 sept. 2008 à 02:13
J'oubliait , merci beacoup pour l'aide !
@+ et a demain.
@+ et a demain.
olivier_123
Messages postés
290
Date d'inscription
jeudi 4 janvier 2007
Statut
Membre
Dernière intervention
16 mai 2009
7
14 sept. 2008 à 21:53
14 sept. 2008 à 21:53
Bon je vais faire le scan. Je reviens, le scan devrait prendre environ 1 heure.
@+
@+