Trojan Drop.Kryptik.EHK

Bonjour,

Depuis peu je reçois régulièrement et toujours par deux des alertes de mon antivirus Avira de la sorte : (voir ci-dessous) et ce toujours le même dossier, juste le nom de fichier changeant.
Si besoin est je peux vous envoyez un rapport Hijack..
Merci d'avance!

Virus or unwanted program 'TR/Drop.Kryptik.EHK [trojan]'
detected in file 'C:\Users\(nom)\AppData\Local\Temp\5E20.tmp.
Action performed: Deny access

39 réponses

Résumé de la discussion

Les alertes répétées d'Avira signalent le cheval de Troie 'TR/Drop.Kryptik.EHK' dans un fichier temporaire situé dans le dossier AppData, avec des noms de fichiers différents mais le même chemin sur l'ordinateur. Plusieurs recommandations préconisent un nettoyage en profondeur avec Malwarebytes en analyse complète, puis la suppression des éléments infectés et le redémarrage si nécessaire, afin d'éliminer les traces laissées par l'infection. D'autres suggestions incluent des outils comme List_Kill'em, Gmer, ZHPDiag et HijackThis pour dépister les rootkits, les entrées de registre et les modules malveillants, avec des scripts ou rapports à partager pour analyse.

Bobot (l’IA à votre service)
  1. Autre :
    inetcpl.cpl=no => Format Non supporté
    0
    1. il faudrait retirer cette ligne :

      inetcpl.cpl=no

      dans le fichier control.ini
      0
      1. Par contre ce n'est possible que avec le premier lien de Nicolas Coolman.

        ZHPFix v1.12.3102 by Nicolas Coolman - Rapport de suppression du 26/05/2010 19:42:25
        Fichier d'export Registre : C:\ZHPExportRegistry-26-05-2010-19-42-25.txt
        Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
        Contact : nicolascoolman@yahoo.fr

        Processus mémoire :
        (Néant)

        Module mémoire :
        (Néant)

        Clé du Registre :
        (Néant)

        Valeur du Registre :
        O4 - HKLM\..\policies\Explorer: [AllowLegacyWebView] Data="1" => Valeur absente
        O4 - HKLM\..\policies\Explorer: [AllowUnhashedWebView] Data="1" => Valeur absente

        Elément de données du Registre :
        (Néant)

        Préférences navigateur :
        (Néant)

        Dossier :
        (Néant)

        Fichier :
        (Néant)

        Logiciel :
        (Néant)

        Script Registre :
        (Néant)

        Master Boot Record :
        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys splx.sys >>UNKNOWN [0x851D2938]<<
        kernel: MBR read successfully
        detected MBR rootkit hooks:
        \Driver\atapi -> 0x8521b1f8
        Warning: possible MBR rootkit infection !
        user & kernel MBR OK
        Use "Recovery Console" command "fixmbr" to clear infection !

        Resultat après le fix :
        Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

        device: opened successfully
        user: MBR read successfully
        kernel: MBR read successfully
        user & kernel MBR OK

        Autre :
        O5 - control.ini: inetcpl.cpl=no => Format Non supporté

        Récapitulatif :
        Processus mémoire : 0
        Module mémoire : 0
        Clé du Registre : 0
        Valeur du Registre : 2
        Elément de données du Registre : 0
        Dossier : 0
        Fichier : 0
        Logiciel : 0
        Master Boot Record : 19
        Préférences navigateur : 0
        Autre : 1

        End of the scan
        0
        1. ▶ Relance ZHPDiag ( Clic droit " Executer en tant qu'administrateur " sous vista )

          ▶ fais un scan puis cette fois-ci cliques sur l'icone en forme d'écusson vert "ZHPFix".

          ▶ ZHPFix se lancera, clique maintenant sur le "H" bleu ( coller les lignes helper )

          ▶ copie/colle ce qui se trouve en gras ci-dessous :

          O4 - HKLM\..\policies\Explorer: [AllowLegacyWebView] Data="1"
          O4 - HKLM\..\policies\Explorer: [AllowUnhashedWebView] Data="1"
          O5 - control.ini: inetcpl.cpl=no
          MBRFix


          ▶ Clique sur "Ok" , puis "Tous" et enfin "Nettoyer".

          ▶ Copie/Colle le rapport à l'écran dans ton prochain message
          0
          1. http://www.cijoint.fr/cjlink.php?file=cj201005/cijRVWqcjd.txt
            0
            1. ▶ Télécharge ZHPDiag (de Nicolas Coolman)

              ou :ZHPDiag

              ▶ Enregistre le sur ton Bureau.

              Une fois le téléchargement achevé,

              ▶ lance ZHPDiag.exe et clique sur Unzip dans la fenêtre qui s'ouvre.

              ▶ Clique sur le tournevis puis sur Tous pour cocher toutes les cases des options.

              ▶ Clique sur la loupe pour lancer l'analyse.

              A la fin de l'analyse,

              ▶ clique sur l'appareil photo et enregistre le rapport sur ton Bureau.

              Pour me le transmettre clique sur ce lien :

              http://www.cijoint.fr/

              ▶ Clique sur Parcourir et cherche le fichier C:\Documents and settings\le_nom_de_ta_session\.ZHPDiag.txt

              ▶ Clique sur Ouvrir.

              ▶ Clique sur "Cliquez ici pour déposer le fichier".

              Un lien de cette forme :

              http://www.cijoint.fr/cjlink.php?file=cj200905/cib7SU.txt

              est ajouté dans la page.

              ▶ Copie ce lien dans ta réponse.
              0
              1. d'accord, et maintenant, bel et bien fini? on peut mettre le sujet en résolu? voir le supprimer si possible vu que c'est du cas par cas il servira à personne, en tout cas merci de ta patience!
                0
                1. non ce sont des redirections infectieuses on ne peut rien faire ..

                  0
                  1. Non google fonctionne à nouveaux donc pour moi tout va bien. Et il n'y a pas moyen de signaler les sites auxquels les recherches google me renvoyés auparavant? Une manière de porter plainte pour les empêcher d'avoir plus de monde sur leur page ect
                    0
                    1. ok tu as encore des soucis ou on peut finaliser ?
                      0
                      1. Avira AntiVir Personal
                        Date de création du fichier de rapport : mardi 25 mai 2010 19:11

                        La recherche porte sur 2155025 souches de virus.

                        Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
                        Numéro de série : 0000149996-ADJIE-0000001
                        Plateforme : Windows Vista
                        Version de Windows : (Service Pack 1) [6.0.6001]
                        Mode Boot : Démarré normalement
                        Identifiant : SYSTEM
                        Nom de l'ordinateur : PC-DE-BASTIEN

                        Informations de version :
                        BUILD.DAT : 9.0.0.75 21698 Bytes 22/01/2010 23:14:00
                        AVSCAN.EXE : 9.0.3.10 466689 Bytes 24/05/2010 19:20:48
                        AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
                        LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
                        LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
                        VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 19:20:41
                        VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 19:20:42
                        VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 19:20:42
                        VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 19:20:42
                        VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 19:20:43
                        VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 19:20:45
                        VBASE006.VDF : 7.10.6.83 2048 Bytes 15/04/2010 19:20:45
                        VBASE007.VDF : 7.10.6.84 2048 Bytes 15/04/2010 19:20:45
                        VBASE008.VDF : 7.10.6.85 2048 Bytes 15/04/2010 19:20:45
                        VBASE009.VDF : 7.10.6.86 2048 Bytes 15/04/2010 19:20:45
                        VBASE010.VDF : 7.10.6.87 2048 Bytes 15/04/2010 19:20:45
                        VBASE011.VDF : 7.10.6.88 2048 Bytes 15/04/2010 19:20:45
                        VBASE012.VDF : 7.10.6.89 2048 Bytes 15/04/2010 19:20:45
                        VBASE013.VDF : 7.10.6.90 2048 Bytes 15/04/2010 19:20:45
                        VBASE014.VDF : 7.10.6.123 126464 Bytes 19/04/2010 19:20:45
                        VBASE015.VDF : 7.10.6.152 123392 Bytes 21/04/2010 19:20:45
                        VBASE016.VDF : 7.10.6.178 122880 Bytes 22/04/2010 19:20:45
                        VBASE017.VDF : 7.10.6.206 120320 Bytes 26/04/2010 19:20:45
                        VBASE018.VDF : 7.10.6.232 99328 Bytes 28/04/2010 19:20:45
                        VBASE019.VDF : 7.10.7.2 155648 Bytes 30/04/2010 19:20:46
                        VBASE020.VDF : 7.10.7.26 119808 Bytes 04/05/2010 19:20:46
                        VBASE021.VDF : 7.10.7.51 118272 Bytes 06/05/2010 19:20:46
                        VBASE022.VDF : 7.10.7.75 404992 Bytes 10/05/2010 19:20:46
                        VBASE023.VDF : 7.10.7.100 125440 Bytes 13/05/2010 19:20:46
                        VBASE024.VDF : 7.10.7.119 177664 Bytes 17/05/2010 19:20:47
                        VBASE025.VDF : 7.10.7.139 129024 Bytes 19/05/2010 19:20:47
                        VBASE026.VDF : 7.10.7.157 145920 Bytes 21/05/2010 19:20:47
                        VBASE027.VDF : 7.10.7.158 2048 Bytes 21/05/2010 19:20:47
                        VBASE028.VDF : 7.10.7.159 2048 Bytes 21/05/2010 19:20:47
                        VBASE029.VDF : 7.10.7.160 2048 Bytes 21/05/2010 19:20:47
                        VBASE030.VDF : 7.10.7.161 2048 Bytes 21/05/2010 19:20:47
                        VBASE031.VDF : 7.10.7.168 105472 Bytes 25/05/2010 15:11:20
                        Version du moteur : 8.2.1.242
                        AEVDF.DLL : 8.1.2.0 106868 Bytes 24/05/2010 19:20:48
                        AESCRIPT.DLL : 8.1.3.29 1343866 Bytes 24/05/2010 19:20:48
                        AESCN.DLL : 8.1.6.1 127347 Bytes 24/05/2010 19:20:48
                        AESBX.DLL : 8.1.3.1 254324 Bytes 24/05/2010 19:20:48
                        AERDL.DLL : 8.1.4.6 541043 Bytes 24/05/2010 19:20:48
                        AEPACK.DLL : 8.2.1.1 426358 Bytes 24/05/2010 19:20:48
                        AEOFFICE.DLL : 8.1.1.0 201081 Bytes 24/05/2010 19:20:47
                        AEHEUR.DLL : 8.1.1.27 2670967 Bytes 24/05/2010 19:20:47
                        AEHELP.DLL : 8.1.11.3 242039 Bytes 24/05/2010 19:20:47
                        AEGEN.DLL : 8.1.3.9 377203 Bytes 24/05/2010 19:20:47
                        AEEMU.DLL : 8.1.2.0 393588 Bytes 24/05/2010 19:20:47
                        AECORE.DLL : 8.1.15.3 192886 Bytes 24/05/2010 19:20:47
                        AEBB.DLL : 8.1.1.0 53618 Bytes 24/05/2010 19:20:47
                        AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
                        AVPREF.DLL : 9.0.3.0 44289 Bytes 24/05/2010 19:20:48
                        AVREP.DLL : 8.0.0.7 159784 Bytes 24/05/2010 19:20:49
                        AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
                        AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
                        AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
                        SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
                        SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
                        NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
                        RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 24/05/2010 19:20:41
                        RCTEXT.DLL : 9.0.73.0 88321 Bytes 24/05/2010 19:20:41

                        Configuration pour la recherche actuelle :
                        Nom de la tâche...............................: Contrôle intégral du système
                        Fichier de configuration......................: c:\program files\avira\antivir desktop\sysscan.avp
                        Documentation.................................: bas
                        Action principale.............................: interactif
                        Action secondaire.............................: ignorer
                        Recherche sur les secteurs d'amorçage maître..: marche
                        Recherche sur les secteurs d'amorçage.........: marche
                        Secteurs d'amorçage...........................: C:, D:,
                        Recherche dans les programmes actifs..........: marche
                        Recherche en cours sur l'enregistrement.......: marche
                        Recherche de Rootkits.........................: marche
                        Contrôle d'intégrité de fichiers système......: arrêt
                        Fichier mode de recherche.....................: Tous les fichiers
                        Recherche sur les archives....................: marche
                        Limiter la profondeur de récursivité..........: 20
                        Archive Smart Extensions......................: marche
                        Heuristique de macrovirus.....................: marche
                        Heuristique fichier...........................: moyen

                        Début de la recherche : mardi 25 mai 2010 19:11

                        La recherche d'objets cachés commence.
                        '127693' objets ont été contrôlés, '0' objets cachés ont été trouvés.

                        La recherche sur les processus démarrés commence :
                        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'avscan.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'avcenter.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'CCC.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'wuauclt.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'epmworker.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'Generic.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'wmpnetwk.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'wmpnscfg.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'iPodService.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'avgnt.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'jusched.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'avgas.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'Application Launcher.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'apdproxy.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'iTunesHelper.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ASScrPro.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'P4P.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'SynTPEnh.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'MOM.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'RtHDVCpl.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'InCD.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'WDC.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'KBFiltr.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'WmiPrvSE.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ATKOSD.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ACEngSvr.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'BatteryLife.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ACMON.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'wcourier.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ATKOSD2.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'HControl.exe' - '1' module(s) sont contrôlés
                        Module OK -> 'C:\Program Files\ATK Hotkey\Hcontrol.exe'
                        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                        Processus de recherche 'conime.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'explorer.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'dwm.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'taskeng.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'SearchIndexer.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'spmgr.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'PnkBstrA.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'LSSrvc.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'InCDsrv.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'guard.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'avguard.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'sched.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'spoolsv.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'GFNEXSrv.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ASLDRSrv.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'ADSMSrv.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'Ati2evxx.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'SLsvc.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'audiodg.exe' - '0' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'Ati2evxx.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'svchost.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'lsm.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'lsass.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'winlogon.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'services.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'wininit.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'csrss.exe' - '1' module(s) sont contrôlés
                        Processus de recherche 'smss.exe' - '1' module(s) sont contrôlés
                        '72' processus ont été contrôlés avec '72' modules

                        La recherche sur les secteurs d'amorçage maître commence :
                        Secteur d'amorçage maître HD0
                        [INFO] Aucun virus trouvé !

                        La recherche sur les secteurs d'amorçage commence :
                        Secteur d'amorçage 'C:\'
                        [INFO] Aucun virus trouvé !
                        Secteur d'amorçage 'D:\'
                        [INFO] Aucun virus trouvé !

                        La recherche sur les renvois aux fichiers exécutables (registre) commence :
                        Le registre a été contrôlé ( '47' fichiers).

                        La recherche sur les fichiers sélectionnés commence :

                        Recherche débutant dans 'C:\' <VistaOS>
                        C:\hiberfil.sys
                        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                        [REMARQUE] Ce fichier est un fichier système Windows.
                        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                        C:\pagefile.sys
                        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                        [REMARQUE] Ce fichier est un fichier système Windows.
                        [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
                        C:\Program Files\ATK Hotkey\HControl.exe
                        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                        C:\Program Files\List_Kill'em\xwkkpyx.pif
                        [RESULTAT] Le fichier contient un programme exécutable. Cependant, celui-ci se dissimule sous une extension de fichier inoffensive (HIDDENEXT/Crypted)
                        C:\Qoobox\Quarantine\C\Users\Bastien\AppData\Roaming\Mozilla\Firefox\Profiles\gsu5k7j9.default\extensions\{93ea4067-1ad9-4c8f-b747-364df19455b0}\chrome\xulcache.jar.vir
                        [0] Type d'archive: ZIP
                        --> content/overlay.xul
                        [RESULTAT] Contient le cheval de Troie TR/Spy.B.1
                        C:\Users\Bastien\AppData\Roaming\Mozilla\Firefox\Profiles\gsu5k7j9.default\extensions\{da6d1c8d-23f9-48d7-bbca-73926b2b0197}\chrome\xulcache.jar
                        [0] Type d'archive: ZIP
                        --> content/overlay.xul
                        [RESULTAT] Contient le cheval de Troie TR/Spy.B.1
                        C:\Windows\System32\drivers\sptd.sys
                        [AVERTISSEMENT] Impossible d'ouvrir le fichier !
                        Recherche débutant dans 'D:\' <DATA>
                        D:\Disque dur\Bastien\virtualdubmod_1_5_10_1_all_inclusive\VirtualDubMOD_1.5.10.1_b2439_fix_+_aide_Fr.exe
                        [RESULTAT] Contient le modèle de détection du logiciel espion ou publicitaire ADSPY/Rabio.PO

                        Début de la désinfection :
                        C:\Program Files\List_Kill'em\xwkkpyx.pif
                        [RESULTAT] Le fichier contient un programme exécutable. Cependant, celui-ci se dissimule sous une extension de fichier inoffensive (HIDDENEXT/Crypted)
                        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4c671456.qua' !
                        C:\Qoobox\Quarantine\C\Users\Bastien\AppData\Roaming\Mozilla\Firefox\Profiles\gsu5k7j9.default\extensions\{93ea4067-1ad9-4c8f-b747-364df19455b0}\chrome\xulcache.jar.vir
                        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4c681455.qua' !
                        C:\Users\Bastien\AppData\Roaming\Mozilla\Firefox\Profiles\gsu5k7j9.default\extensions\{da6d1c8d-23f9-48d7-bbca-73926b2b0197}\chrome\xulcache.jar
                        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '48514d76.qua' !
                        D:\Disque dur\Bastien\virtualdubmod_1_5_10_1_all_inclusive\VirtualDubMOD_1.5.10.1_b2439_fix_+_aide_Fr.exe
                        [RESULTAT] Contient le modèle de détection du logiciel espion ou publicitaire ADSPY/Rabio.PO
                        [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4c6e1449.qua' !

                        Fin de la recherche : mardi 25 mai 2010 20:16
                        Temps nécessaire: 58:23 Minute(s)

                        La recherche a été effectuée intégralement

                        25532 Les répertoires ont été contrôlés
                        395731 Des fichiers ont été contrôlés
                        4 Des virus ou programmes indésirables ont été trouvés
                        0 Des fichiers ont été classés comme suspects
                        0 Des fichiers ont été supprimés
                        0 Des virus ou programmes indésirables ont été réparés
                        4 Les fichiers ont été déplacés dans la quarantaine
                        0 Les fichiers ont été renommés
                        5 Impossible de contrôler des fichiers
                        395722 Fichiers non infectés
                        3300 Les archives ont été contrôlées
                        5 Avertissements
                        6 Consignes
                        127693 Des objets ont été contrôlés lors du Rootkitscan
                        0 Des objets cachés ont été trouvés
                        0
                        1. bien fais donc un scan avec antivir et poste le rapport
                          0
                          1. Depuis peu je reçois régulièrement et toujours par deux des alertes de mon antivirus Avira de la sorte : (voir ci-dessous) et ce toujours le même dossier, juste le nom de fichier changeant.
                            Si besoin est je peux vous envoyez un rapport Hijack..
                            Merci d'avance!

                            Virus or unwanted program 'TR/Drop.Kryptik.EHK [trojan]'
                            detected in file 'C:\Users\(nom)\AppData\Local\Temp\5E20.tmp.
                            Action performed: Deny access

                            0
                            1. Ah effectivement, autant pour moi!
                              Depuis la première action je ne reçois plus de message de mon antivirus, par contre hier "ça" me rediriger vers d'autres sites (autre moteur de recherche). Aujourd'hui ça n'en a plus l'air.
                              Et donc pour répondre à ta question c'est Avira qui me le détecter.
                              0
                          2. qui te detectait le trojan Kriptik! ?
                            0
                            1. Heu je n'ai eu aucun message spécial, et ce trojan je l'ai vu dans aucun rapport.
                              0
                          3. ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤

                            User : Bastien (Administrateurs)
                            Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
                            Start at: 17:18:04 | 25/05/2010

                            Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
                            Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                            Internet Explorer 7.0.6001.18000
                            Windows Firewall Status : Disabled

                            C:\ -> Disque fixe local | 74,52 Go (20,77 Go free) [VistaOS] | NTFS
                            D:\ -> Disque fixe local | 67,69 Go (19,65 Go free) [DATA] | NTFS
                            E:\ -> Disque CD-ROM

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                            C:\Windows\System32\smss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\LogonUI.exe
                            C:\Windows\system32\Ati2evxx.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\Ati2evxx.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                            C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                            C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
                            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            C:\Windows\system32\PnkBstrA.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\userinit.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\Explorer.EXE
                            C:\Windows\system32\runonce.exe
                            C:\Windows\system32\cmd.exe
                            C:\Windows\system32\conime.exe
                            C:\Program Files\ATK Hotkey\Hcontrol.exe
                            C:\Program Files\ATKOSD2\ATKOSD2.exe
                            C:\Program Files\Wireless Console 2\wcourier.exe
                            C:\Program Files\ASUS\Splendid\ACMON.exe
                            C:\Program Files\P4G\BatteryLife.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Windows\System32\ACEngSvr.exe
                            C:\Program Files\ATK Hotkey\ATKOSD.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Program Files\ATK Hotkey\KBFiltr.exe
                            C:\Program Files\ATK Hotkey\WDC.exe
                            C:\Program Files\List_Kill'em\ERUNT.EXE
                            C:\Program Files\List_Kill'em\pv.exe

                            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                            Quarantined & Deleted !! : C:\ProgramData\addr_file.html

                            Quarantined & Deleted !! : C:\Windows\System32\ealregsnapshot1.reg
                            Quarantined & Deleted !! : C:\Users\Bastien\AppData\Local\fusioncache.dat
                            Quarantined & Deleted !! : C:\Users\Bastien\AppData\Local\GDIPFONTCACHEV1.DAT
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$I41U2KL.ini
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$I5U2OPR.ini
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$I5YN70P.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$I6CATCI.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$IE8KIB7.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$IQBDMVX.txt
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$IST9GY3.txt
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$IVCRDB9.lnk
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$IW0A79H.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$IY4ZKJ2.xls
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$R5YN70P.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$R6CATCI.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$RE8KIB7.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$RQBDMVX.txt
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$RST9GY3.txt
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$RVCRDB9.lnk
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$RW0A79H.exe
                            Deleted !! : C:\$Recycle.bin\S-1-5-21-327584761-1432533102-1209779725-1000\$RY4ZKJ2.xls

                            =======
                            Hosts :
                            =======

                            127.0.0.1 localhost

                            ========
                            Registry
                            ========

                            Deleted : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                            Deleted : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                            Deleted : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                            Deleted : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                            Deleted : HKLM\Software\Conduit
                            =================
                            Internet Explorer
                            =================

                            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                            Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                            Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                            Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                            Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                            Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                            Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                            ===============
                            Security Center
                            ===============

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                            cval REG_DWORD 1 (0x1)
                            FirewallDisableNotify REG_DWORD 0 (0x0)
                            AntiVirusDisableNotify REG_DWORD 0 (0x0)
                            UpdatesDisableNotify REG_DWORD 0 (0x0)
                            FirstRunDisabled REG_DWORD 1 (0x1)
                            AntiVirusOverride REG_DWORD 1 (0x1)
                            FirewallOverride REG_DWORD 1 (0x1)

                            ========
                            Services
                            =========

                            Ndisuio : Start = 3
                            EapHost : Start = 2
                            Wlansvc : Start = 2
                            SharedAccess : Start = 2
                            windefend : Start = 2
                            wuauserv : Start = 2
                            wscsvc : Start = 2

                            ============
                            Disk Cleaned
                            anti-ver blaster : OK
                            Prefetch cleaned
                            ================

                            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                            device: opened successfully
                            user: MBR read successfully
                            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys spii.sys >>UNKNOWN [0x851D2938]<<
                            kernel: MBR read successfully
                            detected MBR rootkit hooks:
                            \Driver\atapi -> 0x8521b1f8
                            Warning: possible MBR rootkit infection !
                            user & kernel MBR OK
                            Use "Recovery Console" command "fixmbr" to clear infection !

                            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                            0
                            1. hello

                              ▶ Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                              mais cette fois-ci :

                              ▶ choisis l'Option Clean

                              ton PC va redemarrer,

                              laisse travailler l'outil.

                              en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                              ▶ colle le contenu dans ta reponse
                              0
                              1. ¤¤¤¤¤¤¤¤¤¤ List'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤

                                User : Bastien (Administrateurs)
                                Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
                                Start at: 20:09:58 | 24/05/2010

                                Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz
                                Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                                Internet Explorer 7.0.6001.18000
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local | 74,52 Go (21,27 Go free) [VistaOS] | NTFS
                                D:\ -> Disque fixe local | 67,69 Go (19,65 Go free) [DATA] | NTFS
                                E:\ -> Disque CD-ROM

                                Boot: Normal
                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
                                C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                                C:\Program Files\ATKGFNEX\GFNEXSrv.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                C:\Windows\system32\PnkBstrA.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\ATK Hotkey\Hcontrol.exe
                                C:\Program Files\ATKOSD2\ATKOSD2.exe
                                C:\Program Files\Wireless Console 2\wcourier.exe
                                C:\Program Files\ASUS\Splendid\ACMON.exe
                                C:\Program Files\P4G\BatteryLife.exe
                                C:\Windows\System32\ACEngSvr.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\ATK Hotkey\ATKOSD.exe
                                C:\Program Files\Nero\Nero 7\InCD\InCD.exe
                                C:\Program Files\ATK Hotkey\KBFiltr.exe
                                C:\Program Files\ATK Hotkey\WDC.exe
                                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                                C:\Windows\RtHDVCpl.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\P4P\P4P.exe
                                C:\Windows\ASScrPro.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\Program Files\Windows Media Player\wmpnscfg.exe
                                C:\Program Files\Windows Media Player\wmpnetwk.exe
                                C:\Program Files\Common Files\Teleca Shared\Generic.exe
                                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                                C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                                C:\Windows\system32\wuauclt.exe
                                C:\Windows\system32\SearchProtocolHost.exe
                                C:\Windows\system32\SearchFilterHost.exe
                                C:\Program Files\List_Kill'em\List_Kill'em.exe
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\cmd.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Program Files\List_Kill'em\pv.exe

                                ======================
                                Keys "Run"
                                ======================

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                NeroFilterCheck REG_SZ C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                                InCD REG_SZ C:\Program Files\Nero\Nero 7\InCD\InCD.exe
                                StartCCC REG_SZ C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                                RtHDVCpl REG_SZ RtHDVCpl.exe
                                Skytel REG_SZ Skytel.exe
                                JMB36X IDE Setup REG_SZ C:\Windows\RaidTool\xInsIDE.exe
                                SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                PowerForPhone REG_SZ "C:\Program Files\P4P\P4P.exe"
                                ASUS Screen Saver Protector REG_SZ C:\Windows\ASScrPro.exe
                                ASUS Camera ScreenSaver REG_SZ C:\Windows\ASScrProlog.exe
                                QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                iTunesHelper REG_SZ C:\Program Files\iTunes\iTunesHelper.exe
                                Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                Sony Ericsson PC Suite REG_SZ "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                                !AVG Anti-Spyware REG_SZ "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                                avgnt REG_SZ "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

                                =====================
                                Other Keys
                                =====================

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                                ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
                                ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
                                EnableInstallerDetection REG_DWORD 1 (0x1)
                                EnableLUA REG_DWORD 0 (0x0)
                                EnableSecureUIAPaths REG_DWORD 1 (0x1)
                                EnableVirtualization REG_DWORD 1 (0x1)
                                PromptOnSecureDesktop REG_DWORD 1 (0x1)
                                ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
                                dontdisplaylastusername REG_DWORD 0 (0x0)
                                legalnoticecaption REG_SZ
                                legalnoticetext REG_SZ
                                scforceoption REG_DWORD 0 (0x0)
                                shutdownwithoutlogon REG_DWORD 1 (0x1)
                                undockwithoutlogon REG_DWORD 1 (0x1)
                                FilterAdministratorToken REG_DWORD 0 (0x0)
                                EnableUIADesktopToggle REG_DWORD 0 (0x0)
                                DisableRegistryTools REG_DWORD 0 (0x0)

                                ===============

                                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                NoDriveTypeAutoRun REG_BINARY 95000000
                                NoDriveAutoRun REG_DWORD 0 (0x0)
                                NoDrives REG_DWORD 0 (0x0)

                                ===============

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
                                AllowLegacyWebView REG_DWORD 1 (0x1)
                                AllowUnhashedWebView REG_DWORD 1 (0x1)
                                NoDrives REG_DWORD 0 (0x0)

                                ===============

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

                                ===============

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                ReportBootOk REG_SZ 1
                                Shell REG_SZ Explorer.exe
                                Userinit REG_SZ C:\Windows\system32\userinit.exe,
                                VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
                                AutoRestartShell REG_DWORD 1 (0x1)
                                LegalNoticeCaption REG_SZ
                                LegalNoticeText REG_SZ
                                PowerdownAfterShutdown REG_SZ 0
                                ShutdownWithoutLogon REG_SZ 0
                                cachedlogonscount REG_SZ 10
                                forceunlocklogon REG_DWORD 0 (0x0)
                                passwordexpirywarning REG_DWORD 14 (0xe)
                                Background REG_SZ 0 0 0
                                DebugServerCommand REG_SZ no
                                WinStationsDisabled REG_SZ 0
                                DisableCAD REG_DWORD 1 (0x1)
                                scremoveoption REG_SZ 0
                                ShutdownFlags REG_DWORD 39 (0x27)
                                AutoLogonCount REG_DWORD 9999 (0x270f)
                                SFCDisable REG_DWORD 0 (0x0)
                                System REG_SZ

                                ===============

                                ===============

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                                {57B86673-276A-48B2-BAE7-C6DBB3020EB8} REG_SZ AVG Anti-Spyware 7.5
                                {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

                                ===============

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

                                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

                                ===============
                                ActivX controls
                                ===============

                                [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]

                                ===============
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-A74B-3DCD6583F589}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-9DB8-56FBECED082D}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

                                ==============
                                BHO :
                                ======

                                [<NO NAME> REG_SZ ]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

                                ===
                                DNS
                                ===

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{831C0086-A140-4CCF-9059-11481C48217F}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{A50355E2-9B9B-4DCF-9C38-28178BC43079}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{831C0086-A140-4CCF-9059-11481C48217F}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{A50355E2-9B9B-4DCF-9C38-28178BC43079}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{831C0086-A140-4CCF-9059-11481C48217F}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{A50355E2-9B9B-4DCF-9C38-28178BC43079}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                                ================
                                Internet Explorer :
                                ================

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                                Local Page REG_EXPAND_SZ %SystemRoot%\system32\blank.htm
                                Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                                Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                Start Page REG_SZ https://www.google.fr/?gws_rd=ssl
                                Local Page REG_SZ C:\Windows\system32\blank.htm
                                Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                                ========
                                Services
                                ========

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

                                Ndisuio : 0x3 ( OK = 3 )
                                EapHost : 0x3 ( OK = 2 )
                                Wlansvc : 0x2 ( OK = 2 )
                                SharedAccess : 0x2 ( OK = 2 )
                                windefend : 0x2 ( OK = 2 )
                                wuauserv : 0x2 ( OK = 2 )
                                wscsvc : 0x2 ( OK = 2 )

                                ========
                                Safemode
                                ========

                                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
                                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
                                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

                                =========
                                Atapi.sys
                                =========

                                C:\Windows\ERDNT\cache\atapi.sys :
                                MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                                SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                                C:\Windows\SoftwareDistribution\Download\cd2b15b1a90e884578188440a1660b12\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys :
                                MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
                                SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

                                C:\Windows\System32\drivers\atapi.sys :
                                MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                                SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                                C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys :
                                MD5 :: [b35cfcef838382ab6490b321c87edf17]
                                SHA256 :: [a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0]

                                C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys :
                                MD5 :: [4f4fcb8b6ea06784fb6d475b7ec7300f]
                                SHA256 :: [6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896]

                                C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys :
                                MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                                SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                                C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys :
                                MD5 :: [b35cfcef838382ab6490b321c87edf17]
                                SHA256 :: [a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0]

                                C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys :
                                MD5 :: [e03e8c99d15d0381e02743c36afc7c6f]
                                SHA256 :: [8217348674fc4d0c6d567ffc95b14dfd507f47c5a4728c2ba93d72c412e8527b]

                                C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys :
                                MD5 :: [2d9c903dc76a66813d350a562de40ed9]
                                SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

                                Référence :
                                ==========

                                Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
                                Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
                                Win XP_32b : a64013e98426e1877cb653685c5c0009
                                Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
                                Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
                                Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
                                Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
                                Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
                                Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
                                Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
                                Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
                                Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

                                =======
                                Drive :
                                =======

                                D'fragmenteur de disque Windows
                                Copyright (c) 2006 Microsoft Corp.

                                Rapport d'analyse pour le volume C: VistaOS

                                Taille du volume = 74.52 Go
                                Espace libre = 21.28 Go
                                tendue d'espace libre la plus grande = 216 Mo
                                Pourcentage de fragmentation des fichiers = 28 %

                                Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

                                Vous devriez d'fragmenter ce volume.

                                ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                                Present !! : C:\ProgramData\addr_file.html
                                Present !! : C:\ProgramData\addr_file.html
                                Present !! : C:\ProgramData\addr_file.html
                                Present !! : C:\ProgramData\addr_file.html
                                Present !! : C:\Windows\System32\ealregsnapshot1.reg
                                Present !! : C:\Users\Bastien\AppData\Local\fusioncache.dat
                                Present !! : C:\Users\Bastien\AppData\Local\GDIPFONTCACHEV1.DAT

                                ¤¤¤¤¤¤¤¤¤¤ Keys :

                                Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                                Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                                Present !! : HKEY_USERS\S-1-5-21-327584761-1432533102-1209779725-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                                Present !! : "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                                Present !! : "HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
                                Present !! : HKLM\Software\Conduit

                                ============

                                catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2010-05-24 20:22:24
                                Windows 6.0.6001 Service Pack 1 FAT NTAPI

                                scanning hidden processes ...

                                scanning hidden services ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden processes: 0
                                hidden services: 0
                                hidden files: 0

                                Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                                device: opened successfully
                                user: MBR read successfully
                                called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll iaStor.sys spvv.sys >>UNKNOWN [0x851D2938]<<
                                kernel: MBR read successfully
                                detected MBR rootkit hooks:
                                \Driver\atapi -> 0x8521b1f8
                                Warning: possible MBR rootkit infection !
                                user & kernel MBR OK
                                Use "Recovery Console" command "fixmbr" to clear infection !

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                                cval REG_DWORD 1 (0x1)
                                FirewallDisableNotify REG_DWORD 0 (0x0)
                                AntiVirusDisableNotify REG_DWORD 0 (0x0)
                                UpdatesDisableNotify REG_DWORD 0 (0x0)

                                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                                End of scan : 20:22:25,74
                                0
                                1. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

                                  ▶ Télécharge List_Kill'em

                                  et enregistre le sur ton bureau

                                  double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

                                  Laisse coché :

                                  ♦ Executer Shortcut
                                  ♦ Executer List_Kill'em

                                  une fois terminée , clic sur "terminer" et le programme se lancera seul

                                  choisis l'option Search

                                  ▶ laisse travailler l'outil

                                  à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

                                  ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
                                  0
                                  1. gen hackman stp aide moi je ne recois tes reponses que via ma messagerie qui a ete piratee et non en direct comme sur msn stp
                                    0
                                  2. Ok pour antivirus, pour le parefeu le prochain coup
                                    0
                                2. GMER 1.0.15.15281 - http://www.gmer.net
                                  Rootkit scan 2010-05-24 19:02:44
                                  Windows 6.0.6001 Service Pack 1
                                  Running: gmer.exe; Driver: C:\Users\Bastien\AppData\Local\Temp\fwddapoc.sys

                                  ---- Devices - GMER 1.0.15 ----

                                  AttachedDevice \FileSystem\Ntfs \Ntfs AsDsm.sys (Data Security Manager Driver/Windows (R) Codename Longhorn DDK provider)
                                  AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF dynamique/Microsoft Corporation)
                                  AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF dynamique/Microsoft Corporation)

                                  Device \FileSystem\fastfat \Fat 8BFB5A7A

                                  AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)

                                  ---- Registry - GMER 1.0.15 ----

                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0018f337f16b
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x83 0x84 0x2C 0x51 ...
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 2
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA8 0xEE 0x22 0xA2 ...
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
                                  Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x8F 0xE9 0x32 0x1B ...
                                  Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet)
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x83 0x84 0x2C 0x51 ...
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 2
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA8 0xEE 0x22 0xA2 ...
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
                                  Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x8F 0xE9 0x32 0x1B ...

                                  ---- Files - GMER 1.0.15 ----

                                  File C:\ADSM_PData_0150 0 bytes
                                  File C:\ADSM_PData_0150\DB 0 bytes
                                  File C:\ADSM_PData_0150\DB\SI.db 624 bytes
                                  File C:\ADSM_PData_0150\DB\UL.db 16 bytes
                                  File C:\ADSM_PData_0150\DB\VL.db 16 bytes
                                  File C:\ADSM_PData_0150\DB\_avt 512 bytes
                                  File C:\ADSM_PData_0150\DragWait.exe 253952 bytes executable
                                  File C:\ADSM_PData_0150\_avt 512 bytes
                                  File C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86 0 bytes
                                  File C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\AsDsm.sys 29752 bytes executable
                                  File C:\Program Files\ASUS\ASUS Data Security Manager\driver\x86\_avt 512 bytes

                                  ---- EOF - GMER 1.0.15 ----
                                  0
                                  • 1
                                  • 2