332 Virus
RésoluConfiguration: Windows XP Internet Explorer 6.0
43 réponses
Une infection par espilogiciels est détectée sur Windows XP par Ad-aware et l’utilisateur ne parvient pas à obtenir le rapport du scan ni à faire apparaître le curseur. Plusieurs réponses préconisent l’usage d’outils de nettoyage et de vérification comme HijackThis, ComboFix ou des scripts automatisés pour identifier et supprimer les composants malveillants et générer un rapport diagnostic. D’autres échanges évoquent des rapports détaillés et des entrées détectées dans les journaux, avec des mentions de VundoFix et des indications sur le redémarrage et la collecte de logs. En cas d’incertitude, la discussion suggère d’employer d’autres outils de nettoyage et de vérifier les rapports sur des supports externes pour éviter des gestes risqués sans preuves.
-
Contributeur sécuritéc'est un peu une histoire de fou.
je vais creuser, je reviendrais plus tard
-
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\dsubxhnu
*******************
Script file located at: \??\C:\eggoclwe.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\windbg48.sys not found!
Deletion of file C:\WINDOWS\system32\windbg48.sys failed!
Could not process line:
C:\WINDOWS\system32\windbg48.sys
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.//////////////////////////////////////////
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\dsubxhnu
*******************
Script file located at: \??\C:\eggoclwe.txt
Script file not found! Error
Could not open script file! Status: 0xc0000034 Abort!
et aussi SReng
[CODE]
2007-05-13,16:52:09
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows XP Publisher]
<CursorXP><C:\themeGold55\CursorXP\CursorXP.exe -s> [ ]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"> [Sun Microsystems, Inc.]
<ZoneAlarm Client><"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"> [(Verified)Check Point Software Technologies Ltd.]
<TkBellExe><"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [Anti-Malware Development a.s.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{26FAFD75-1005-41F6-978D-178C00165C0B}><> [N/A]
<{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll> [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<CDBurn><> [N/A]
==================================
Startup Folders
N/A
==================================
Services
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
<C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe><Macrovision Corporation>
[iPodService / iPodService][Stopped/Manual Start]
<C:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Disabled]
<C:\WINDOWS\System32\nvsvc32.exe><N/A>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[TrueVector Internet Monitor / vsmon][Running/Auto Start]
<C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service><Zone Labs, LLC>
[Service de numéro de série du lecteur multimédia portable / WmdmPmSN][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
==================================
Drivers
[0õÁwindbg48 / 0õÁwindbg48][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\windbg48.sys><N/A>
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[Logitech USB Monitor Filter / LVUSBSta][Stopped/Manual Start]
<system32\drivers\lvusbsta.sys><N/A>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Logitech QuickCam Communicate / QCMerced][Stopped/Manual Start]
<System32\DRIVERS\LVCM.sys><N/A>
[Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C) / rtl8139][Running/Manual Start]
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[srescan / srescan][Running/Boot Start]
<\SystemRoot\System32\ZoneLabs\srescan.sys><Zone Labs, LLC>
[vsdatant / vsdatant][Running/System Start]
<System32\vsdatant.sys><Zone Labs, LLC>
[Codec Teletext standard / WSTCODEC][Stopped/Manual Start]
<System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
==================================
Browser Add-ons
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[&Research]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\System32\macromed\Director\SwDir.dll, Adobe Systems, Inc.>
[Java Plug-in 1.5.0_10]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll, N/A>
[ActiveScan Installer Class]
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} <C:\WINDOWS\Downloaded Program Files\asinst.dll, Panda Software>
[Java Plug-in 1.5.0_10]
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll, N/A>
[Java Plug-in 1.5.0_10]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[E&xporter vers Microsoft Excel]
<res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
Running Processes
[PID: 320][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 368][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 392][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 436][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 448][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 616][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 640][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 708][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 764][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 848][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\system32\mdimon.dll] [Microsoft Corporation, 11.3.1897.0]
[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll] [Microsoft Corporation, 11.3.1897.0]
[PID: 996][C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE] [Microsoft Corporation, 7.00.9466]
[PID: 1052][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 1084][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1652][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[PID: 1844][C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe] [Sun Microsystems, Inc., 5.0.100.3]
[PID: 1864][C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[PID: 1872][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1900][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1920][C:\themeGold55\CursorXP\CursorXP.exe] [ , 1, 0, 0, 1]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[PID: 192][C:\Program Files\MSN Messenger\MsnMsgr.Exe] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\System32\sirenacm.dll] [Microsoft Corp., 8.1.0178.00]
[C:\WINDOWS\System32\msdmo.dll] [, ]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[PID: 1384][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\Fichiers communs\Microsoft Shared\INK\SKCHUI.DLL] [Microsoft Corporation, 1.0.1038.0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1524][C:\PROGRA~1\WINZIP\winzip32.exe] [WinZip Computing, S.L., 22.0 (32-bit)]
[C:\PROGRA~1\WINZIP\wzeay32.dll] [WinZip Computing, S.L., 0.9.7j (32-bit)]
[C:\PROGRA~1\WINZIP\WZCKTREE.DLL] [WinZip Computing, S.L., 1.1 (32-bit)]
[C:\PROGRA~1\WINZIP\WZSMTP.DLL] [WinZip Computing, S.L., 1.0.7445.0]
[C:\PROGRA~1\WINZIP\WZVINFO.DLL] [WinZip Computing, S.L., 1.1 (32-bit)]
[C:\PROGRA~1\WINZIP\WZGDIP32.DLL] [WinZip Computing, S.L., 1.1 (32-bit)]
[C:\PROGRA~1\WINZIP\WZCAB3.DLL] [WinZip Computing, S.L., 3.1 (32-bit)]
[C:\PROGRA~1\WINZIP\wz32.dll] [WinZip Computing, S.L., 22.0 (32-bit)]
[C:\PROGRA~1\WINZIP\UNRAR.DLL] [N/A, ]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[PID: 1840][C:\Documents and Settings\ARNAUD\Local Settings\Temp\wzf9cc\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
Hidden Process
N/A
==================================
[/CODE]
-
Contributeur sécuritébizarre, pourtant il figure bien dans le rapport de SREng
* Copie les lignes de la citation suivante, d'un trait :
Files to Delete:
C:\WINDOWS\system32\windbg48.sys
--> Clic droit / "copier"
Maintenant crée un nouveau document texte : clic droit de souris sur le bureau, "Nouveau" > "Document Texte".
* Ouvre-le et colle dedans ce que tu viens de copier précédemment
* Enregistre ce fichier sur ton bureau (nom : mad.txt)
* Télécharge à présent The Avenger
http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/
* Dézippe-le sur ton bureau et double-clique sur le fichier "avenger.exe"
* Clique sur "Ok"
* Sélectionne "Load Script from File" et clique sur l'icône en forme de dossier.
* Sélectionne le fichier mad.txt qui est sur ton bureau
* Clique sur le feu vert pour lancer le script
* Clique sur "Oui"
* Accepte de redémarrer ton pc
après le redémarrage :
* Ouvre le fichier C:\avenger.txt et copie/colle son contenu ici
ainsi qu'un nouveau log SREng stp
-
Contributeur sécurité
-démarrer -poste de travail ou autre dossier -menu outils -options de dossier -onglet affichage puis - activer la case : Afficher les fichiers et dossiers cachés - désactiver la case : Masquer les extensions des fichiers dont le type est connu - désactiver la case : Masquer les fichier protégés du système d'exploitation Puis - Appliquer
-
Je ne sais pas?
-
Contributeur sécuritétu as affiché les fichiers et dossiers cachés ?
-
Contributeur sécuritére
un petit quelque chose qui ne me plait pas, il faudrait aller sur VIRUS TOTAL Le faire analyser
http://www.virustotal.com/en/indexf.html
clique sur parcourir, recherche le fichier
C:\WINDOWS\system32\windbg48.sys
clique sur SEND
patiente
et reviens avec le rapport stp
-
[CODE]
2007-05-13,14:25:42
System Repair Engineer 2.4.12.806
Smallfrogs (http://www.KZTechs.com)
Windows XP Professional Service Pack 1 (Build 2600) - Administrative User - Completed Functions Allowed
Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\System32\ctfmon.exe> [(Verified)Microsoft Windows XP Publisher]
<CursorXP><C:\themeGold55\CursorXP\CursorXP.exe -s> [ ]
<MsnMsgr><"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<load><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"> [Sun Microsystems, Inc.]
<ZoneAlarm Client><"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"> [(Verified)Check Point Software Technologies Ltd.]
<TkBellExe><"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<!AVG Anti-Spyware><"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized> [Anti-Malware Development a.s.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows XP Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows XP Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
<{26FAFD75-1005-41F6-978D-178C00165C0B}><> [N/A]
<{57B86673-276A-48B2-BAE7-C6DBB3020EB8}><C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll> [Anti-Malware Development a.s.]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<CDBurn><> [N/A]
==================================
Startup Folders
N/A
==================================
Services
[AVG Anti-Spyware Guard / AVG Anti-Spyware Guard][Running/Auto Start]
<C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe><Anti-Malware Development a.s.>
[Accès du périphérique d'interface utilisateur / HidServ][Stopped/Disabled]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[InstallDriver Table Manager / IDriverT][Stopped/Manual Start]
<C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe><Macrovision Corporation>
[iPodService / iPodService][Stopped/Manual Start]
<C:\Program Files\iPod\bin\iPodService.exe><Apple Computer, Inc.>
[NVIDIA Driver Helper Service / NVSvc][Stopped/Disabled]
<C:\WINDOWS\System32\nvsvc32.exe><N/A>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[TrueVector Internet Monitor / vsmon][Running/Auto Start]
<C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service><Zone Labs, LLC>
[Service de numéro de série du lecteur multimédia portable / WmdmPmSN][Stopped/Manual Start]
<C:\WINDOWS\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
==================================
Drivers
[0õÁwindbg48 / 0õÁwindbg48][Stopped/Auto Start]
<\??\C:\WINDOWS\system32\windbg48.sys><N/A>
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[AVG Anti-Spyware Driver / AVG Anti-Spyware Driver][Running/System Start]
<\??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys><N/A>
[AVG Anti-Spyware Clean Driver / AvgAsCln][Running/System Start]
<System32\DRIVERS\AvgAsCln.sys><GRISOFT, s.r.o.>
[Logitech USB Monitor Filter / LVUSBSta][Stopped/Manual Start]
<system32\drivers\lvusbsta.sys><N/A>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<System32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[Logitech QuickCam Communicate / QCMerced][Stopped/Manual Start]
<System32\DRIVERS\LVCM.sys><N/A>
[Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C) / rtl8139][Running/Manual Start]
<System32\DRIVERS\RTL8139.SYS><Realtek Semiconductor Corporation>
[Secdrv / Secdrv][Stopped/Manual Start]
<System32\DRIVERS\secdrv.sys><N/A>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[srescan / srescan][Running/Boot Start]
<\SystemRoot\System32\ZoneLabs\srescan.sys><Zone Labs, LLC>
[vsdatant / vsdatant][Running/System Start]
<System32\vsdatant.sys><Zone Labs, LLC>
[Codec Teletext standard / WSTCODEC][Stopped/Manual Start]
<System32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
==================================
Browser Add-ons
[AcroIEHlprObj Class]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[&Research]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} <C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL, Microsoft Corporation>
[Shockwave ActiveX Control]
{166B1BCA-3F9C-11CF-8075-444553540000} <C:\WINDOWS\System32\macromed\Director\SwDir.dll, Adobe Systems, Inc.>
[Java Plug-in 1.5.0_10]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll, N/A>
[ActiveScan Installer Class]
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} <C:\WINDOWS\Downloaded Program Files\asinst.dll, Panda Software>
[Java Plug-in 1.5.0_10]
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll, N/A>
[Java Plug-in 1.5.0_10]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx, Adobe Systems, Inc.>
[E&xporter vers Microsoft Excel]
<res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000, N/A>
==================================
Running Processes
[PID: 320][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 372][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 396][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 440][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 452][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 628][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 652][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[PID: 1412][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll] [Zone Labs, LLC, 7.0.337.000]
[C:\Program Files\Zone Labs\ZoneAlarm\zlavscan_Loc040c.dll] [Zone Labs Inc., 5.3.017.000]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll] [Anti-Malware Development a.s., 7, 5, 0, 49]
[C:\Program Files\Alwil Software\Avast4\ashShell.dll] [ALWIL Software, 4, 7, 997, 0]
[PID: 1840][C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe] [Sun Microsystems, Inc., 5.0.100.3]
[PID: 1856][C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3760]
[PID: 1864][C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe] [Anti-Malware Development a.s., 7, 5, 0, 50]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll] [Anti-Malware Development a.s., 4, 2, 0, 15]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[PID: 1956][C:\WINDOWS\System32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.1106 (xpsp1.020828-1920)]
[PID: 1964][C:\themeGold55\CursorXP\CursorXP.exe] [ , 1, 0, 0, 1]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[PID: 564][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\Fichiers communs\Microsoft Shared\INK\SKCHUI.DLL] [Microsoft Corporation, 1.0.1038.0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSXML5.DLL] [Microsoft Corporation, 5.00.2916.0]
[C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\System32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 8.5.1r102]
[PID: 1440][C:\WINDOWS\System32\WISPTIS.EXE] [Microsoft Corporation, 1.0.2201.0 (xpsp1.020820-1800)]
[C:\Program Files\Fichiers communs\Microsoft Shared\INK\TPCPS.DLL] [Microsoft Corporation, 1.0.2201.0 (xpsp1.020820-1800)]
[PID: 2476][C:\Program Files\MSN Messenger\msnmsgr.exe] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\MSNCore.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1]
[C:\Program Files\MSN Messenger\ContactsUX.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\WINDOWS\System32\sirenacm.dll] [Microsoft Corp., 8.1.0178.00]
[C:\Program Files\MSN Messenger\msgslang.8.1.0178.00.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\msgsres.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\custsat.dll] [Microsoft Corporation, 9.0.3790.2428 (srv03_sp1_qfe.050422-1043)]
[C:\Program Files\MSN Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\System32\msdmo.dll] [, ]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\MSN Messenger\lmcdata.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\contact.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\abssm.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\dfsr.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\Program Files\MSN Messenger\usnsvcps.dll] [Microsoft Corporation, 8.1.0178.00]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\PROGRA~1\MSNMES~1\MSGSC8~1.DLL] [Microsoft Corporation, 8.1.0178.00]
[PID: 1532][C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\AGM.dll] [Adobe Systems Incorporated, 4.10.50]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\CoolType.dll] [Adobe Systems Incorporated, 4.13.42]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\JP2KLib.dll] [Adobe system Incorporated, 1.0.22891]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\OPP.dll] [Adobe Systems Incorporated, 1.02.05]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\BIB.dll] [Adobe Systems Incorporated, 1.1.14]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ACE.dll] [Adobe Systems Incorporated, 2.03.24]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[c:\program files\adobe\acrobat 6.0\reader\rdlang32.fra] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\WINDOWS\System32\ATMLIB.dll] [Adobe Systems, 5.1 Build 225]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\SPPlugins\ADMPlugin.apl] [Adobe Systems Incorporated, 3.01acp01]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\SPPlugins\ExpressViews.apl] [Adobe Systems Incorporated, 6.0]
[C:\Program Files\Fichiers communs\Microsoft Shared\INK\INKOBJ.DLL] [Microsoft Corporation, 2.0.2201.0 (xpsp1.020820-1800)]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Accessibility.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\AcroForm.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\Annots.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\DigSig.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\eBook.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\EScript.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\EWH32.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\HLS.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\IA32.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\ImageViewer\ImageViewer.API] [Adobe Systems Inc., 6.0.1.38590]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\MakeAccessible.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Multimedia\Multimedia.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PDDom.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\PictureTasks.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PPKLite.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\printme.api] [Electronics For Imaging, Inc., 6, 0, 16, 1]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\reflow.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\SaveAsRTF.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Search.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Search5.api] [Adobe Systems Incorporated, 6.0.0.2003051500]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\SendMail.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Soap.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Updater.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\esdupdate.dll] [Adobe Systems, 2, 0, 0, 21]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\weblink.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\XFA.api] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PPKLite.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Accessibility.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\AcroForm.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\Annots.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\DigSig.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\eBook.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\EScript.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\EWH32.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\HLS.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\MakeAccessible.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Multimedia\Multimedia.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PDDom.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\PictureTasks.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\printme.FRA] [N/A, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\reflow.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\SaveAsRTF.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Search.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Search5.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\SendMail.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Soap.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\Updater.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\weblink.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\XFA.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\IA32.FRA] [, ]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\plug_ins\ImageViewer\ImageViewer.FRA] [, ]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[PID: 1944][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\Fichiers communs\Microsoft Shared\INK\SKCHUI.DLL] [Microsoft Corporation, 1.0.1038.0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\wmp.dll] [Microsoft Corporation, 9.00.00.2980]
[C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL] [Microsoft Corporation, 11.0.5510]
[C:\WINDOWS\System32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 8.5.1r102]
[PID: 2724][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 6.00.2800.1106 (xpsp1.020828-1920)]
[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 6.0.1.2003110300]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\Fichiers communs\Microsoft Shared\INK\SKCHUI.DLL] [Microsoft Corporation, 1.0.1038.0]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSXML5.DLL] [Microsoft Corporation, 5.00.2916.0]
[C:\WINDOWS\System32\Macromed\Flash\Flash9c.ocx] [Adobe Systems, Inc., 9,0,45,0]
[C:\WINDOWS\System32\wdmaud.drv] [Microsoft Corporation, 5.1.2600.0 (XPClient.010817-1148)]
[C:\WINDOWS\System32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\WINDOWS\System32\Macromed\Common\SwSupport.dll] [Macromedia, Inc., 8.5.1r102]
[PID: 3228][C:\PROGRA~1\WINZIP\winzip32.exe] [WinZip Computing, S.L., 22.0 (32-bit)]
[C:\PROGRA~1\WINZIP\wzeay32.dll] [WinZip Computing, S.L., 0.9.7j (32-bit)]
[C:\PROGRA~1\WINZIP\WZCKTREE.DLL] [WinZip Computing, S.L., 1.1 (32-bit)]
[C:\PROGRA~1\WINZIP\WZSMTP.DLL] [WinZip Computing, S.L., 1.0.7445.0]
[C:\PROGRA~1\WINZIP\WZVINFO.DLL] [WinZip Computing, S.L., 1.1 (32-bit)]
[C:\PROGRA~1\WINZIP\WZGDIP32.DLL] [WinZip Computing, S.L., 1.1 (32-bit)]
[C:\PROGRA~1\WINZIP\WZCAB3.DLL] [WinZip Computing, S.L., 3.1 (32-bit)]
[C:\PROGRA~1\WINZIP\wz32.dll] [WinZip Computing, S.L., 22.0 (32-bit)]
[C:\PROGRA~1\WINZIP\UNRAR.DLL] [N/A, ]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
[C:\Program Files\Microsoft Office\OFFICE11\msohev.dll] [Microsoft Corporation, 11.0.5510]
[C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll] [Anti-Malware Development a.s., 7, 5, 0, 47]
[PID: 3740][C:\Documents and Settings\ARNAUD\Local Settings\Temp\wzadf3\SREng.EXE] [Smallfrogs Studio, 2.4.12.806]
[C:\WINDOWS\System32\SYNCOR11.DLL] [SoundMAX, 1.2.3]
[C:\themeGold55\CursorXP\CurXP0.dll] [N/A, ]
==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock Provider
N/A
==================================
Autorun.Inf
N/A
==================================
HOSTS File
127.0.0.1 localhost
==================================
API HOOK
N/A
==================================
Hidden Process
N/A
==================================
[/CODE] -
Contributeur sécuritére
pas sûr que ce soit infectieux
fait ceci :
Télécharge SREng (par Smallfrogs) de ce lien:
http://www.kztechs.com/eng/download.html
Extrait tout son contenu sur ton Bureau
Du dossier sreng2 qui se trouve maintenant sur ton Bureau, double clique sur SREng.exe afin de lancer l'outil
Clique sur Smart Scan
Ensuite, clique sur le bouton [Scan]
Lorsque complété, clique sur le bouton [Save Reports]
Sauvegarde le rapport sur ton Bureau
Copie/colle le contenu du fichier SREnglLOG.log dans ta prochaine réponse, s'il te plaît. -
J'ai toujours un problème mais je sais pas si c'est du a c'est problème de espilogiciel. Car il y a "Windows Installer" qui s'ouvre à chaque fois que je lance word, un truc office et à chaque fois qu'une page internet s'ouvre.
-
Est ce que effecer tout ce qui est vundo suffit car je ne trouve pas de uninstall?
-
Contributeur sécuritébonjour,
ok, pour le rapport de panda, ras il faudra supprimer vundofix
pour résumer la situation, as tu encore des problèmes ? -
--
"voir la vie avec les yeux du futur" -
Voici le Active scan rapport
Incident Statut Analyse
Spyware:Cookie/RealMedia No Désinfecté C:\Documents and Settings\ARNAUD\Cookies\arnaud@247realmedia[1].txt
Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\ARNAUD\Cookies\arnaud@advertising[1].txt
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\ARNAUD\Cookies\arnaud@bluestreak[2].txt
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\ARNAUD\Cookies\arnaud@xiti[1].txt
Spyware:Cookie/Xiti No Désinfecté C:\RECYCLER\S-1-5-21-789336058-1993962763-1343024091-1003\Dc10.txt
Adware:Adware/WinAntivirus2006 No Désinfecté C:\VundoFix Backups\hrqetmwg.dll.bad
-
Je suis reparti pour faire le scan il a été fait en 2 min contre 1H hier.
J'en suis à la phase T6, par rapport au tuto. C'est comme ça qu'on appelle la page ou tout est expliqué? Bref, hier soir j'ai relancé un coup de AVG anti spyware c'est peut être pour ça que ça marche mieux.
-
Bonjour.
J'ai trouvé plein de choses enregistrés active scan sur mon ordi mais pas de activescan.txt que faire? -
Contributeur sécuritédonc maintenant il faudrait que tu puisses choisir ce que tu dois scanner
la fenêtre activescan a disparu ? elle avait chargé à 100%-
-
@beuveDésolé je dois partir. Je reviens demain. bonne nuit
-
-
Contributeur sécuritéregarde ma page celle que je viens de te donner et dit moi à quelle fenêtre tu t'es arrêté
-
J'ai comme l'impression que la page de scan s'est remise à scanner mais je ne sais pas vraiment car elle a eu fini d'enregistrer ses dossiers déjà donc je comprend pas j'ai pas eu de proposition d'enregistrer dans les disques locaux. Alors je vais chercher ou i est a enregistrer
-
Contributeur sécuritésinon tu jètes un oeil à ce lien, tu auras les images plus rapidement que sur l'autre lien que je t'ai donné
http://pageperso.aol.fr/loraline60/panda_scan.htm
- 1
- 2
- 3