Erreur d'application Rundll32.exe HELP ME!!!
RésoluL'instruction à "0x012c7d2d" emploie l'adresse mémoire "0x00000000". La mémoire ne peut pas être "written".
Aider mois svp!!!
Configuration: Windows XP Firefox 3.0.1
26 réponses
Le fil porte sur une erreur mémoire après l'exécution de CCleaner sous Windows XP, indiquant que l'instruction à 0x012c7d2d utilise l'adresse 0x00000000 et que la mémoire ne peut pas être écrite. Plusieurs éléments de réponse proposent des mesures techniques: Réponse 1 suggère d'utiliser Flash_Disinfector et d'enregistrer un rapport RSIT après exécution des vérifications. En parallèle, certaines réponses agrègent simplement la demande d'aide sans apport technique précis, tandis que d'autres fournissent des extraits du rapport RSIT et des éléments de HijackThis pour étayer l'analyse. Dernier élément utile, le rapport RSIT et HijackThis indiquent de multiples services et programmes démarrés, ce qui suggère une activité système étendue et une possible infection de modules indésirables.
-
Contributeur sécuritéRe,
bien, à toi.
En lisant ton rapport, j'ai vu que tu avais des rapports de navilog. ca m'a permis de découvrir que tu en étais à ton 5ème topic, que tu avais laissé tombé au moins 2 fois et que il s'est passé 5 jours entre ma réponse et la tienne.
Alors le "help me please" est de mauvais goût.
Télécharge Flash_Disinfector de sUBs ici :
https://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
Enregistre le sur ton Bureau.
Double clique sur Flash_Disinfector.exe pour le lancer
.
Quand le message : "Plug in yours flash drive & clic Ok to begin disinfection" apparaitra , connecte les clés USB et périphériques USB externes susceptibles d'avoir été infectés.
Puis clique sur Ok
Les icônes sur le Bureau vont disparaitre jusqu'à l'apparition du message: "Done!!"
Appuye sur "Ok", pour faire réapparaitre le Bureau
Remets un rapport RSIT. -
J'ai été voir en enfer, j'ai rien trouvé :-(
Une personne a eu le même problème hier, son post était trop gros, il a fallu le fragmenter. -
Contributeur sécuritéRe,
je comprenais bien que vous pouvez pas remonter indéfiniment dans le temps.
j'ai reposté et c'est parti dans l'enfer ccmien.. -
Ah ben je peux pas remonter plus loin que 20h :-(
Resposte si tu veux, je transmettrai. -
Contributeur sécuritéBonsoir,
merci de le recherche sacabouffe (mais les posts sont antérieurs).
Je remets le contenu du rapport RSIT e,nvoyé par mp.
Le scan on line par Kaspersky (post 21) reste à faire. -
Salut
Désolé, j'ai rien en réserve depuis 20h :-(
Bonne soirée -
Contributeur sécuritéBonsoir,
j'ai demandé à la modération si des posts n'étaient pas aux oubliettes, y compris un post de moi en réponse à ton mp.
En attendant leur réponse, fais ça :
Fais un scan en ligne Kaspersky avec Internet Explorer :
- Clique sur Démarrer Online-Scanner
- Clique maintenant sur J'accepte.
- Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
- Patiente pendant l'installation des Mises à jour.
- Choisis par la suite l'analyse du Poste de travail.
- Sauvegarde puis colle le rapport généré en fin d'analyse.
AIDE : Configurer le contrôle des ActiveX
NOTE : <ital>Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle <gras>O -
Pourkoi je ne pe pa poster le rapport, sa fait 3 jour que j'éssaye
-
Contributeur sécuritéBonjour,
j'espère que tu as pris le rapport trop tôt et que tu as fait la suite.
Refais tourner MBAM pour vérification.
Pour info, zPharao.exe est une saleté.
J'ai l'impression qu'elle n'a pas fait de dégats.
Pour vérifier :
refais un rapport RSIT. -
voila le rapport:
Malwarebytes' Anti-Malware 1.28
Version de la base de données: 1251
Windows 5.1.2600 Service Pack 2
11/10/2008 06:50:45
mbam-log-2008-10-11 (06-50-29).txt
Type de recherche: Examen complet (C:\|E:\|G:\|H:\|X:\|Y:\|Z:\|)
Eléments examinés: 232106
Temps écoulé: 2 hour(s), 46 minute(s), 11 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 5
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
E:\kkkk\logiciel\ Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe (Trojan.Downloader) -> No action taken.
E:\kkkk\logiciel\ Norton Antivirus Professional 2004 + keygen\ Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe (Trojan.Downloader) -> No action taken.
E:\kkkk\logiciel\Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe (Trojan.Downloader) -> No action taken.
E:\kkkk\plan\Utilitaire\logiciel arhi,autocad\Graphisoft\ArchiCAD 9\Extensions\ArchiTerra 2.05\ArchiCad_ArchiTerra_2.05_(AC90)_crk.exe (Trojan.Downloader) -> No action taken.
C:\zPharaoh.exe (Worm.Mabezat) -> No action taken. -
Contributeur sécuritéRe,
on fera ça à la fin.
Je crois que tu as MBAM.
mets le à jour et scanne.
Poste le rapport. -
est ce qu'il faut que j'éfface OTMoveit3 aprés son utilisation
-
sllt voici le rapport:
========== FILES ==========
E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe moved successfully.
OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10102008_201726 -
Contributeur sécuritéBonjour,
toujours avec ta clé connectée,
Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
Double-clique sur OTMoveIt3.exe pour le lancer.
Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.
Copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".
:files
E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur "Exit" pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .
Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes. -
Fichier SpeederXP1.6.exe reçu le 2008.10.10 16:35:21 (CET)
Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
Résultat: 5/35 (14.29%)
en train de charger les informations du serveur...
Votre fichier est dans la file d'attente, en position: ___.
L'heure estimée de démarrage est entre ___ et ___ .
Ne fermez pas la fenêtre avant la fin de l'analyse.
L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
les résultats seront affichés au fur et à mesure de leur génération.
Formaté Formaté
Impression des résultats Impression des résultats
Votre fichier a expiré ou n'existe pas.
Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.
Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
Email:
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.10.10.1 2008.10.10 -
AntiVir 7.8.1.34 2008.10.10 -
Authentium 5.1.0.4 2008.10.10 -
Avast 4.8.1248.0 2008.10.09 -
AVG 8.0.0.161 2008.10.10 -
BitDefender 7.2 2008.10.10 Trojan.Pws.Lenmir.30
CAT-QuickHeal 9.50 2008.10.10 -
ClamAV 0.93.1 2008.10.10 -
DrWeb 4.44.0.09170 2008.10.10 -
eSafe 7.0.17.0 2008.10.08 Win32.VB.cny
eTrust-Vet 31.6.6139 2008.10.09 -
Ewido 4.0 2008.10.10 -
F-Prot 4.4.4.56 2008.10.10 -
F-Secure 8.0.14332.0 2008.10.10 -
Fortinet 3.113.0.0 2008.10.10 -
GData 19 2008.10.10 Trojan.Pws.Lenmir.30
Ikarus T3.1.1.34.0 2008.10.10 Trojan.Win32.VB.cny
K7AntiVirus 7.10.489 2008.10.09 -
Kaspersky 7.0.0.125 2008.10.10 -
McAfee 5402 2008.10.09 -
Microsoft 1.4005 2008.10.10 -
Norman 5.80.02 2008.10.10 -
Panda 9.0.0.4 2008.10.10 -
PCTools 4.4.2.0 2008.10.10 -
Prevx1 V2 2008.10.10 -
Rising 20.65.42.00 2008.10.10 -
SecureWeb-Gateway 6.7.6 2008.10.10 -
Sophos 4.34.0 2008.10.10 -
Sunbelt 3.1.1708.1 2008.10.10 -
Symantec 10 2008.10.10 -
TheHacker 6.3.1.0.105 2008.10.10 -
TrendMicro 8.700.0.1004 2008.10.10 -
VBA32 3.12.8.6 2008.10.09 Trojan.Win32.VB.cny
ViRobot 2008.10.10.1416 2008.10.10 -
VirusBuster 4.5.11.0 2008.10.10 -
Information additionnelle
File size: 560724 bytes
MD5...: a768a3156382b4c6f0ae531f8e9f0c9a
SHA1..: 63626c63133739d2420f7139f962364640b2e991
SHA256: dd468d9cede5f0529e840b1ad2a37e79205226d8e6139b5860d2bdf380b36e61
SHA512: f22cf7c47f058ba8daa3bbe67e8ff282c008bc99c5fc524f742814c188196a6c
8c0e7f625dba1a2ebae8aa9058f326da35b9dea7d2d56ebf7f7296a38b23f8e8
PEiD..: -
TrID..: File type identification
Inno Setup installer (96.7%)
Generic Win/DOS Executable (1.6%)
DOS Executable Generic (1.6%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x40bf98
timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
machinetype.......: 0x14c (I386)
( 8 sections )
name viradd virsiz rawdsiz ntrpy md5
CODE 0x1000 0xb650 0xb800 6.48 d81967196488bed91d07a25e8d0ce84c
DATA 0xd000 0x17e0 0x1800 3.26 56a5aaf0af5228630c63c49761fd2e97
BSS 0xf000 0x1190 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.idata 0x11000 0x75e 0x800 4.53 8f5d13420b574360d07b7076ddb1a364
.tls 0x12000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rdata 0x13000 0x18 0x200 0.21 c233c0ea7d984808a57c6681c85abaad
.reloc 0x14000 0x854 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
.rsrc 0x15000 0x1400 0x1400 4.17 045d4bbb9ecd3d1e283590f9f4834b8e
( 8 imports )
> kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, ExitProcess, CreateFileA, CloseHandle
> user32.dll: MessageBoxA
> oleaut32.dll: VariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
> advapi32.dll: OpenProcessToken, LookupPrivilegeValueA
> kernel32.dll: Sleep, SetLastError, SetErrorMode, GetWindowsDirectoryA, GetVersionExA, GetTempFileNameA, GetSystemDefaultLCID, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetCPInfo, FormatMessageA, DeleteFileA, CreateProcessA, CloseHandle
> user32.dll: TranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, GetSystemMetrics, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA, CharNextA
> comctl32.dll: InitCommonControls
> advapi32.dll: AdjustTokenPrivileges
( 0 exports )
packers (Kaspersky): UPX, UPX, UPX, UPX -
Contributeur sécuritéRe,
la politique des cracks est assez proche de la roulette russe.
Laisse ta clé E:\ connectée.
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier : E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Si VirusTotal indique que le fichier a déjà été analysé, cliquer sur le bouton Reanalyse le fichier maintenant -
BitDefender Online Scanner
Rapport d'analyse généré à: Thu, Oct 09, 2008 - 22:32:06
Voie d'analyse: A:\;C:\;D:\;E:\;F:\;G:\;H:\;
Statistiques
Temps
00:56:30
Fichiers
167117
Directoires
13724
Secteurs de boot
0
Archives
2799
Paquets programmes
13269
Résultats
Virus identifiés
3
Fichiers infectés
3
Fichiers suspects
0
Avertissements
0
Désinfectés
0
Fichiers effacés
3
Info sur les moteurs
Définition virus
1854547
Version des moteurs
AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)
Analyse des plugins
16
Archive des plugins
43
Unpack des plugins
7
E-mail plugins
6
Système plugins
4
Paramètres d'analyse
Première action
Désinfecté
Seconde Action
Supprimé
Heuristique
Oui
Acceptez les avertissements
Oui
Extensions analysées
exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
Excludez les extensions
Analyse d'emails
Oui
Analyse des Archives
Oui
Analyser paquets programmes
Oui
Analyse des fichiers
Oui
Analyse de boot
Oui
Fichier analysé
Statut
C:\Documents and Settings\Misterdy\Mes documents\téléchar\pqremove.com
Infecté par: Trojan.Generic.169733
C:\Documents and Settings\Misterdy\Mes documents\téléchar\pqremove.com
Supprimé
C:\Program Files\Navilog1\Backupnavi\egsso.exe
Détecté avec: Adware.NaviPromo.Gen.2
C:\Program Files\Navilog1\Backupnavi\egsso.exe
Echec de la désinfection
C:\Program Files\Navilog1\Backupnavi\egsso.exe
Supprimé
E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)=>(Instyler Module 9)
Infecté par: Trojan.Pws.Lenmir.30
E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)=>(Instyler Module 9)
Echec de la désinfection
E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)=>(Instyler Module 9)
Supprimé
E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)
Echec de la mise à jour -
Contributeur sécuritéTr,
parfait, on a éliminé l'infection des disques amovibles. -
et maintenant je fais une analyse en ligne avc bitdefender pour avoir le rapport, que je v afficher dan quelque minute
-
slt g dja fait rav , puis j'ai fait vacciner les clé et périphérique usb, puis j'ai fais un rapport avec combofix, et puis j'ai crée un fichier bloc note avec:
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a1a3f3e-8d21-11dd-acea-001e8ce1ec2b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5ca3fe8-8fd0-11dd-acf3-001e8ce1ec2b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11aefc8c-6ed7-11dd-ac89-001e8ce1ec2b}]
que j'ai glisser sur combofix et voici le rapport obtenue:
ComboFix 08-10-07.06 - Misterdy 2008-10-09 20:37:30.5 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2333 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Misterdy\Bureau\ComboFix.exe
Commutateurs utilisés
C:\Documents and Settings\Misterdy\Bureau\CFScript.txt
[COLOR=RED]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/COLOR]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-09 au 2008-10-09 ))))))))))))))))))))))))))))))))))))
.
2008-10-09 19:46 . 2008-10-09 19:46 <REP> d--hs---- C:\Documents and Settings\Misterdy\UserData
2008-10-09 12:23 . 2008-10-09 12:23 268 --ah----- C:\sqmdata08.sqm
2008-10-09 12:23 . 2008-10-09 12:23 244 --ah----- C:\sqmnoopt08.sqm
2008-10-09 12:19 . 2001-08-24 14:00 2,864 --a------ C:\WINDOWS\WINDOWS\system32\MSCICH32.DLL
2008-10-09 12:17 . 2008-10-09 12:17 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\cadwork.cat
2008-10-09 12:04 . 2008-10-09 12:17 <REP> d-------- C:\Program Files\cadwork.dir
2008-10-09 12:04 . 2008-10-09 12:04 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\cadwork
2008-10-09 12:04 . 2008-10-09 12:08 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\cadwork
2008-10-08 20:09 . 2008-10-08 20:09 268 --ah----- C:\sqmdata07.sqm
2008-10-08 20:09 . 2008-10-08 20:09 244 --ah----- C:\sqmnoopt07.sqm
2008-10-08 19:23 . 2008-10-08 19:23 268 --ah----- C:\sqmdata06.sqm
2008-10-08 19:23 . 2008-10-08 19:23 244 --ah----- C:\sqmnoopt06.sqm
2008-10-07 21:20 . 2008-10-07 21:20 268 --ah----- C:\sqmdata05.sqm
2008-10-07 21:20 . 2008-10-07 21:20 244 --ah----- C:\sqmnoopt05.sqm
2008-10-07 21:16 . 2008-10-07 21:16 268 --ah----- C:\sqmdata04.sqm
2008-10-07 21:16 . 2008-10-07 21:16 244 --ah----- C:\sqmnoopt04.sqm
2008-10-07 20:20 . 2008-10-07 20:20 268 --ah----- C:\sqmdata03.sqm
2008-10-07 20:20 . 2008-10-07 20:20 244 --ah----- C:\sqmnoopt03.sqm
2008-10-07 20:14 . 2008-10-07 20:14 268 --ah----- C:\sqmdata02.sqm
2008-10-07 20:14 . 2008-10-07 20:14 244 --ah----- C:\sqmnoopt02.sqm
2008-10-07 20:13 . 2008-10-07 20:25 <REP> d-------- C:\Program Files\Microsoft Bootvis
2008-10-07 19:21 . 2008-10-07 19:21 268 --ah----- C:\sqmdata01.sqm
2008-10-07 19:21 . 2008-10-07 19:21 244 --ah----- C:\sqmnoopt01.sqm
2008-10-07 18:42 . 2008-10-07 18:43 <REP> d-------- C:\rsit
2008-10-07 13:23 . 2008-10-07 13:23 268 --ah----- C:\sqmdata00.sqm
2008-10-07 13:23 . 2008-10-07 13:23 244 --ah----- C:\sqmnoopt00.sqm
2008-10-05 20:43 . 2008-10-05 20:43 <REP> d-------- C:\Program Files\iTunes
2008-10-05 20:43 . 2008-10-05 20:43 <REP> d-------- C:\Program Files\iPod
2008-10-05 20:43 . 2008-10-07 17:21 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Apple Computer
2008-10-05 20:43 . 2008-10-05 20:43 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 20:43 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\WINDOWS\system32\GEARAspi.dll
2008-10-05 20:43 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-10-05 20:42 . 2008-10-05 20:42 <REP> d-------- C:\Program Files\Bonjour
2008-10-05 20:41 . 2008-10-05 20:42 <REP> d-------- C:\Program Files\QuickTime
2008-10-05 20:41 . 2008-10-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-10-05 20:41 . 2008-10-05 20:41 <REP> d-------- C:\Program Files\Apple Software Update
2008-10-05 20:41 . 2008-10-05 20:43 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-10-05 20:41 . 2008-10-05 20:41 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2008-10-03 19:12 . 2008-10-03 19:12 <REP> d-------- C:\Program Files\Microsoft Games
2008-10-01 21:34 . 2008-10-03 18:00 <REP> d-------- C:\UT2004
2008-10-01 21:34 . 2002-07-08 00:14 1,294,336 --a------ C:\WINDOWS\WINDOWS\system32\vorbis.acm
2008-10-01 20:08 . 2008-10-01 20:08 <REP> d-------- C:\Documents and Settings\Administrateur.MISTERDY\Application Data\Malwarebytes
2008-10-01 19:17 . 2007-04-20 07:34 674,048 -ra------ C:\WINDOWS\WINDOWS\system32\drivers\3xHybrid.sys
2008-10-01 19:17 . 2007-01-29 04:29 1,748 --a------ C:\WINDOWS\WINDOWS\French.lng
2008-10-01 19:17 . 2007-02-13 08:03 1,324 --a------ C:\WINDOWS\WINDOWS\TVP3XDrv.ini
2008-10-01 18:47 . 2008-10-01 18:50 <REP> d-------- C:\Program Files\SuperCopier
2008-09-30 22:01 . 2008-09-30 22:01 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-30 22:01 . 2008-09-30 22:01 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Malwarebytes
2008-09-30 22:01 . 2008-09-30 22:01 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-09-30 22:01 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-30 22:01 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\WINDOWS\system32\drivers\mbam.sys
2008-09-30 17:58 . 2008-10-02 19:09 <REP> d-------- C:\Program Files\Navilog1
2008-09-30 06:50 . 2008-09-30 06:50 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\DivX
2008-09-29 20:50 . 2008-09-29 20:50 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
2008-09-29 20:01 . 2008-09-29 20:00 1,388,544 --a------ C:\WINDOWS\WINDOWS\system32\msvbvm60.dll
2008-09-29 18:57 . 2008-09-30 21:51 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-27 19:19 . 2008-09-27 19:19 <REP> d--hs---- C:\Documents and Settings\Misterdy\PrivacIE
2008-09-27 18:50 . 2008-09-27 18:51 <REP> d--h-c--- C:\WINDOWS\WINDOWS\ie8
2008-09-27 00:10 . 2008-09-27 00:10 <REP> d--h----- C:\WINDOWS\WINDOWS\system32\GroupPolicy
2008-09-25 19:34 . 2008-09-25 19:34 45 --a------ C:\WINDOWS\WINDOWS\system32\initdebug.nfo
2008-09-25 16:34 . 2008-10-07 10:03 8,627 --a------ C:\WINDOWS\WINDOWS\system32\PAV_FOG.OPC
2008-09-25 15:55 . 2008-09-25 15:55 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Backup
2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\WINDOWS\WINDOWS\system32\PAV
2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\Program Files\Panda Security
2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Panda Security
2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Panda Security
2008-09-25 15:54 . 2008-06-18 18:03 520,448 --a------ C:\WINDOWS\WINDOWS\system32\PavSHook.dll
2008-09-25 15:54 . 2003-10-22 18:23 446,464 --a------ C:\WINDOWS\WINDOWS\system32\HHActiveX.dll
2008-09-25 15:54 . 2008-06-26 11:25 197,888 --a------ C:\WINDOWS\WINDOWS\system32\drivers\neti1634.sys
2008-09-25 15:54 . 2008-06-24 14:48 193,280 --a------ C:\WINDOWS\WINDOWS\system32\TpUtil.dll
2008-09-25 15:54 . 2007-02-08 11:53 107,568 --a------ C:\WINDOWS\WINDOWS\system32\SYSTOOLS.DLL
2008-09-25 15:54 . 2008-06-18 18:03 87,296 --a------ C:\WINDOWS\WINDOWS\system32\PavLspHook.dll
2008-09-25 15:54 . 2008-03-18 16:58 58,672 --a------ C:\WINDOWS\WINDOWS\system32\avldr.dll
2008-09-25 15:54 . 2008-06-18 18:03 55,552 --a------ C:\WINDOWS\WINDOWS\system32\pavipc.dll
2008-09-25 15:53 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\WINDOWS\system32\drivers\pavboot.sys
2008-09-25 15:52 . 2008-09-25 15:52 <REP> d-------- C:\Program Files\Fichiers communs\Panda Security
2008-09-25 15:52 . 2008-02-07 12:03 179,640 -ra------ C:\WINDOWS\WINDOWS\system32\drivers\PavProc.sys
2008-09-25 15:52 . 2008-03-04 15:59 41,144 -ra------ C:\WINDOWS\WINDOWS\system32\drivers\ShlDrv51.sys
2008-09-25 14:24 . 2008-09-30 06:46 <REP> d-------- C:\Temp
2008-09-25 13:32 . 2008-09-27 16:14 <REP> d-------- C:\WINDOWS\WINDOWS\system32\CatRoot_bak
2008-09-25 12:04 . 2008-09-25 12:04 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Ubisoft
2008-09-25 12:04 . 2008-09-25 12:04 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ubisoft
2008-09-25 11:54 . 2008-09-25 11:54 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\InstallShield
2008-09-25 09:37 . 2008-09-25 09:37 129,536 --a------ C:\WINDOWS\WINDOWS\system32\IJL15.dll
2008-09-22 11:24 . 2002-07-17 09:20 45,056 --a------ C:\WINDOWS\WINDOWS\system32\WNASPI2K.BAK
2008-09-22 11:24 . 2002-07-17 08:53 16,877 --a------ C:\WINDOWS\WINDOWS\system32\drivers\ASPI2K.BAK
2008-09-22 11:24 . 2002-07-17 16:22 5,600 --a------ C:\WINDOWS\WINDOWS\system\WINASPI.BAK
2008-09-22 11:24 . 2002-07-17 16:22 4,672 --a------ C:\WINDOWS\WINDOWS\system\WOWPOST.BAK
2008-09-22 11:22 . 2008-10-05 20:41 <REP> d-------- C:\WINDOWS\WINDOWS\system32\QuickTime
2008-09-22 11:22 . 2003-03-25 06:49 301,568 -ra------ C:\WINDOWS\WINDOWS\system32\L3codeca.acm
2008-09-22 11:22 . 2004-08-04 00:55 294,912 --a------ C:\WINDOWS\WINDOWS\system32\msh263.drv
2008-09-19 20:35 . 2005-02-26 07:34 442,368 -ra------ C:\WINDOWS\WINDOWS\system32\vp6vfw.dll
2008-09-18 15:49 . 2008-09-18 15:49 <REP> d-------- C:\WINDOWS\WINDOWS\system32\URTTEMP
2008-09-18 15:46 . 2008-09-18 15:46 669,184 --a------ C:\WINDOWS\WINDOWS\system32\pbsvc.exe
2008-09-18 09:10 . 2008-09-25 09:37 94,208 --a------ C:\WINDOWS\WINDOWS\system32\ScrUnZip.dll
2008-09-16 02:14 . 2008-09-16 02:14 3,596,288 --a------ C:\WINDOWS\WINDOWS\system32\qt-dx331.dll
2008-09-16 02:14 . 2008-09-16 02:14 524,288 --a------ C:\WINDOWS\WINDOWS\system32\DivXsm.exe
2008-09-16 02:14 . 2008-09-16 02:14 9,878 --a------ C:\WINDOWS\WINDOWS\system32\dsm_fr.qm
2008-09-16 02:14 . 2008-09-16 02:14 4,816 --a------ C:\WINDOWS\WINDOWS\system32\divxsm.tlb
2008-09-16 02:11 . 2008-09-16 02:11 823,296 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx0c.dll
2008-09-16 02:11 . 2008-09-16 02:11 823,296 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx07.dll
2008-09-16 02:11 . 2008-09-16 02:11 815,104 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx0a.dll
2008-09-16 02:11 . 2008-09-16 02:11 802,816 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx11.dll
2008-09-16 02:11 . 2008-09-16 02:11 683,520 --a------ C:\WINDOWS\WINDOWS\system32\DivX.dll
2008-09-16 02:11 . 2008-09-16 02:11 634,880 --a------ C:\WINDOWS\WINDOWS\system32\divxdec.ax
2008-09-16 02:11 . 2008-09-16 02:11 352,401 --a------ C:\WINDOWS\WINDOWS\system32\DivXMedia.ax
2008-09-16 02:11 . 2008-09-16 02:11 161,096 --a------ C:\WINDOWS\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-09-16 02:11 . 2008-09-16 02:11 12,288 --a------ C:\WINDOWS\WINDOWS\system32\DivXWMPExtType.dll
2008-09-14 22:47 . 2008-09-14 22:54 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\codeblocks
2008-09-14 20:18 . 2008-09-17 22:58 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-09-14 20:09 . 2008-09-14 20:09 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-09-10 20:23 . 2008-09-19 19:41 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-09-10 19:32 . 2008-09-10 19:36 <REP> d-------- C:\WINDOWS\WINDOWS\system32\XPSViewer
2008-09-10 19:31 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\WINDOWS\system32\spmsg2.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 18:07 1,132 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFLTR.CFG.bck
2008-10-09 18:07 1,132 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFLTR.CFG
2008-10-09 10:23 294,988 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFCONT.DAT.bck
2008-10-09 10:23 294,988 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFCONT.DAT
2008-10-08 17:39 122,880 ----a-w C:\VaccinUSB.exe
2008-10-02 13:36 --------- d-----w C:\Program Files\Google
2008-10-01 20:08 --------- d-----w C:\Program Files\SuperCopier2
2008-10-01 19:34 --------- d-----w C:\Program Files\VstPlugins
2008-10-01 17:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-01 17:19 --------- d-----w C:\Program Files\CyberLink
2008-09-30 21:37 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\Desktopicon
2008-09-30 19:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-09-29 17:26 --------- d-----w C:\Program Files\DivX
2008-09-29 16:56 --------- d-----w C:\Program Files\Unlocker
2008-09-29 16:56 --------- d-----w C:\Program Files\CCleaner
2008-09-29 16:19 --------- d-----w C:\Program Files\Olympus
2008-09-27 18:36 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-27 18:06 31 ----a-w C:\Program Files\Fichiers communs\appop.log
2008-09-26 22:01 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\BitTorrent
2008-09-25 09:55 --------- d-----w C:\Program Files\Ubisoft
2008-09-22 11:35 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-09-22 11:24 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-09-18 13:46 22,328 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\PnkBstrK.sys
2008-09-18 13:46 22,328 ----a-w C:\Documents and Settings\Misterdy\Application Data\PnkBstrK.sys
2008-09-18 13:46 103,736 ----a-w C:\WINDOWS\WINDOWS\system32\PnkBstrB.exe
2008-09-18 12:04 --------- d-----w C:\Program Files\Microsoft Works
2008-09-18 06:00 --------- d-----w C:\Program Files\Electronic Arts
2008-09-16 19:14 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-09-16 00:14 9,464 ------w C:\WINDOWS\WINDOWS\system32\drivers\cdralw2k.sys
2008-09-16 00:14 9,336 ------w C:\WINDOWS\WINDOWS\system32\drivers\cdr4_xp.sys
2008-09-16 00:14 43,528 ------w C:\WINDOWS\WINDOWS\system32\drivers\PxHelp20.sys
2008-09-16 00:14 129,784 ------w C:\WINDOWS\WINDOWS\system32\pxafs.dll
2008-09-16 00:14 120,056 ------w C:\WINDOWS\WINDOWS\system32\pxcpyi64.exe
2008-09-16 00:14 118,520 ------w C:\WINDOWS\WINDOWS\system32\pxinsi64.exe
2008-09-16 00:12 81,920 ----a-w C:\WINDOWS\WINDOWS\system32\dpl100.dll
2008-09-16 00:12 593,920 ----a-w C:\WINDOWS\WINDOWS\system32\dpuGUI11.dll
2008-09-16 00:12 57,344 ----a-w C:\WINDOWS\WINDOWS\system32\dpv11.dll
2008-09-16 00:12 53,248 ----a-w C:\WINDOWS\WINDOWS\system32\dpuGUI10.dll
2008-09-16 00:12 344,064 ----a-w C:\WINDOWS\WINDOWS\system32\dpus11.dll
2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\WINDOWS\system32\dpu11.dll
2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\WINDOWS\system32\dpu10.dll
2008-09-16 00:12 200,704 ----a-w C:\WINDOWS\WINDOWS\system32\ssldivx.dll
2008-09-16 00:12 196,608 ----a-w C:\WINDOWS\WINDOWS\system32\dtu100.dll
2008-09-16 00:12 1,044,480 ----a-w C:\WINDOWS\WINDOWS\system32\libdivx.dll
2008-09-14 18:13 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-09-12 19:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-09-10 18:37 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-10 17:33 --------- d-----w C:\Program Files\MSBuild
2008-08-29 08:18 87,336 ----a-w C:\WINDOWS\WINDOWS\system32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w C:\WINDOWS\WINDOWS\system32\dnssd.dll
2008-08-22 19:22 --------- d-----w C:\Program Files\Fichiers communs\BOONTY Shared
2008-08-22 19:22 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\BOONTY
2008-08-22 01:08 878,592 ----a-w C:\WINDOWS\WINDOWS\system32\wininet.dll
2008-08-22 01:08 43,008 ----a-w C:\WINDOWS\WINDOWS\system32\licmgr10.dll
2008-08-22 01:07 18,944 ----a-w C:\WINDOWS\WINDOWS\system32\corpol.dll
2008-08-22 01:06 72,704 ----a-w C:\WINDOWS\WINDOWS\system32\admparse.dll
2008-08-22 01:06 71,680 ----a-w C:\WINDOWS\WINDOWS\system32\iesetup.dll
2008-08-22 01:06 434,176 ----a-w C:\WINDOWS\WINDOWS\system32\vbscript.dll
2008-08-22 01:05 48,640 ------w C:\WINDOWS\WINDOWS\system32\PrivacIE.dll
2008-08-22 01:05 48,128 ----a-w C:\WINDOWS\WINDOWS\system32\mshtmler.dll
2008-08-22 01:05 35,840 ----a-w C:\WINDOWS\WINDOWS\system32\imgutil.dll
2008-08-22 01:04 45,568 ----a-w C:\WINDOWS\WINDOWS\system32\mshta.exe
2008-08-22 00:57 156,160 ----a-w C:\WINDOWS\WINDOWS\system32\msls31.dll
2008-08-17 16:09 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Trymedia
2008-08-17 15:26 --------- d-----w C:\Program Files\Eidos
2008-08-13 19:11 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-08-13 17:49 --------- d-----w C:\Program Files\Trend Micro
2008-08-13 06:45 --------- d-----w C:\Program Files\GFi
2008-08-12 07:46 --------- d-----w C:\Program Files\Fichiers communs\DirectX
2008-08-11 23:23 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\wmp
2008-08-11 22:03 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\Talkback
2008-08-11 11:42 --------- d-----w C:\Program Files\Valve
2008-08-11 11:27 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\Azureus
2008-08-11 10:50 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
2008-08-05 15:55 265,720 ----a-w C:\WINDOWS\WINDOWS\system32\msdbg2.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\WINDOWS\system32\muweb.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WINDOWS\WLXPGSS.SCR
2008-07-15 10:29 66,872 ----a-w C:\WINDOWS\WINDOWS\system32\PnkBstrA.exe
2008-07-09 13:00 98,304 ----a-w C:\WINDOWS\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((( snapshot@2008-10-08_21.38.56.81 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-27 11:04:48 247,904 ----a-w C:\WINDOWS\WINDOWS\system32\FNTCACHE.DAT
+ 2008-10-09 17:39:22 251,088 ----a-w C:\WINDOWS\WINDOWS\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
"ctfmon.exe"="C:\WINDOWS\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-07-09 9216]
"Center Agent"="C:\Program Files\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe" [2007-07-13 1435648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\WINDOWS\WINDOWS\system32\dumprep 0 -u" [X]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"JMB36X IDE Setup"="C:\WINDOWS\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 36864]
"36X Raid Configurer"="C:\WINDOWS\WINDOWS\system32\JMRaidSetup.exe" [2006-11-16 1953792]
"Ai Gear Help"="C:\Program Files\ASUS\AI Gear\GearHelp.exe" [2006-07-27 415744]
"Launch Ai Booster"="C:\Program Files\ASUS\AI Booster\OverClk.exe" [2006-11-28 3714048]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.15\AsRunHelp.exe" [2006-11-14 363008]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NvCplDaemon"="C:\WINDOWS\WINDOWS\system32\NvCpl.dll" [2008-03-24 13524992]
"NvMediaCenter"="C:\WINDOWS\WINDOWS\system32\NvMcTray.dll" [2008-03-24 86016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"nwiz"="nwiz.exe" [2008-03-24 C:\WINDOWS\WINDOWS\system32\nwiz.exe]
C:\Documents and Settings\Misterdy\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - C:\WINDOWS\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-05-14 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 16:58 58672 C:\WINDOWS\WINDOWS\system32\avldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP54"= SP5X_32.DLL
"vidc.jpeg"= m3jpeg32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R0 ivicd;Ivi CDVD Filter Driver;C:\WINDOWS\WINDOWS\system32\drivers\ivicd.sys [2005-01-12 38784]
R0 pavboot;Panda boot driver;C:\WINDOWS\WINDOWS\system32\Drivers\pavboot.sys [2008-06-19 28544]
R1 APPFLT;App Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\APPFLT.SYS [2008-06-25 73728]
R1 DSAFLT;DSA Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\DSAFLT.SYS [2008-06-18 52992]
R1 FNETMON;NetMon Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\fnetmon.SYS [2008-03-28 22072]
R1 IDSFLT;Ids Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\IDSFLT.SYS [2008-06-18 193792]
R1 NETFLTDI;Panda Net Driver [TDI Layer];C:\WINDOWS\WINDOWS\system32\Drivers\NETFLTDI.SYS [2008-07-11 14:58 158848]
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\WINDOWS\system32\DRIVERS\ShlDrv51.sys [2008-03-04 41144]
R1 WNMFLT;Wifi Monitor Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\WNMFLT.SYS [2008-06-18 46720]
R2 Gwmsrv;Panda Goodware Cache Manager;C:\WINDOWS\WINDOWS\system32\svchost -k Panda [ ]
R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\WINDOWS\system32\DRIVERS\PavProc.sys [2008-02-07 179640]
R2 PskSvcRetail;Panda PSK service;C:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2008-06-25 28928]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\WINDOWS\system32\drivers\av5flt.sys [ ]
R3 NetiMFLT01060034;PANDA NDIS IM Filter Miniport v1.6.0.34;C:\WINDOWS\WINDOWS\system32\DRIVERS\neti1634.sys [2008-06-26 197888]
R3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\WINDOWS\system32\PavSRK.sys [ ]
R3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\WINDOWS\system32\PavTPK.sys [ ]
S3 VNUSB;VN Series Device;C:\WINDOWS\WINDOWS\system32\DRIVERS\VNUSB.sys [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
.
Contenu du dossier 'Tâches planifiées'
2008-10-07 C:\WINDOWS\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-10-09 C:\WINDOWS\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-09 20:41:36
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-09 20:43:48
ComboFix-quarantined-files.txt 2008-10-09 18:43:36
ComboFix2.txt 2008-10-09 18:32:45
ComboFix3.txt 2008-10-08 19:47:29
ComboFix4.txt 2008-10-08 19:40:00
Avant-CF: 9 996 582 912 octets libres
Après-CF: 9,983,356,928 octets libres
330 --- E O F --- 2008-09-20 17:26:54
- 1
- 2