Erreur d'application Rundll32.exe HELP ME!!!

Résolu
Slt j'ai executer ccleaner et le message suivant et apparu:

L'instruction à "0x012c7d2d" emploie l'adresse mémoire "0x00000000". La mémoire ne peut pas être "written".

Aider mois svp!!!
Configuration: Windows XP
Firefox 3.0.1

26 réponses

Résumé de la discussion

Le fil porte sur une erreur mémoire après l'exécution de CCleaner sous Windows XP, indiquant que l'instruction à 0x012c7d2d utilise l'adresse 0x00000000 et que la mémoire ne peut pas être écrite. Plusieurs éléments de réponse proposent des mesures techniques: Réponse 1 suggère d'utiliser Flash_Disinfector et d'enregistrer un rapport RSIT après exécution des vérifications. En parallèle, certaines réponses agrègent simplement la demande d'aide sans apport technique précis, tandis que d'autres fournissent des extraits du rapport RSIT et des éléments de HijackThis pour étayer l'analyse. Dernier élément utile, le rapport RSIT et HijackThis indiquent de multiples services et programmes démarrés, ce qui suggère une activité système étendue et une possible infection de modules indésirables.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    bien, à toi.

    En lisant ton rapport, j'ai vu que tu avais des rapports de navilog. ca m'a permis de découvrir que tu en étais à ton 5ème topic, que tu avais laissé tombé au moins 2 fois et que il s'est passé 5 jours entre ma réponse et la tienne.

    Alors le "help me please" est de mauvais goût.

    Télécharge Flash_Disinfector de sUBs ici :

    https://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe

    Enregistre le sur ton Bureau.

    Double clique sur Flash_Disinfector.exe pour le lancer
    .
    Quand le message : "Plug in yours flash drive & clic Ok to begin disinfection" apparaitra , connecte les clés USB et périphériques USB externes susceptibles d'avoir été infectés.

    Puis clique sur Ok

    Les icônes sur le Bureau vont disparaitre jusqu'à l'apparition du message: "Done!!"

    Appuye sur "Ok", pour faire réapparaitre le Bureau

    Remets un rapport RSIT.
    4
    1. J'ai été voir en enfer, j'ai rien trouvé :-(
      Une personne a eu le même problème hier, son post était trop gros, il a fallu le fragmenter.
      0
      1. Contributeur sécurité
        Re,

        je comprenais bien que vous pouvez pas remonter indéfiniment dans le temps.

        j'ai reposté et c'est parti dans l'enfer ccmien..
        0
        1. Ah ben je peux pas remonter plus loin que 20h :-(
          Resposte si tu veux, je transmettrai.
          0
          1. Contributeur sécurité
            Bonsoir,

            merci de le recherche sacabouffe (mais les posts sont antérieurs).

            Je remets le contenu du rapport RSIT e,nvoyé par mp.

            Le scan on line par Kaspersky (post 21) reste à faire.
            0
            1. Salut
              Désolé, j'ai rien en réserve depuis 20h :-(
              Bonne soirée
              0
              1. Contributeur sécurité
                Bonsoir,

                j'ai demandé à la modération si des posts n'étaient pas aux oubliettes, y compris un post de moi en réponse à ton mp.

                En attendant leur réponse, fais ça :

                Fais un scan en ligne Kaspersky avec Internet Explorer :
                - Clique sur Démarrer Online-Scanner

                - Clique maintenant sur J'accepte.
                - Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
                - Patiente pendant l'installation des Mises à jour.
                - Choisis par la suite l'analyse du Poste de travail.
                - Sauvegarde puis colle le rapport généré en fin d'analyse.

                AIDE : Configurer le contrôle des ActiveX

                NOTE : <ital>Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle <gras>O
                0
                1. Pourkoi je ne pe pa poster le rapport, sa fait 3 jour que j'éssaye
                  -1
                  1. Contributeur sécurité
                    Bonjour,

                    j'espère que tu as pris le rapport trop tôt et que tu as fait la suite.

                    Refais tourner MBAM pour vérification.

                    Pour info, zPharao.exe est une saleté.

                    J'ai l'impression qu'elle n'a pas fait de dégats.

                    Pour vérifier :

                    refais un rapport RSIT.
                    0
                    1. voila le rapport:
                      Malwarebytes' Anti-Malware 1.28
                      Version de la base de données: 1251
                      Windows 5.1.2600 Service Pack 2

                      11/10/2008 06:50:45
                      mbam-log-2008-10-11 (06-50-29).txt

                      Type de recherche: Examen complet (C:\|E:\|G:\|H:\|X:\|Y:\|Z:\|)
                      Eléments examinés: 232106
                      Temps écoulé: 2 hour(s), 46 minute(s), 11 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 5

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      E:\kkkk\logiciel\ Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe (Trojan.Downloader) -> No action taken.
                      E:\kkkk\logiciel\ Norton Antivirus Professional 2004 + keygen\ Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe (Trojan.Downloader) -> No action taken.
                      E:\kkkk\logiciel\Microsoft Windows Key Gen. 2003 or XP Pro or Office-XP keygen(1)\XPKey.exe (Trojan.Downloader) -> No action taken.
                      E:\kkkk\plan\Utilitaire\logiciel arhi,autocad\Graphisoft\ArchiCAD 9\Extensions\ArchiTerra 2.05\ArchiCad_ArchiTerra_2.05_(AC90)_crk.exe (Trojan.Downloader) -> No action taken.
                      C:\zPharaoh.exe (Worm.Mabezat) -> No action taken.
                      0
                      1. Contributeur sécurité
                        Re,

                        on fera ça à la fin.

                        Je crois que tu as MBAM.

                        mets le à jour et scanne.

                        Poste le rapport.
                        0
                        1. est ce qu'il faut que j'éfface OTMoveit3 aprés son utilisation
                          0
                          1. sllt voici le rapport:

                            ========== FILES ==========
                            E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe moved successfully.

                            OTMoveIt3 by OldTimer - Version 1.0.4.2 log created on 10102008_201726
                            0
                            1. Contributeur sécurité
                              Bonjour,

                              toujours avec ta clé connectée,

                              Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :

                              http://oldtimer.geekstogo.com/OTMoveIt3.exe

                              Double-clique sur OTMoveIt3.exe pour le lancer.

                              Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

                              Copie la liste qui se trouve en gras ci-dessous,

                              et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

                              :files
                              E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe


                              Clique sur "MoveIt!" pour lancer la suppression.

                              Le résultat apparaitra dans le cadre "Results".

                              Clique sur "Exit" pour fermer.

                              Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

                              Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
                              0
                              1. Fichier SpeederXP1.6.exe reçu le 2008.10.10 16:35:21 (CET)
                                Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
                                Résultat: 5/35 (14.29%)
                                en train de charger les informations du serveur...
                                Votre fichier est dans la file d'attente, en position: ___.
                                L'heure estimée de démarrage est entre ___ et ___ .
                                Ne fermez pas la fenêtre avant la fin de l'analyse.
                                L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                                Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                                Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                                les résultats seront affichés au fur et à mesure de leur génération.
                                Formaté Formaté
                                Impression des résultats Impression des résultats
                                Votre fichier a expiré ou n'existe pas.
                                Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

                                Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
                                Email:

                                Antivirus Version Dernière mise à jour Résultat
                                AhnLab-V3 2008.10.10.1 2008.10.10 -
                                AntiVir 7.8.1.34 2008.10.10 -
                                Authentium 5.1.0.4 2008.10.10 -
                                Avast 4.8.1248.0 2008.10.09 -
                                AVG 8.0.0.161 2008.10.10 -
                                BitDefender 7.2 2008.10.10 Trojan.Pws.Lenmir.30
                                CAT-QuickHeal 9.50 2008.10.10 -
                                ClamAV 0.93.1 2008.10.10 -
                                DrWeb 4.44.0.09170 2008.10.10 -
                                eSafe 7.0.17.0 2008.10.08 Win32.VB.cny
                                eTrust-Vet 31.6.6139 2008.10.09 -
                                Ewido 4.0 2008.10.10 -
                                F-Prot 4.4.4.56 2008.10.10 -
                                F-Secure 8.0.14332.0 2008.10.10 -
                                Fortinet 3.113.0.0 2008.10.10 -
                                GData 19 2008.10.10 Trojan.Pws.Lenmir.30
                                Ikarus T3.1.1.34.0 2008.10.10 Trojan.Win32.VB.cny
                                K7AntiVirus 7.10.489 2008.10.09 -
                                Kaspersky 7.0.0.125 2008.10.10 -
                                McAfee 5402 2008.10.09 -
                                Microsoft 1.4005 2008.10.10 -
                                Norman 5.80.02 2008.10.10 -
                                Panda 9.0.0.4 2008.10.10 -
                                PCTools 4.4.2.0 2008.10.10 -
                                Prevx1 V2 2008.10.10 -
                                Rising 20.65.42.00 2008.10.10 -
                                SecureWeb-Gateway 6.7.6 2008.10.10 -
                                Sophos 4.34.0 2008.10.10 -
                                Sunbelt 3.1.1708.1 2008.10.10 -
                                Symantec 10 2008.10.10 -
                                TheHacker 6.3.1.0.105 2008.10.10 -
                                TrendMicro 8.700.0.1004 2008.10.10 -
                                VBA32 3.12.8.6 2008.10.09 Trojan.Win32.VB.cny
                                ViRobot 2008.10.10.1416 2008.10.10 -
                                VirusBuster 4.5.11.0 2008.10.10 -
                                Information additionnelle
                                File size: 560724 bytes
                                MD5...: a768a3156382b4c6f0ae531f8e9f0c9a
                                SHA1..: 63626c63133739d2420f7139f962364640b2e991
                                SHA256: dd468d9cede5f0529e840b1ad2a37e79205226d8e6139b5860d2bdf380b36e61
                                SHA512: f22cf7c47f058ba8daa3bbe67e8ff282c008bc99c5fc524f742814c188196a6c
                                8c0e7f625dba1a2ebae8aa9058f326da35b9dea7d2d56ebf7f7296a38b23f8e8
                                PEiD..: -
                                TrID..: File type identification
                                Inno Setup installer (96.7%)
                                Generic Win/DOS Executable (1.6%)
                                DOS Executable Generic (1.6%)
                                Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
                                PEInfo: PE Structure information

                                ( base data )
                                entrypointaddress.: 0x40bf98
                                timedatestamp.....: 0x2a425e19 (Fri Jun 19 22:22:17 1992)
                                machinetype.......: 0x14c (I386)

                                ( 8 sections )
                                name viradd virsiz rawdsiz ntrpy md5
                                CODE 0x1000 0xb650 0xb800 6.48 d81967196488bed91d07a25e8d0ce84c
                                DATA 0xd000 0x17e0 0x1800 3.26 56a5aaf0af5228630c63c49761fd2e97
                                BSS 0xf000 0x1190 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
                                .idata 0x11000 0x75e 0x800 4.53 8f5d13420b574360d07b7076ddb1a364
                                .tls 0x12000 0x8 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
                                .rdata 0x13000 0x18 0x200 0.21 c233c0ea7d984808a57c6681c85abaad
                                .reloc 0x14000 0x854 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
                                .rsrc 0x15000 0x1400 0x1400 4.17 045d4bbb9ecd3d1e283590f9f4834b8e

                                ( 8 imports )
                                > kernel32.dll: DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, ExitProcess, CreateFileA, CloseHandle
                                > user32.dll: MessageBoxA
                                > oleaut32.dll: VariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
                                > advapi32.dll: OpenProcessToken, LookupPrivilegeValueA
                                > kernel32.dll: Sleep, SetLastError, SetErrorMode, GetWindowsDirectoryA, GetVersionExA, GetTempFileNameA, GetSystemDefaultLCID, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetCPInfo, FormatMessageA, DeleteFileA, CreateProcessA, CloseHandle
                                > user32.dll: TranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, GetSystemMetrics, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA, CharNextA
                                > comctl32.dll: InitCommonControls
                                > advapi32.dll: AdjustTokenPrivileges

                                ( 0 exports )
                                packers (Kaspersky): UPX, UPX, UPX, UPX
                                0
                                1. Contributeur sécurité
                                  Re,

                                  la politique des cracks est assez proche de la roulette russe.

                                  Laisse ta clé E:\ connectée.

                                  Rends toi sur ce site :

                                  https://www.virustotal.com/gui/

                                  Clique sur parcourir et cherche ce fichier : E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe

                                  Clique sur Send File.

                                  Un rapport va s'élaborer ligne à ligne.

                                  Attends la fin. Il doit comprendre la taille du fichier envoyé.

                                  Sauvegarde le rapport avec le bloc-note.

                                  Copie le dans ta réponse.

                                  Si VirusTotal indique que le fichier a déjà été analysé, cliquer sur le bouton Reanalyse le fichier maintenant
                                  0
                                  1. BitDefender Online Scanner

                                    Rapport d'analyse généré à: Thu, Oct 09, 2008 - 22:32:06

                                    Voie d'analyse: A:\;C:\;D:\;E:\;F:\;G:\;H:\;

                                    Statistiques

                                    Temps
                                    00:56:30

                                    Fichiers
                                    167117

                                    Directoires
                                    13724

                                    Secteurs de boot
                                    0

                                    Archives
                                    2799

                                    Paquets programmes
                                    13269

                                    Résultats

                                    Virus identifiés
                                    3

                                    Fichiers infectés
                                    3

                                    Fichiers suspects
                                    0

                                    Avertissements
                                    0

                                    Désinfectés
                                    0

                                    Fichiers effacés
                                    3

                                    Info sur les moteurs

                                    Définition virus
                                    1854547

                                    Version des moteurs
                                    AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

                                    Analyse des plugins
                                    16

                                    Archive des plugins
                                    43

                                    Unpack des plugins
                                    7

                                    E-mail plugins
                                    6

                                    Système plugins
                                    4

                                    Paramètres d'analyse

                                    Première action
                                    Désinfecté

                                    Seconde Action
                                    Supprimé

                                    Heuristique
                                    Oui

                                    Acceptez les avertissements
                                    Oui

                                    Extensions analysées
                                    exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                                    Excludez les extensions

                                    Analyse d'emails
                                    Oui

                                    Analyse des Archives
                                    Oui

                                    Analyser paquets programmes
                                    Oui

                                    Analyse des fichiers
                                    Oui

                                    Analyse de boot
                                    Oui

                                    Fichier analysé
                                    Statut

                                    C:\Documents and Settings\Misterdy\Mes documents\téléchar\pqremove.com
                                    Infecté par: Trojan.Generic.169733

                                    C:\Documents and Settings\Misterdy\Mes documents\téléchar\pqremove.com
                                    Supprimé

                                    C:\Program Files\Navilog1\Backupnavi\egsso.exe
                                    Détecté avec: Adware.NaviPromo.Gen.2

                                    C:\Program Files\Navilog1\Backupnavi\egsso.exe
                                    Echec de la désinfection

                                    C:\Program Files\Navilog1\Backupnavi\egsso.exe
                                    Supprimé

                                    E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)=>(Instyler Module 9)
                                    Infecté par: Trojan.Pws.Lenmir.30

                                    E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)=>(Instyler Module 9)
                                    Echec de la désinfection

                                    E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)=>(Instyler Module 9)
                                    Supprimé

                                    E:\stock\EMule a RAzzo!\Speeder Xp v1.6 Crack(Acelera Emule Doble Velocidad)By Mc Stryker\SpeederXP1.6.exe=>(Instyler o)
                                    Echec de la mise à jour
                                    0
                                    1. Contributeur sécurité
                                      Tr,

                                      parfait, on a éliminé l'infection des disques amovibles.
                                      0
                                      1. et maintenant je fais une analyse en ligne avc bitdefender pour avoir le rapport, que je v afficher dan quelque minute
                                        0
                                        1. slt g dja fait rav , puis j'ai fait vacciner les clé et périphérique usb, puis j'ai fais un rapport avec combofix, et puis j'ai crée un fichier bloc note avec:
                                          Registry::
                                          [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a1a3f3e-8d21-11dd-acea-001e8ce1ec2b}]
                                          [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5ca3fe8-8fd0-11dd-acf3-001e8ce1ec2b}]
                                          [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11aefc8c-6ed7-11dd-ac89-001e8ce1ec2b}]

                                          que j'ai glisser sur combofix et voici le rapport obtenue:

                                          ComboFix 08-10-07.06 - Misterdy 2008-10-09 20:37:30.5 - NTFSx86
                                          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2333 [GMT 2:00]
                                          Lancé depuis: C:\Documents and Settings\Misterdy\Bureau\ComboFix.exe
                                          Commutateurs utilisés
                                          C:\Documents and Settings\Misterdy\Bureau\CFScript.txt

                                          [COLOR=RED]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/COLOR]
                                          .

                                          ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-09 au 2008-10-09 ))))))))))))))))))))))))))))))))))))
                                          .

                                          2008-10-09 19:46 . 2008-10-09 19:46 <REP> d--hs---- C:\Documents and Settings\Misterdy\UserData
                                          2008-10-09 12:23 . 2008-10-09 12:23 268 --ah----- C:\sqmdata08.sqm
                                          2008-10-09 12:23 . 2008-10-09 12:23 244 --ah----- C:\sqmnoopt08.sqm
                                          2008-10-09 12:19 . 2001-08-24 14:00 2,864 --a------ C:\WINDOWS\WINDOWS\system32\MSCICH32.DLL
                                          2008-10-09 12:17 . 2008-10-09 12:17 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\cadwork.cat
                                          2008-10-09 12:04 . 2008-10-09 12:17 <REP> d-------- C:\Program Files\cadwork.dir
                                          2008-10-09 12:04 . 2008-10-09 12:04 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\cadwork
                                          2008-10-09 12:04 . 2008-10-09 12:08 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\cadwork
                                          2008-10-08 20:09 . 2008-10-08 20:09 268 --ah----- C:\sqmdata07.sqm
                                          2008-10-08 20:09 . 2008-10-08 20:09 244 --ah----- C:\sqmnoopt07.sqm
                                          2008-10-08 19:23 . 2008-10-08 19:23 268 --ah----- C:\sqmdata06.sqm
                                          2008-10-08 19:23 . 2008-10-08 19:23 244 --ah----- C:\sqmnoopt06.sqm
                                          2008-10-07 21:20 . 2008-10-07 21:20 268 --ah----- C:\sqmdata05.sqm
                                          2008-10-07 21:20 . 2008-10-07 21:20 244 --ah----- C:\sqmnoopt05.sqm
                                          2008-10-07 21:16 . 2008-10-07 21:16 268 --ah----- C:\sqmdata04.sqm
                                          2008-10-07 21:16 . 2008-10-07 21:16 244 --ah----- C:\sqmnoopt04.sqm
                                          2008-10-07 20:20 . 2008-10-07 20:20 268 --ah----- C:\sqmdata03.sqm
                                          2008-10-07 20:20 . 2008-10-07 20:20 244 --ah----- C:\sqmnoopt03.sqm
                                          2008-10-07 20:14 . 2008-10-07 20:14 268 --ah----- C:\sqmdata02.sqm
                                          2008-10-07 20:14 . 2008-10-07 20:14 244 --ah----- C:\sqmnoopt02.sqm
                                          2008-10-07 20:13 . 2008-10-07 20:25 <REP> d-------- C:\Program Files\Microsoft Bootvis
                                          2008-10-07 19:21 . 2008-10-07 19:21 268 --ah----- C:\sqmdata01.sqm
                                          2008-10-07 19:21 . 2008-10-07 19:21 244 --ah----- C:\sqmnoopt01.sqm
                                          2008-10-07 18:42 . 2008-10-07 18:43 <REP> d-------- C:\rsit
                                          2008-10-07 13:23 . 2008-10-07 13:23 268 --ah----- C:\sqmdata00.sqm
                                          2008-10-07 13:23 . 2008-10-07 13:23 244 --ah----- C:\sqmnoopt00.sqm
                                          2008-10-05 20:43 . 2008-10-05 20:43 <REP> d-------- C:\Program Files\iTunes
                                          2008-10-05 20:43 . 2008-10-05 20:43 <REP> d-------- C:\Program Files\iPod
                                          2008-10-05 20:43 . 2008-10-07 17:21 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Apple Computer
                                          2008-10-05 20:43 . 2008-10-05 20:43 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
                                          2008-10-05 20:43 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\WINDOWS\system32\GEARAspi.dll
                                          2008-10-05 20:43 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\WINDOWS\system32\drivers\GEARAspiWDM.sys
                                          2008-10-05 20:42 . 2008-10-05 20:42 <REP> d-------- C:\Program Files\Bonjour
                                          2008-10-05 20:41 . 2008-10-05 20:42 <REP> d-------- C:\Program Files\QuickTime
                                          2008-10-05 20:41 . 2008-10-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\Apple
                                          2008-10-05 20:41 . 2008-10-05 20:41 <REP> d-------- C:\Program Files\Apple Software Update
                                          2008-10-05 20:41 . 2008-10-05 20:43 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
                                          2008-10-05 20:41 . 2008-10-05 20:41 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
                                          2008-10-03 19:12 . 2008-10-03 19:12 <REP> d-------- C:\Program Files\Microsoft Games
                                          2008-10-01 21:34 . 2008-10-03 18:00 <REP> d-------- C:\UT2004
                                          2008-10-01 21:34 . 2002-07-08 00:14 1,294,336 --a------ C:\WINDOWS\WINDOWS\system32\vorbis.acm
                                          2008-10-01 20:08 . 2008-10-01 20:08 <REP> d-------- C:\Documents and Settings\Administrateur.MISTERDY\Application Data\Malwarebytes
                                          2008-10-01 19:17 . 2007-04-20 07:34 674,048 -ra------ C:\WINDOWS\WINDOWS\system32\drivers\3xHybrid.sys
                                          2008-10-01 19:17 . 2007-01-29 04:29 1,748 --a------ C:\WINDOWS\WINDOWS\French.lng
                                          2008-10-01 19:17 . 2007-02-13 08:03 1,324 --a------ C:\WINDOWS\WINDOWS\TVP3XDrv.ini
                                          2008-10-01 18:47 . 2008-10-01 18:50 <REP> d-------- C:\Program Files\SuperCopier
                                          2008-09-30 22:01 . 2008-09-30 22:01 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                                          2008-09-30 22:01 . 2008-09-30 22:01 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Malwarebytes
                                          2008-09-30 22:01 . 2008-09-30 22:01 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
                                          2008-09-30 22:01 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\WINDOWS\system32\drivers\mbamswissarmy.sys
                                          2008-09-30 22:01 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\WINDOWS\system32\drivers\mbam.sys
                                          2008-09-30 17:58 . 2008-10-02 19:09 <REP> d-------- C:\Program Files\Navilog1
                                          2008-09-30 06:50 . 2008-09-30 06:50 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\DivX
                                          2008-09-29 20:50 . 2008-09-29 20:50 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PCPitstop
                                          2008-09-29 20:01 . 2008-09-29 20:00 1,388,544 --a------ C:\WINDOWS\WINDOWS\system32\msvbvm60.dll
                                          2008-09-29 18:57 . 2008-09-30 21:51 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                                          2008-09-27 19:19 . 2008-09-27 19:19 <REP> d--hs---- C:\Documents and Settings\Misterdy\PrivacIE
                                          2008-09-27 18:50 . 2008-09-27 18:51 <REP> d--h-c--- C:\WINDOWS\WINDOWS\ie8
                                          2008-09-27 00:10 . 2008-09-27 00:10 <REP> d--h----- C:\WINDOWS\WINDOWS\system32\GroupPolicy
                                          2008-09-25 19:34 . 2008-09-25 19:34 45 --a------ C:\WINDOWS\WINDOWS\system32\initdebug.nfo
                                          2008-09-25 16:34 . 2008-10-07 10:03 8,627 --a------ C:\WINDOWS\WINDOWS\system32\PAV_FOG.OPC
                                          2008-09-25 15:55 . 2008-09-25 15:55 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Backup
                                          2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\WINDOWS\WINDOWS\system32\PAV
                                          2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\Program Files\Panda Security
                                          2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Panda Security
                                          2008-09-25 15:54 . 2008-09-25 15:54 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Panda Security
                                          2008-09-25 15:54 . 2008-06-18 18:03 520,448 --a------ C:\WINDOWS\WINDOWS\system32\PavSHook.dll
                                          2008-09-25 15:54 . 2003-10-22 18:23 446,464 --a------ C:\WINDOWS\WINDOWS\system32\HHActiveX.dll
                                          2008-09-25 15:54 . 2008-06-26 11:25 197,888 --a------ C:\WINDOWS\WINDOWS\system32\drivers\neti1634.sys
                                          2008-09-25 15:54 . 2008-06-24 14:48 193,280 --a------ C:\WINDOWS\WINDOWS\system32\TpUtil.dll
                                          2008-09-25 15:54 . 2007-02-08 11:53 107,568 --a------ C:\WINDOWS\WINDOWS\system32\SYSTOOLS.DLL
                                          2008-09-25 15:54 . 2008-06-18 18:03 87,296 --a------ C:\WINDOWS\WINDOWS\system32\PavLspHook.dll
                                          2008-09-25 15:54 . 2008-03-18 16:58 58,672 --a------ C:\WINDOWS\WINDOWS\system32\avldr.dll
                                          2008-09-25 15:54 . 2008-06-18 18:03 55,552 --a------ C:\WINDOWS\WINDOWS\system32\pavipc.dll
                                          2008-09-25 15:53 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\WINDOWS\system32\drivers\pavboot.sys
                                          2008-09-25 15:52 . 2008-09-25 15:52 <REP> d-------- C:\Program Files\Fichiers communs\Panda Security
                                          2008-09-25 15:52 . 2008-02-07 12:03 179,640 -ra------ C:\WINDOWS\WINDOWS\system32\drivers\PavProc.sys
                                          2008-09-25 15:52 . 2008-03-04 15:59 41,144 -ra------ C:\WINDOWS\WINDOWS\system32\drivers\ShlDrv51.sys
                                          2008-09-25 14:24 . 2008-09-30 06:46 <REP> d-------- C:\Temp
                                          2008-09-25 13:32 . 2008-09-27 16:14 <REP> d-------- C:\WINDOWS\WINDOWS\system32\CatRoot_bak
                                          2008-09-25 12:04 . 2008-09-25 12:04 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\Ubisoft
                                          2008-09-25 12:04 . 2008-09-25 12:04 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ubisoft
                                          2008-09-25 11:54 . 2008-09-25 11:54 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\InstallShield
                                          2008-09-25 09:37 . 2008-09-25 09:37 129,536 --a------ C:\WINDOWS\WINDOWS\system32\IJL15.dll
                                          2008-09-22 11:24 . 2002-07-17 09:20 45,056 --a------ C:\WINDOWS\WINDOWS\system32\WNASPI2K.BAK
                                          2008-09-22 11:24 . 2002-07-17 08:53 16,877 --a------ C:\WINDOWS\WINDOWS\system32\drivers\ASPI2K.BAK
                                          2008-09-22 11:24 . 2002-07-17 16:22 5,600 --a------ C:\WINDOWS\WINDOWS\system\WINASPI.BAK
                                          2008-09-22 11:24 . 2002-07-17 16:22 4,672 --a------ C:\WINDOWS\WINDOWS\system\WOWPOST.BAK
                                          2008-09-22 11:22 . 2008-10-05 20:41 <REP> d-------- C:\WINDOWS\WINDOWS\system32\QuickTime
                                          2008-09-22 11:22 . 2003-03-25 06:49 301,568 -ra------ C:\WINDOWS\WINDOWS\system32\L3codeca.acm
                                          2008-09-22 11:22 . 2004-08-04 00:55 294,912 --a------ C:\WINDOWS\WINDOWS\system32\msh263.drv
                                          2008-09-19 20:35 . 2005-02-26 07:34 442,368 -ra------ C:\WINDOWS\WINDOWS\system32\vp6vfw.dll
                                          2008-09-18 15:49 . 2008-09-18 15:49 <REP> d-------- C:\WINDOWS\WINDOWS\system32\URTTEMP
                                          2008-09-18 15:46 . 2008-09-18 15:46 669,184 --a------ C:\WINDOWS\WINDOWS\system32\pbsvc.exe
                                          2008-09-18 09:10 . 2008-09-25 09:37 94,208 --a------ C:\WINDOWS\WINDOWS\system32\ScrUnZip.dll
                                          2008-09-16 02:14 . 2008-09-16 02:14 3,596,288 --a------ C:\WINDOWS\WINDOWS\system32\qt-dx331.dll
                                          2008-09-16 02:14 . 2008-09-16 02:14 524,288 --a------ C:\WINDOWS\WINDOWS\system32\DivXsm.exe
                                          2008-09-16 02:14 . 2008-09-16 02:14 9,878 --a------ C:\WINDOWS\WINDOWS\system32\dsm_fr.qm
                                          2008-09-16 02:14 . 2008-09-16 02:14 4,816 --a------ C:\WINDOWS\WINDOWS\system32\divxsm.tlb
                                          2008-09-16 02:11 . 2008-09-16 02:11 823,296 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx0c.dll
                                          2008-09-16 02:11 . 2008-09-16 02:11 823,296 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx07.dll
                                          2008-09-16 02:11 . 2008-09-16 02:11 815,104 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx0a.dll
                                          2008-09-16 02:11 . 2008-09-16 02:11 802,816 --a------ C:\WINDOWS\WINDOWS\system32\divx_xx11.dll
                                          2008-09-16 02:11 . 2008-09-16 02:11 683,520 --a------ C:\WINDOWS\WINDOWS\system32\DivX.dll
                                          2008-09-16 02:11 . 2008-09-16 02:11 634,880 --a------ C:\WINDOWS\WINDOWS\system32\divxdec.ax
                                          2008-09-16 02:11 . 2008-09-16 02:11 352,401 --a------ C:\WINDOWS\WINDOWS\system32\DivXMedia.ax
                                          2008-09-16 02:11 . 2008-09-16 02:11 161,096 --a------ C:\WINDOWS\WINDOWS\system32\DivXCodecVersionChecker.exe
                                          2008-09-16 02:11 . 2008-09-16 02:11 12,288 --a------ C:\WINDOWS\WINDOWS\system32\DivXWMPExtType.dll
                                          2008-09-14 22:47 . 2008-09-14 22:54 <REP> d-------- C:\Documents and Settings\Misterdy\Application Data\codeblocks
                                          2008-09-14 20:18 . 2008-09-17 22:58 <REP> d-------- C:\Program Files\Kaspersky Lab
                                          2008-09-14 20:09 . 2008-09-14 20:09 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
                                          2008-09-10 20:23 . 2008-09-19 19:41 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
                                          2008-09-10 19:32 . 2008-09-10 19:36 <REP> d-------- C:\WINDOWS\WINDOWS\system32\XPSViewer
                                          2008-09-10 19:31 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\WINDOWS\system32\spmsg2.dll

                                          .
                                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                          .
                                          2008-10-09 18:07 1,132 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFLTR.CFG.bck
                                          2008-10-09 18:07 1,132 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFLTR.CFG
                                          2008-10-09 10:23 294,988 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFCONT.DAT.bck
                                          2008-10-09 10:23 294,988 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\APPFCONT.DAT
                                          2008-10-08 17:39 122,880 ----a-w C:\VaccinUSB.exe
                                          2008-10-02 13:36 --------- d-----w C:\Program Files\Google
                                          2008-10-01 20:08 --------- d-----w C:\Program Files\SuperCopier2
                                          2008-10-01 19:34 --------- d-----w C:\Program Files\VstPlugins
                                          2008-10-01 17:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                          2008-10-01 17:19 --------- d-----w C:\Program Files\CyberLink
                                          2008-09-30 21:37 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\Desktopicon
                                          2008-09-30 19:51 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
                                          2008-09-29 17:26 --------- d-----w C:\Program Files\DivX
                                          2008-09-29 16:56 --------- d-----w C:\Program Files\Unlocker
                                          2008-09-29 16:56 --------- d-----w C:\Program Files\CCleaner
                                          2008-09-29 16:19 --------- d-----w C:\Program Files\Olympus
                                          2008-09-27 18:36 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                                          2008-09-27 18:06 31 ----a-w C:\Program Files\Fichiers communs\appop.log
                                          2008-09-26 22:01 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\BitTorrent
                                          2008-09-25 09:55 --------- d-----w C:\Program Files\Ubisoft
                                          2008-09-22 11:35 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
                                          2008-09-22 11:24 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
                                          2008-09-18 13:46 22,328 ----a-w C:\WINDOWS\WINDOWS\system32\drivers\PnkBstrK.sys
                                          2008-09-18 13:46 22,328 ----a-w C:\Documents and Settings\Misterdy\Application Data\PnkBstrK.sys
                                          2008-09-18 13:46 103,736 ----a-w C:\WINDOWS\WINDOWS\system32\PnkBstrB.exe
                                          2008-09-18 12:04 --------- d-----w C:\Program Files\Microsoft Works
                                          2008-09-18 06:00 --------- d-----w C:\Program Files\Electronic Arts
                                          2008-09-16 19:14 --------- d-----w C:\Program Files\Microsoft SQL Server
                                          2008-09-16 00:14 9,464 ------w C:\WINDOWS\WINDOWS\system32\drivers\cdralw2k.sys
                                          2008-09-16 00:14 9,336 ------w C:\WINDOWS\WINDOWS\system32\drivers\cdr4_xp.sys
                                          2008-09-16 00:14 43,528 ------w C:\WINDOWS\WINDOWS\system32\drivers\PxHelp20.sys
                                          2008-09-16 00:14 129,784 ------w C:\WINDOWS\WINDOWS\system32\pxafs.dll
                                          2008-09-16 00:14 120,056 ------w C:\WINDOWS\WINDOWS\system32\pxcpyi64.exe
                                          2008-09-16 00:14 118,520 ------w C:\WINDOWS\WINDOWS\system32\pxinsi64.exe
                                          2008-09-16 00:12 81,920 ----a-w C:\WINDOWS\WINDOWS\system32\dpl100.dll
                                          2008-09-16 00:12 593,920 ----a-w C:\WINDOWS\WINDOWS\system32\dpuGUI11.dll
                                          2008-09-16 00:12 57,344 ----a-w C:\WINDOWS\WINDOWS\system32\dpv11.dll
                                          2008-09-16 00:12 53,248 ----a-w C:\WINDOWS\WINDOWS\system32\dpuGUI10.dll
                                          2008-09-16 00:12 344,064 ----a-w C:\WINDOWS\WINDOWS\system32\dpus11.dll
                                          2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\WINDOWS\system32\dpu11.dll
                                          2008-09-16 00:12 294,912 ----a-w C:\WINDOWS\WINDOWS\system32\dpu10.dll
                                          2008-09-16 00:12 200,704 ----a-w C:\WINDOWS\WINDOWS\system32\ssldivx.dll
                                          2008-09-16 00:12 196,608 ----a-w C:\WINDOWS\WINDOWS\system32\dtu100.dll
                                          2008-09-16 00:12 1,044,480 ----a-w C:\WINDOWS\WINDOWS\system32\libdivx.dll
                                          2008-09-14 18:13 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
                                          2008-09-12 19:27 --------- d-----w C:\Program Files\Microsoft Silverlight
                                          2008-09-10 18:37 --------- d-----w C:\Program Files\Microsoft.NET
                                          2008-09-10 17:33 --------- d-----w C:\Program Files\MSBuild
                                          2008-08-29 08:18 87,336 ----a-w C:\WINDOWS\WINDOWS\system32\dns-sd.exe
                                          2008-08-29 07:53 61,440 ----a-w C:\WINDOWS\WINDOWS\system32\dnssd.dll
                                          2008-08-22 19:22 --------- d-----w C:\Program Files\Fichiers communs\BOONTY Shared
                                          2008-08-22 19:22 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\BOONTY
                                          2008-08-22 01:08 878,592 ----a-w C:\WINDOWS\WINDOWS\system32\wininet.dll
                                          2008-08-22 01:08 43,008 ----a-w C:\WINDOWS\WINDOWS\system32\licmgr10.dll
                                          2008-08-22 01:07 18,944 ----a-w C:\WINDOWS\WINDOWS\system32\corpol.dll
                                          2008-08-22 01:06 72,704 ----a-w C:\WINDOWS\WINDOWS\system32\admparse.dll
                                          2008-08-22 01:06 71,680 ----a-w C:\WINDOWS\WINDOWS\system32\iesetup.dll
                                          2008-08-22 01:06 434,176 ----a-w C:\WINDOWS\WINDOWS\system32\vbscript.dll
                                          2008-08-22 01:05 48,640 ------w C:\WINDOWS\WINDOWS\system32\PrivacIE.dll
                                          2008-08-22 01:05 48,128 ----a-w C:\WINDOWS\WINDOWS\system32\mshtmler.dll
                                          2008-08-22 01:05 35,840 ----a-w C:\WINDOWS\WINDOWS\system32\imgutil.dll
                                          2008-08-22 01:04 45,568 ----a-w C:\WINDOWS\WINDOWS\system32\mshta.exe
                                          2008-08-22 00:57 156,160 ----a-w C:\WINDOWS\WINDOWS\system32\msls31.dll
                                          2008-08-17 16:09 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Trymedia
                                          2008-08-17 15:26 --------- d-----w C:\Program Files\Eidos
                                          2008-08-13 19:11 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
                                          2008-08-13 17:49 --------- d-----w C:\Program Files\Trend Micro
                                          2008-08-13 06:45 --------- d-----w C:\Program Files\GFi
                                          2008-08-12 07:46 --------- d-----w C:\Program Files\Fichiers communs\DirectX
                                          2008-08-11 23:23 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\wmp
                                          2008-08-11 22:03 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\Talkback
                                          2008-08-11 11:42 --------- d-----w C:\Program Files\Valve
                                          2008-08-11 11:27 --------- d-----w C:\Documents and Settings\Misterdy\Application Data\Azureus
                                          2008-08-11 10:50 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
                                          2008-08-05 15:55 265,720 ----a-w C:\WINDOWS\WINDOWS\system32\msdbg2.dll
                                          2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\WINDOWS\system32\cdm.dll
                                          2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\WINDOWS\system32\wuauclt.exe
                                          2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\WINDOWS\system32\wups2.dll
                                          2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\WINDOWS\system32\wups.dll
                                          2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\WINDOWS\system32\wuapi.dll
                                          2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\WINDOWS\system32\wucltui.dll
                                          2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\WINDOWS\system32\wuweb.dll
                                          2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\WINDOWS\system32\wuaueng.dll
                                          2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\WINDOWS\system32\mucltui.dll
                                          2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\WINDOWS\system32\muweb.dll
                                          2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WINDOWS\WLXPGSS.SCR
                                          2008-07-15 10:29 66,872 ----a-w C:\WINDOWS\WINDOWS\system32\PnkBstrA.exe
                                          2008-07-09 13:00 98,304 ----a-w C:\WINDOWS\WINDOWS\system32\CmdLineExt.dll
                                          .

                                          ((((((((((((((((((((((((((((( snapshot@2008-10-08_21.38.56.81 )))))))))))))))))))))))))))))))))))))))))
                                          .
                                          - 2008-09-27 11:04:48 247,904 ----a-w C:\WINDOWS\WINDOWS\system32\FNTCACHE.DAT
                                          + 2008-10-09 17:39:22 251,088 ----a-w C:\WINDOWS\WINDOWS\system32\FNTCACHE.DAT
                                          .
                                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                          .
                                          .
                                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                          REGEDIT4

                                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
                                          "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
                                          "ctfmon.exe"="C:\WINDOWS\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
                                          "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-07-09 9216]
                                          "Center Agent"="C:\Program Files\KWorld Multimedia\HyperMediaCenter\DTVR\Scheduled.exe" [2007-07-13 1435648]

                                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          "UserFaultCheck"="C:\WINDOWS\WINDOWS\system32\dumprep 0 -u" [X]
                                          "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
                                          "JMB36X IDE Setup"="C:\WINDOWS\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 36864]
                                          "36X Raid Configurer"="C:\WINDOWS\WINDOWS\system32\JMRaidSetup.exe" [2006-11-16 1953792]
                                          "Ai Gear Help"="C:\Program Files\ASUS\AI Gear\GearHelp.exe" [2006-07-27 415744]
                                          "Launch Ai Booster"="C:\Program Files\ASUS\AI Booster\OverClk.exe" [2006-11-28 3714048]
                                          "AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.15\AsRunHelp.exe" [2006-11-14 363008]
                                          "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
                                          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                                          "NvCplDaemon"="C:\WINDOWS\WINDOWS\system32\NvCpl.dll" [2008-03-24 13524992]
                                          "NvMediaCenter"="C:\WINDOWS\WINDOWS\system32\NvMcTray.dll" [2008-03-24 86016]
                                          "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                                          "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
                                          "nwiz"="nwiz.exe" [2008-03-24 C:\WINDOWS\WINDOWS\system32\nwiz.exe]

                                          C:\Documents and Settings\Misterdy\Menu D‚marrer\Programmes\D‚marrage\
                                          RocketDock.lnk - C:\WINDOWS\WINDOWS\BricoPacks\Crystal Clear\RocketDock\RocketDock.exe [2006-05-14 344064]

                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
                                          2008-03-18 16:58 58672 C:\WINDOWS\WINDOWS\system32\avldr.dll

                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                          "VIDC.SP54"= SP5X_32.DLL
                                          "vidc.jpeg"= m3jpeg32.dll

                                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
                                          @="Service"

                                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                          "EnableFirewall"= 0 (0x0)

                                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                          "%windir%\\system32\\sessmgr.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                                          "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
                                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                          "C:\\WINDOWS\\WINDOWS\\system32\\dpvsetup.exe"=
                                          "C:\\WINDOWS\\WINDOWS\\system32\\PnkBstrA.exe"=
                                          "C:\\WINDOWS\\WINDOWS\\system32\\PnkBstrB.exe"=
                                          "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
                                          "C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
                                          "C:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
                                          "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
                                          "C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
                                          "C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
                                          "C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
                                          "C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
                                          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                                          "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

                                          R0 ivicd;Ivi CDVD Filter Driver;C:\WINDOWS\WINDOWS\system32\drivers\ivicd.sys [2005-01-12 38784]
                                          R0 pavboot;Panda boot driver;C:\WINDOWS\WINDOWS\system32\Drivers\pavboot.sys [2008-06-19 28544]
                                          R1 APPFLT;App Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\APPFLT.SYS [2008-06-25 73728]
                                          R1 DSAFLT;DSA Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\DSAFLT.SYS [2008-06-18 52992]
                                          R1 FNETMON;NetMon Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\fnetmon.SYS [2008-03-28 22072]
                                          R1 IDSFLT;Ids Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\IDSFLT.SYS [2008-06-18 193792]
                                          R1 NETFLTDI;Panda Net Driver [TDI Layer];C:\WINDOWS\WINDOWS\system32\Drivers\NETFLTDI.SYS [2008-07-11 14:58 158848]
                                          R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\WINDOWS\system32\DRIVERS\ShlDrv51.sys [2008-03-04 41144]
                                          R1 WNMFLT;Wifi Monitor Filter Plugin;C:\WINDOWS\WINDOWS\system32\Drivers\WNMFLT.SYS [2008-06-18 46720]
                                          R2 Gwmsrv;Panda Goodware Cache Manager;C:\WINDOWS\WINDOWS\system32\svchost -k Panda [ ]
                                          R2 PavProc;Panda Process Protection Driver;C:\WINDOWS\WINDOWS\system32\DRIVERS\PavProc.sys [2008-02-07 179640]
                                          R2 PskSvcRetail;Panda PSK service;C:\Program Files\Panda Security\Panda Internet Security 2009\PskSvc.exe [2008-06-25 28928]
                                          R3 3xHybrid;3xHybrid service;C:\WINDOWS\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
                                          R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\WINDOWS\system32\drivers\av5flt.sys [ ]
                                          R3 NetiMFLT01060034;PANDA NDIS IM Filter Miniport v1.6.0.34;C:\WINDOWS\WINDOWS\system32\DRIVERS\neti1634.sys [2008-06-26 197888]
                                          R3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\WINDOWS\system32\PavSRK.sys [ ]
                                          R3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\WINDOWS\system32\PavTPK.sys [ ]
                                          S3 VNUSB;VN Series Device;C:\WINDOWS\WINDOWS\system32\DRIVERS\VNUSB.sys [ ]

                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                          panda REG_MULTI_SZ Gwmsrv
                                          .
                                          Contenu du dossier 'Tâches planifiées'

                                          2008-10-07 C:\WINDOWS\WINDOWS\Tasks\AppleSoftwareUpdate.job
                                          - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

                                          2008-10-09 C:\WINDOWS\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
                                          - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
                                          .

                                          **************************************************************************

                                          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                          Rootkit scan 2008-10-09 20:41:36
                                          Windows 5.1.2600 Service Pack 2 NTFS

                                          Recherche de processus cachés ...

                                          Recherche d'éléments en démarrage automatique cachés ...

                                          Recherche de fichiers cachés ...

                                          Scan terminé avec succès
                                          Fichiers cachés: 0

                                          **************************************************************************
                                          .
                                          Heure de fin: 2008-10-09 20:43:48
                                          ComboFix-quarantined-files.txt 2008-10-09 18:43:36
                                          ComboFix2.txt 2008-10-09 18:32:45
                                          ComboFix3.txt 2008-10-08 19:47:29
                                          ComboFix4.txt 2008-10-08 19:40:00

                                          Avant-CF: 9 996 582 912 octets libres
                                          Après-CF: 9,983,356,928 octets libres

                                          330 --- E O F --- 2008-09-20 17:26:54
                                          0
                                          • 1
                                          • 2