

crissou
Membres-
Compteur de contenus
43 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par crissou
-
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
ça y est j'ai envoyé le fichier 2pack.exe avec bleeping, mais en tapant le chemin car je ne le trouvais pas sous c:\windows. J'attends tes instructions. Merci -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Cherche le service suivant:ChanService Double clique dessus: -dans le champs"Status du service" sélectionne "arrêté" -dans le champs"Type de démarrage" sélectionne"désactivé" puis "Appliquer" puis"ok" impossible c'est en grisé. rapport winfind : WinPFind3 logfile created on: 28/07/2007 10:39:45 WinPFind3U by OldTimer - Version 1.0.39 Folder = C:\Documents and Settings\romestan\Bureau\WinPFind3u\ Microsoft Windows XP Service Pack 1 (Version = 5.1.2600) Internet Explorer (Version = 6.0.2800.1106) 247,48 Mb Total Physical Memory | 82,90 Mb Available Physical Memory | 33,50% Memory free 521,67 Mb Paging File | 72,04 Mb Available in Paging File | 13,81% Paging File free Paging file location(s): C:\pagefile.sys 144 288; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 35,25 Gb Total Space | 30,96 Gb Free Space | 87,81% Space Free D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded Computer Name: SN200412170005 Current User Name: romestan Logged in as Administrator. Current Boot Mode: Normal [Processes - Non-Microsoft Only] 2pack.exe -> %SystemRoot%\2pack.exe -> [Ver = | Size = 585728 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = RHS] 2pack.exe -> %SystemRoot%\2pack.exe -> [Ver = | Size = 585728 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = RHS] bdagent.exe -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ] bdmcon.exe -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ] devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Modified Date = 23/08/2001 17:47:34 | Attr = ] e_famt9ee.exe -> %System32%\spool\drivers\w32x86\3\E_FAMT9EE.EXE -> SEIKO EPSON CORPORATION [Ver = 3.07 | Size = 110592 bytes | Modified Date = 03/03/2004 05:07:00 | Attr = ] slserv.exe -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ] winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.38.0 | Size = 322048 bytes | Modified Date = 23/06/2007 15:15:54 | Attr = ] xcommsvr.exe -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ] [Win32 Services - Non-Microsoft Only] (bdss) BitDefender Scan Server [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Softwin\BitDefender Scan Server\bdss.exe -> [Ver = | Size = 81920 bytes | Modified Date = 19/01/2007 16:12:56 | Attr = ] (ChanSirv) ChanService [Win32_Own | Auto | Running] -> %SystemRoot%\2pack.exe -> [Ver = | Size = 585728 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = RHS] (dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.0.503.0 | Size = 205312 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ] (LIVESRV) BitDefender Desktop Update Service [Win32_Own | Auto | Stopped] -> %CommonProgramFiles%\Softwin\BitDefender Update Service\livesrv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 18 | Size = 237568 bytes | Modified Date = 14/07/2007 21:33:04 | Attr = ] (Seagate Communication) Seagate Communication [Win32_Own | Disabled | Stopped] -> %System32%\dllcache\seagatecom.exe -> File not found (SLService) SmartLinkService [Win32_Own | Auto | Running] -> %System32%\slserv.exe -> [Ver = 2.80.00(24Apr2000) | Size = 45056 bytes | Modified Date = 05/05/2002 09:29:34 | Attr = ] (VSSERV) BitDefender Virus Shield [Win32_Own | Auto | Stopped] -> %ProgramFiles%\Softwin\BitDefender10\vsserv.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 1, 147 | Size = 462848 bytes | Modified Date = 14/07/2007 21:32:52 | Attr = ] (XCOMM) BitDefender Communicator [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Softwin\BitDefender Communicator\xcommsvr.exe -> SOFTWIN S.R.L [Ver = 1, 8, 11, 0 | Size = 86016 bytes | Modified Date = 09/11/2006 13:33:04 | Attr = ] [Registry - Non-Microsoft Only] < Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> BDAgent -> %ProgramFiles%\Softwin\BitDefender10\bdagent.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 16 | Size = 69632 bytes | Modified Date = 26/03/2007 15:49:46 | Attr = ] BDMCon -> %ProgramFiles%\Softwin\BitDefender10\bdmcon.exe -> SOFTWIN S.R.L. [Ver = 10, 2, 0, 15 | Size = 290816 bytes | Modified Date = 14/07/2007 21:32:44 | Attr = ] < AppInit_DLLs [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs -> *AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls -> sockspy.dll -> %System32%\sockspy.dll -> [Ver = | Size = 73728 bytes | Modified Date = 26/01/2006 20:19:52 | Attr = ] < SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Modified Date = 13/12/2002 07:09:16 | Attr = ] < CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> < CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 36 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutoRun -> ÿÿÿÿ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> < HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 127.0.0.1 localhost -> -> < Internet Explorer Settings > -> -> HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome -> HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Local Page -> %SystemRoot%\system32\blank.htm -> HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Start Page -> about:blank -> HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKCU: Local Page -> C:\WINDOWS\System32\blank.htm -> HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKCU: Start Page -> http://www.google.fr/ -> HKCU: ProxyEnable -> 0 -> < BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %SystemDrive%\APPS\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 16/04/2001 16:39:02 | Attr = ] {53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ] < DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {9112AFD1-4BD4-4285-AFE7-48BFAE17DD2B} -> (Intel® PRO/100 VE Network Connection) -> {E54B0B60-E0CA-4847-99A6-8BF3DB3AF3F9} -> () -> {EA06B917-0C19-44AD-88F2-6A85EFDA9002} -> (Carte réseau 1394) -> < Default Protocols [HKLM] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults -> shell -> shell protocol not assigned -> < Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> ipp -> Reg Data - Key not found -> File not found msdaipp -> Reg Data - Key not found -> File not found < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab -> DirectAnimation Java Classes -> - CodeBase = file://C:\WINDOWS\Java\classes\dajava.cab -> Microsoft XML Parser for Java -> - CodeBase = file://C:\WINDOWS\Java\classes\xmldso.cab -> [Registry - Additional Scans - Non-Microsoft Only] < Security Settings > -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\FirewallDisableNotify -> 0 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> Rpcss; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Utilise la bande passante réseau inactive pour transférer des données. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINDOWS\system32\qmgr.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Internet Connection Sharing -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> Netman;NLA;RasMan;ALG; -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\\Epoch -> 11477 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\WINDOWS\2pack.exe -> C:\WINDOWS\2pack.exe:*:Enabled:Chan Services For Win32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\139:TCP -> 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\445:TCP -> 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\137:UDP -> 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\138:UDP -> 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\1900:UDP -> 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\\2869:TCP -> 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\\ServiceUpgrade -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Setup\InterfacesUnfirewalledAtUpdate\\All -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\ -> Root\LEGACY_SHAREDACCESS00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Enum\\NextInstance -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k netsvcs -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation de mises à jour Windows critiques. Si le service est désactivé, le système d'exploitation peut être mis à jour manuellement sur le site Web de Windows Update. -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINDOWS\System32\wuauserv.dll -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 -> < Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ -> {22524CA1-515C-4153-9807-52AE65F73B5F} -> BitDefender Antivirus Plus v10 -> {350C940c-3D7C-4EE8-BAA9-00BCB3D54227} -> WebFldrs XP -> {8855FF30-19CE-4CB1-A654-87B38369CCE1} -> Sonic RecordNow DX -> EPSON Printer and Utilities -> EPSON Logiciel imprimante -> EPSON Scanner -> EPSON Scan -> EVEREST Home Edition_is1 -> EVEREST Home Edition v2.20 -> Free.fr -> Free - Kit de connexion -> HijackThis -> HijackThis 1.99.1 -> KB833987 -> Correctif Windows XP - KB833987 -> KB835409 -> Mise à jour pour Windows XP (KB835409) -> KB835732 -> Correctif Windows XP - KB835732 -> KB840987 -> Correctif Windows XP - KB840987 -> KB842773 -> Correctif Windows XP - KB842773 -> KB873339 -> Correctif Windows XP - KB873339 -> KB885835 -> Correctif Windows XP - KB885835 -> KB885836 -> Correctif Windows XP - KB885836 -> KB888302 -> Correctif Windows XP - KB888302 -> KB890046 -> Mise à jour de sécurité pour Windows XP (KB890046) -> KB890859 -> Correctif Windows XP - KB890859 -> KB891781 -> Correctif Windows XP - KB891781 -> KB893756 -> Mise à jour de sécurité pour Windows XP (KB893756) -> KB893803v2 -> Windows Installer 3.1 (KB893803) -> KB896358 -> Mise à jour de sécurité pour Windows XP (KB896358) -> KB896423 -> Mise à jour de sécurité pour Windows XP (KB896423) -> KB896424 -> Mise à jour de sécurité pour Windows XP (KB896424) -> KB896428 -> Mise à jour de sécurité pour Windows XP (KB896428) -> KB898458 -> Mise à jour de sécurité pour Step by Step Interactive Training (KB898458) -> KB898461 -> Mise à jour pour Windows XP (KB898461) -> KB899587 -> Mise à jour de sécurité pour Windows XP (KB899587) -> KB899591 -> Mise à jour de sécurité pour Windows XP (KB899591) -> KB900725 -> Mise à jour de sécurité pour Windows XP (KB900725) -> KB901017 -> Mise à jour de sécurité pour Windows XP (KB901017) -> KB901214 -> Mise à jour de sécurité pour Windows XP (KB901214) -> KB902400 -> Mise à jour de sécurité pour Windows XP (KB902400) -> KB904706 -> Mise à jour de sécurité pour Windows XP (KB904706) -> KB905414 -> Mise à jour de sécurité pour Windows XP (KB905414) -> KB905495 -> Mise à jour de sécurité pour Windows XP (KB905495) -> KB905749 -> Mise à jour de sécurité pour Windows XP (KB905749) -> KB908519 -> Mise à jour de sécurité pour Windows XP (KB908519) -> KB908531 -> Mise à jour pour Windows XP (KB908531) -> KB910437 -> Mise à jour pour Windows XP (KB910437) -> KB911280 -> Mise à jour pour Windows XP (KB911280) -> KB911562 -> Mise à jour de sécurité pour Windows XP (KB911562) -> KB911564 -> Mise à jour de sécurité pour Lecteur Windows Media (KB911564) -> KB911567-OE6SP1-20060316.165634 -> Correctif Windows XP - KB911567 -> KB911927 -> Mise à jour de sécurité pour Windows XP (KB911927) -> KB912919 -> Mise à jour de sécurité pour Windows XP (KB912919) -> KB913580 -> Mise à jour de sécurité pour Windows XP (KB913580) -> KB914388 -> Mise à jour de sécurité pour Windows XP (KB914388) -> KB914389 -> Mise à jour de sécurité pour Windows XP (KB914389) -> KB914798 -> Mise à jour de sécurité pour Windows XP (KB914798) -> KB917344 -> Mise à jour de sécurité pour Windows XP (KB917344) -> KB917422 -> Mise à jour de sécurité pour Windows XP (KB917422) -> KB917734_WMP8 -> Mise à jour de sécurité pour Lecteur Windows Media 8 (KB917734) -> KB917953 -> Mise à jour de sécurité pour Windows XP (KB917953) -> KB918439-IE6SP1-20060530.145346 -> Correctif Windows XP - KB918439 -> KB918899-IE6SP1-20060725.123917 -> Correctif Windows XP - KB918899 -> KB919007 -> Mise à jour de sécurité pour Windows XP (KB919007) -> KB920670 -> Mise à jour de sécurité pour Windows XP (KB920670) -> KB920683 -> Mise à jour de sécurité pour Windows XP (KB920683) -> KB920685 -> Mise à jour de sécurité pour Windows XP (KB920685) -> KB921883 -> Mise à jour de sécurité pour Windows XP (KB921883) -> KB922616 -> Mise à jour de sécurité pour Windows XP (KB922616) -> KB922819 -> Mise à jour de sécurité pour Windows XP (KB922819) -> KB923191 -> Mise à jour de sécurité pour Windows XP (KB923191) -> KB923414 -> Mise à jour de sécurité pour Windows XP (KB923414) -> KB924191 -> Mise à jour de sécurité pour Windows XP (KB924191) -> KB924496 -> Mise à jour de sécurité pour Windows XP (KB924496) -> KB925486-IE6SP1-20060918.120000 -> Correctif Windows XP - KB925486 -> mIRC -> mIRC -> PROSet -> Intel® PRO Ethernet Adapter and Software -> Q327979 -> Correctif Windows XP (SP2) Q327979 -> q330512 -> Correctif Windows XP (SP2) q330512 -> Q330909 -> Correctif Windows XP (SP2) Q330909 -> Q331060 -> Package du correctif Windows XP [voir Q331060 pour plus de détails] -> Q331816 -> Correctif Windows XP (SP2) Q331816 -> Q810020 -> Correctif Windows XP (SP2) Q810020 -> Q815411 -> Correctif Windows XP (SP2) Q815411 -> ShockwaveFlash -> Adobe Flash Player 9 ActiveX -> SigmaTel C-Major -> SigmaTel C-Major Audio -> Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.4 -> T r o j a n R e m o v e r_is1 -> Trojan Remover 6.6.1 -> [Files/Folders - Created Within 30 days] 1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Created Date = 16/07/2007 21:54:49 | Attr = ] APPS -> %SystemDrive%\APPS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = ] Bases -> %SystemDrive%\Bases -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ] BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Created Date = 14/07/2007 18:22:08 | Attr = RHS] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Created Date = 14/07/2007 18:21:59 | Attr = RHS] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 27/07/2007 21:12:03 | Attr = ] DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Created Date = 14/07/2007 16:58:00 | Attr = H ] Downloads -> %SystemDrive%\Downloads -> [Folder | Created Date = 17/07/2007 14:35:10 | Attr = ] DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Created Date = 14/07/2007 16:57:48 | Attr = H ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Created Date = 02/01/1601 23:00:00 | Attr = HS] hijackthis -> %SystemDrive%\hijackthis -> [Folder | Created Date = 16/07/2007 16:20:33 | Attr = ] Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Created Date = 17/07/2007 14:33:51 | Attr = ] PNP -> %SystemDrive%\PNP -> [Folder | Created Date = 14/07/2007 16:58:46 | Attr = H ] QooBox -> %SystemDrive%\QooBox -> [Folder | Created Date = 27/07/2007 21:14:55 | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Created Date = 14/07/2007 18:26:49 | Attr = HS] Sohbet Chat.lnk -> %SystemDrive%\Sohbet Chat.lnk -> [Ver = | Size = 496 bytes | Created Date = 28/07/2007 09:11:41 | Attr = ] Sohbet-Script -> %SystemDrive%\Sohbet-Script -> [Folder | Created Date = 28/07/2007 09:11:32 | Attr = ] sohbet.exe -> %SystemDrive%\sohbet.exe -> [Ver = | Size = 1801415 bytes | Created Date = 28/07/2007 09:11:22 | Attr = ] UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Created Date = 14/07/2007 17:00:32 | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Created Date = 23/07/2007 15:14:30 | Attr = H ] $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Created Date = 24/07/2007 09:09:56 | Attr = H ] $NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Created Date = 16/07/2007 21:54:19 | Attr = H ] $NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Created Date = 23/07/2007 15:15:23 | Attr = H ] $NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Created Date = 16/07/2007 21:55:00 | Attr = H ] $NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Created Date = 16/07/2007 21:58:45 | Attr = H ] $NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Created Date = 24/07/2007 09:10:50 | Attr = H ] $NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Created Date = 27/07/2007 19:17:16 | Attr = H ] $NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Created Date = 24/07/2007 09:13:43 | Attr = H ] $NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Created Date = 27/07/2007 19:18:50 | Attr = H ] $NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Created Date = 27/07/2007 19:10:47 | Attr = H ] $NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Created Date = 27/07/2007 19:13:09 | Attr = H ] $NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Created Date = 27/07/2007 19:05:53 | Attr = H ] $NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Created Date = 27/07/2007 19:13:29 | Attr = H ] $NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Created Date = 27/07/2007 19:17:41 | Attr = H ] $NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Created Date = 24/07/2007 09:08:53 | Attr = H ] $NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Created Date = 24/07/2007 09:11:28 | Attr = H ] $NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Created Date = 24/07/2007 09:12:09 | Attr = H ] $NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Created Date = 27/07/2007 19:09:15 | Attr = H ] $NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Created Date = 24/07/2007 09:08:17 | Attr = H ] $NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Created Date = 23/07/2007 15:19:50 | Attr = H ] $NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Created Date = 24/07/2007 09:14:38 | Attr = H ] $NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Created Date = 24/07/2007 09:12:26 | Attr = H ] $NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Created Date = 23/07/2007 15:19:20 | Attr = H ] $NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Created Date = 27/07/2007 19:18:06 | Attr = H ] $NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Created Date = 27/07/2007 19:11:50 | Attr = H ] $NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Created Date = 27/07/2007 19:13:58 | Attr = H ] $NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Created Date = 23/07/2007 15:22:42 | Attr = H ] $NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Created Date = 23/07/2007 15:22:05 | Attr = H ] $NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Created Date = 27/07/2007 19:15:19 | Attr = H ] $NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Created Date = 27/07/2007 19:09:32 | Attr = H ] $NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Created Date = 27/07/2007 19:08:53 | Attr = H ] $NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Created Date = 23/07/2007 15:17:02 | Attr = H ] $NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Created Date = 27/07/2007 19:15:45 | Attr = H ] $NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Created Date = 24/07/2007 09:11:47 | Attr = H ] $NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Created Date = 27/07/2007 19:17:29 | Attr = H ] $NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Created Date = 23/07/2007 15:27:02 | Attr = H ] $NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Created Date = 27/07/2007 19:09:51 | Attr = H ] $NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Created Date = 24/07/2007 09:13:01 | Attr = H ] $NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Created Date = 27/07/2007 19:10:26 | Attr = H ] $NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Created Date = 23/07/2007 15:16:12 | Attr = H ] $NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Created Date = 27/07/2007 19:12:50 | Attr = H ] $NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Created Date = 27/07/2007 19:07:38 | Attr = H ] $NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Created Date = 27/07/2007 19:12:27 | Attr = H ] $NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Created Date = 27/07/2007 19:11:24 | Attr = H ] $NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Created Date = 23/07/2007 15:21:35 | Attr = H ] $NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Created Date = 27/07/2007 19:12:08 | Attr = H ] $NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Created Date = 27/07/2007 19:16:08 | Attr = H ] $NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Created Date = 23/07/2007 15:17:53 | Attr = H ] $NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Created Date = 23/07/2007 15:23:17 | Attr = H ] $NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Created Date = 23/07/2007 15:25:55 | Attr = H ] $NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Created Date = 23/07/2007 15:14:33 | Attr = H ] $NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Created Date = 27/07/2007 19:17:54 | Attr = H ] $NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Created Date = 27/07/2007 19:18:37 | Attr = H ] $NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Created Date = 24/07/2007 09:12:44 | Attr = H ] $NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Created Date = 24/07/2007 09:14:16 | Attr = H ] $NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Created Date = 23/07/2007 15:20:15 | Attr = H ] $NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Created Date = 24/07/2007 09:13:19 | Attr = H ] $NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Created Date = 27/07/2007 19:20:18 | Attr = H ] $NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Created Date = 27/07/2007 19:16:58 | Attr = H ] $NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Created Date = 24/07/2007 09:10:31 | Attr = H ] $NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Created Date = 14/07/2007 18:11:50 | Attr = H ] $NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Created Date = 14/07/2007 18:12:01 | Attr = H ] $NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Created Date = 14/07/2007 18:12:09 | Attr = H ] $NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Created Date = 14/07/2007 18:12:15 | Attr = H ] $NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Created Date = 14/07/2007 18:12:22 | Attr = H ] $NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Created Date = 14/07/2007 18:12:28 | Attr = H ] $NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Created Date = 14/07/2007 18:12:34 | Attr = H ] AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Created Date = 14/07/2007 18:23:10 | Attr = ] catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ] CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Created Date = 14/07/2007 22:12:46 | Attr = ] Drivers -> %SystemRoot%\Drivers -> [Folder | Created Date = 14/07/2007 18:15:46 | Attr = ] erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 27/07/2007 21:18:34 | Attr = ] jautoexp.dat -> %SystemRoot%\jautoexp.dat -> [Ver = | Size = 6550 bytes | Created Date = 23/07/2007 15:24:39 | Attr = ] Minidump -> %SystemRoot%\Minidump -> [Folder | Created Date = 26/07/2007 22:17:32 | Attr = ] Modio -> %SystemRoot%\Modio -> [Folder | Created Date = 14/07/2007 18:12:58 | Attr = ] NEC.BMP -> %SystemRoot%\NEC.BMP -> [Ver = | Size = 149262 bytes | Created Date = 14/07/2007 18:15:08 | Attr = ] nircmd.exe -> %SystemRoot%\nircmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 27/07/2007 21:12:19 | Attr = ] Profiles -> %SystemRoot%\Profiles -> [Folder | Created Date = 14/07/2007 18:23:11 | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Created Date = 24/07/2007 10:09:04 | Attr = ] RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Created Date = 14/07/2007 18:15:32 | Attr = ] REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Created Date = 14/07/2007 18:29:00 | Attr = ] RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Created Date = 14/07/2007 18:26:20 | Attr = ] sl.lng -> %SystemRoot%\sl.lng -> [Ver = | Size = 49354 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] SmCfg.exe -> %SystemRoot%\SmCfg.exe -> [Ver = 2, 80, 1, 0 | Size = 61440 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Created Date = 14/07/2007 18:26:48 | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:11:09 | Attr = ] unvise32qt.exe -> %SystemRoot%\unvise32qt.exe -> MindVision [Ver = 2.8.3 | Size = 86016 bytes | Created Date = 14/07/2007 18:24:04 | Attr = ] $ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Created Date = 14/07/2007 18:26:44 | Attr = ] amr_cpl.dll -> %System32%\amr_cpl.dll -> [Ver = 2, 81, 0, 0 | Size = 139264 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Created Date = 14/07/2007 19:20:20 | Attr = ] bits -> %System32%\bits -> [Folder | Created Date = 24/07/2007 09:10:54 | Attr = ] ctwdm32.dll -> %System32%\ctwdm32.dll -> Creative Technology Ltd. [Ver = 5.0.0.2001 | Size = 4096 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] devcon32.dll -> %System32%\devcon32.dll -> Creative Technology Ltd. [Ver = 4.06.651 | Size = 256512 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] devldr32.exe -> %System32%\devldr32.exe -> Creative Technology Ltd. [Ver = 1, 0, 0, 17 | Size = 24064 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Created Date = 14/07/2007 22:14:02 | Attr = ] EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ] EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Created Date = 14/07/2007 22:14:00 | Attr = ] EPSTP32U.DAT -> %System32%\EPSTP32U.DAT -> [Ver = | Size = 6390 bytes | Created Date = 14/07/2007 22:14:00 | Attr = R ] eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Created Date = 14/07/2007 22:14:03 | Attr = ] esccmd.dll -> %System32%\esccmd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 22528 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ] escimgd.dll -> %System32%\escimgd.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 46080 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ] escwiad.dll -> %System32%\escwiad.dll -> SEIKO EPSON CORP. [Ver = 1.05 | Size = 29696 bytes | Created Date = 14/07/2007 22:13:23 | Attr = ] E_DCINST.DLL -> %System32%\E_DCINST.DLL -> SEIKO EPSON CORP. [Ver = 1, 0, 0, 1 | Size = 31744 bytes | Created Date = 15/07/2007 08:55:22 | Attr = ] E_FBCB9EE.DLL -> %System32%\E_FBCB9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 2, 0, 0, 27 | Size = 64000 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ] E_FBCH9EE.DLL -> %System32%\E_FBCH9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 1, 1, 0, 0 | Size = 34304 bytes | Created Date = 15/07/2007 08:55:16 | Attr = ] E_FLM9EE.DLL -> %System32%\E_FLM9EE.DLL -> SEIKO EPSON CORPORATION [Ver = 5, 1, 0, 0 | Size = 79654 bytes | Created Date = 15/07/2007 08:55:15 | Attr = ] hccutils.dll -> %System32%\hccutils.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 114688 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] iAlmCoIn_0_v9.dll -> %System32%\iAlmCoIn_0_v9.dll -> Intel Corporation [Ver = 1.00.1000.1 | Size = 61440 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmdd5.dll -> %System32%\ialmdd5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 435266 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmdev5.dll -> %System32%\ialmdev5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 192507 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmdnt5.dll -> %System32%\ialmdnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 114236 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmgdev.dll -> %System32%\ialmgdev.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 188416 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmgicd.dll -> %System32%\ialmgicd.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 1859584 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmrem.dll -> %System32%\ialmrem.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 57344 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmrnt5.dll -> %System32%\ialmrnt5.dll -> Intel Corporation [Ver = 6.13.01.3413 | Size = 33792 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxcfg.exe -> %System32%\igfxcfg.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 483328 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxcpl.cpl -> %System32%\igfxcpl.cpl -> Intel Corporation [Ver = 3,0,0,1992 | Size = 94208 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdev.dll -> %System32%\igfxdev.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 147456 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdgps.dll -> %System32%\igfxdgps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 45056 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdiag.exe -> %System32%\igfxdiag.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxdo.dll -> %System32%\igfxdo.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxeud.dll -> %System32%\igfxeud.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 221184 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxexps.dll -> %System32%\igfxexps.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 32768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxext.exe -> %System32%\igfxext.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 86016 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhara.lhp -> %System32%\igfxhara.lhp -> [Ver = | Size = 55633 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxharb.lhp -> %System32%\igfxharb.lhp -> [Ver = | Size = 55654 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhchs.lhp -> %System32%\igfxhchs.lhp -> [Ver = | Size = 55426 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhcht.lhp -> %System32%\igfxhcht.lhp -> [Ver = | Size = 56139 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhcsy.lhp -> %System32%\igfxhcsy.lhp -> [Ver = | Size = 58343 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhdan.lhp -> %System32%\igfxhdan.lhp -> [Ver = | Size = 56933 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhdeu.lhp -> %System32%\igfxhdeu.lhp -> [Ver = | Size = 58017 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhell.lhp -> %System32%\igfxhell.lhp -> [Ver = | Size = 58791 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxheng.lhp -> %System32%\igfxheng.lhp -> [Ver = | Size = 55186 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhenu.lhp -> %System32%\igfxhenu.lhp -> [Ver = | Size = 55002 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhesp.lhp -> %System32%\igfxhesp.lhp -> [Ver = | Size = 56980 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhfin.lhp -> %System32%\igfxhfin.lhp -> [Ver = | Size = 57762 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhfra.lhp -> %System32%\igfxhfra.lhp -> [Ver = | Size = 56829 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhfrc.lhp -> %System32%\igfxhfrc.lhp -> [Ver = | Size = 56735 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhheb.lhp -> %System32%\igfxhheb.lhp -> [Ver = | Size = 61249 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhhun.lhp -> %System32%\igfxhhun.lhp -> [Ver = | Size = 59369 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhita.lhp -> %System32%\igfxhita.lhp -> [Ver = | Size = 56548 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhjpn.lhp -> %System32%\igfxhjpn.lhp -> [Ver = | Size = 57858 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhk.dll -> %System32%\igfxhk.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 118784 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhkor.lhp -> %System32%\igfxhkor.lhp -> [Ver = | Size = 63399 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhnld.lhp -> %System32%\igfxhnld.lhp -> [Ver = | Size = 57353 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhnor.lhp -> %System32%\igfxhnor.lhp -> [Ver = | Size = 56813 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhplk.lhp -> %System32%\igfxhplk.lhp -> [Ver = | Size = 58108 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhptb.lhp -> %System32%\igfxhptb.lhp -> [Ver = | Size = 56119 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhptg.lhp -> %System32%\igfxhptg.lhp -> [Ver = | Size = 56649 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhrus.lhp -> %System32%\igfxhrus.lhp -> [Ver = | Size = 58767 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhsve.lhp -> %System32%\igfxhsve.lhp -> [Ver = | Size = 56636 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhtha.lhp -> %System32%\igfxhtha.lhp -> [Ver = | Size = 59797 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxhtrk.lhp -> %System32%\igfxhtrk.lhp -> [Ver = | Size = 57768 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxpph.dll -> %System32%\igfxpph.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 204800 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrara.lrc -> %System32%\igfxrara.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrarb.lrc -> %System32%\igfxrarb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrchs.lrc -> %System32%\igfxrchs.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrcht.lrc -> %System32%\igfxrcht.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrcsy.lrc -> %System32%\igfxrcsy.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrdan.lrc -> %System32%\igfxrdan.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrdeu.lrc -> %System32%\igfxrdeu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] igfxrell.lrc -> %System32%\igfxrell.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 163840 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxreng.lrc -> %System32%\igfxreng.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrenu.lrc -> %System32%\igfxrenu.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxres.dll -> %System32%\igfxres.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:17:29 | Attr = ] igfxresp.lrc -> %System32%\igfxresp.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxress.dll -> %System32%\igfxress.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 503808 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrfin.lrc -> %System32%\igfxrfin.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrfra.lrc -> %System32%\igfxrfra.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrfrc.lrc -> %System32%\igfxrfrc.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrheb.lrc -> %System32%\igfxrheb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrhun.lrc -> %System32%\igfxrhun.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrita.lrc -> %System32%\igfxrita.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrjpn.lrc -> %System32%\igfxrjpn.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrkor.lrc -> %System32%\igfxrkor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 151552 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrnld.lrc -> %System32%\igfxrnld.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrnor.lrc -> %System32%\igfxrnor.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrplk.lrc -> %System32%\igfxrplk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrptb.lrc -> %System32%\igfxrptb.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrptg.lrc -> %System32%\igfxrptg.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 159744 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrrus.lrc -> %System32%\igfxrrus.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrsve.lrc -> %System32%\igfxrsve.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrtha.lrc -> %System32%\igfxrtha.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxrtrk.lrc -> %System32%\igfxrtrk.lrc -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxsrvc.dll -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1992 | Size = 315392 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] igfxtray.exe -> %System32%\igfxtray.exe -> Intel Corporation [Ver = 3,0,0,1992 | Size = 155648 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] javasup.vxd -> %System32%\javasup.vxd -> [Ver = | Size = 7315 bytes | Created Date = 23/07/2007 15:24:40 | Attr = ] minirec.exe -> %System32%\minirec.exe -> SmartLink [Ver = 1.0 (8.1.2001) | Size = 163840 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] mpeg2data.ax -> %System32%\mpeg2data.ax -> [Ver = | Size = 57856 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] msdvbnp.ax -> %System32%\msdvbnp.ax -> [Ver = | Size = 52224 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] ntio.sys -> %System32%\ntio.sys -> [Ver = | Size = 34000 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio404.sys -> %System32%\ntio404.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio411.sys -> %System32%\ntio411.sys -> [Ver = | Size = 35648 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio412.sys -> %System32%\ntio412.sys -> [Ver = | Size = 35424 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] ntio804.sys -> %System32%\ntio804.sys -> [Ver = | Size = 34560 bytes | Created Date = 16/07/2007 21:57:16 | Attr = ] PreInstall -> %System32%\PreInstall -> [Folder | Created Date = 23/07/2007 15:19:56 | Attr = ] psisdecd.dll -> %System32%\psisdecd.dll -> [Ver = | Size = 354816 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] psisrndr.ax -> %System32%\psisrndr.ax -> [Ver = | Size = 30208 bytes | Created Date = 14/07/2007 18:15:13 | Attr = ] QuickTime -> %System32%\QuickTime -> [Folder | Created Date = 14/07/2007 18:23:54 | Attr = ] ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Created Date = 14/07/2007 18:13:07 | Attr = ] sblfx.dll -> %System32%\sblfx.dll -> Creative Technology Ltd. [Ver = 5.12.01.3210 | Size = 495616 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] sfman32.dll -> %System32%\sfman32.dll -> Creative Technology Ltd. [Ver = 4.06.501 | Size = 51200 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] slcpappl.chm -> %System32%\slcpappl.chm -> [Ver = | Size = 136104 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] slcpappl.cpl -> %System32%\slcpappl.cpl -> SmartLink [Ver = 2, 92, 0, 2 | Size = 339968 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] SLLights.dll -> %System32%\SLLights.dll -> [Ver = 2, 0, 9, 9 | Size = 405504 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] slmh.cab -> %System32%\slmh.cab -> [Ver = | Size = 351388 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] slmh.exe -> %System32%\slmh.exe -> SmartLink [Ver = 2, 92, 0, 3 | Size = 372736 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Created Date = 17/07/2007 08:12:20 | Attr = ] spupdsvc.inf -> %System32%\spupdsvc.inf -> [Ver = | Size = 170 bytes | Created Date = 24/07/2007 09:12:03 | Attr = ] swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ] swsc.exe -> %System32%\swsc.exe -> SteelWerX [Ver = 2.0.0.0 | Size = 370688 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ] swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 27/07/2007 21:12:15 | Attr = ] unacev2.dll -> %System32%\unacev2.dll -> [Ver = | Size = 75264 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] UNRAR3.dll -> %System32%\UNRAR3.dll -> [Ver = | Size = 153088 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] vfind.exe -> %System32%\vfind.exe -> [Ver = | Size = 49152 bytes | Created Date = 27/07/2007 21:12:18 | Attr = ] zonedoff.reg -> %System32%\zonedoff.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:19 | Attr = ] zonedon.reg -> %System32%\zonedon.reg -> [Ver = | Size = 113 bytes | Created Date = 23/07/2007 15:24:20 | Attr = ] ztvunace26.dll -> %System32%\ztvunace26.dll -> [Ver = | Size = 77312 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] ztvunrar36.dll -> %System32%\ztvunrar36.dll -> [Ver = | Size = 162304 bytes | Created Date = 14/07/2007 18:48:35 | Attr = ] 2gmgsmt.sf2 -> %System32%\drivers\2gmgsmt.sf2 -> [Ver = | Size = 2104298 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] a302.sys -> %System32%\drivers\a302.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a303.sys -> %System32%\drivers\a303.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 27703 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a304.sys -> %System32%\drivers\a304.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 45111 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a305.sys -> %System32%\drivers\a305.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 11319 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a306.sys -> %System32%\drivers\a306.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 16439 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a307.sys -> %System32%\drivers\a307.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20535 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a308.sys -> %System32%\drivers\a308.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a309.sys -> %System32%\drivers\a309.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 25655 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a310.sys -> %System32%\drivers\a310.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 32823 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a311.sys -> %System32%\drivers\a311.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 31799 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a312.sys -> %System32%\drivers\a312.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 10807 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a313.sys -> %System32%\drivers\a313.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 35895 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] a314.sys -> %System32%\drivers\a314.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 17463 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ctlfacem.sys -> %System32%\drivers\ctlfacem.sys -> Creative Technology Ltd. [Ver = 5.12.01.2108 built by: WinDDK | Size = 6912 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] ctljystk.sys -> %System32%\drivers\ctljystk.sys -> Creative Technology Ltd. [Ver = 5.1.2501.0 built by: WinDDK | Size = 3712 bytes | Created Date = 14/07/2007 18:08:52 | Attr = ] emu10k1m.sys -> %System32%\drivers\emu10k1m.sys -> Creative Technology Ltd. [Ver = 5.12.01.3300 built by: WinDDK | Size = 283904 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] fbxusb.sys -> %System32%\drivers\fbxusb.sys -> FreeBox SA [Ver = 1.2.0.0 | Size = 18848 bytes | Created Date = 14/07/2007 19:31:27 | Attr = R ] ialmkchw.sys -> %System32%\drivers\ialmkchw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 78144 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmnt5.sys -> %System32%\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 87579 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] ialmsbw.sys -> %System32%\drivers\ialmsbw.sys -> Intel Corporation [Ver = 6.13.01.3413 | Size = 108480 bytes | Created Date = 14/07/2007 18:15:46 | Attr = ] KProcCheck.sys -> %System32%\drivers\KProcCheck.sys -> [Ver = | Size = 4096 bytes | Created Date = 26/07/2007 22:17:01 | Attr = ] sfmanm.sys -> %System32%\drivers\sfmanm.sys -> Creative Technology Ltd. [Ver = 4.10.3300 | Size = 36480 bytes | Created Date = 14/07/2007 18:08:48 | Attr = ] ssmdrv.sys -> %System32%\drivers\ssmdrv.sys -> Avira GmbH [Ver = 7.0.1.1 | Size = 28352 bytes | Created Date = 14/07/2007 18:50:45 | Attr = ] vch.sys -> %System32%\drivers\vch.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 20021 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] wa301a.sys -> %System32%\drivers\wa301a.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] wa301b.sys -> %System32%\drivers\wa301b.sys -> Intel Corporation [Ver = 4.13.01.3413 | Size = 30775 bytes | Created Date = 14/07/2007 18:15:47 | Attr = ] winddx.sys -> %System32%\drivers\winddx.sys -> Smart Link Ltd. [Ver = 2.80.02 | Size = 42328 bytes | Created Date = 14/07/2007 18:12:58 | Attr = ] [Files/Folders - Modified Within 30 days] 1d445837b1976b19ea6acbd2c817 -> %SystemDrive%\1d445837b1976b19ea6acbd2c817 -> [Folder | Modified Date = 16/07/2007 22:56:28 | Attr = ] APPS -> %SystemDrive%\APPS -> [Folder | Modified Date = 14/07/2007 19:24:22 | Attr = ] Bases -> %SystemDrive%\Bases -> [Folder | Modified Date = 17/07/2007 15:36:36 | Attr = ] BOOT.BAK -> %SystemDrive%\BOOT.BAK -> [Ver = | Size = 193 bytes | Modified Date = 14/07/2007 19:17:44 | Attr = RHS] BOOT.INI -> %SystemDrive%\BOOT.INI -> [Ver = | Size = 274 bytes | Modified Date = 14/07/2007 19:44:24 | Attr = RHS] cmdcons -> %SystemDrive%\cmdcons -> [Folder | Modified Date = 14/07/2007 19:22:10 | Attr = RHS] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 27/07/2007 22:29:28 | Attr = ] DIVTOOLS -> %SystemDrive%\DIVTOOLS -> [Folder | Modified Date = 14/07/2007 17:58:00 | Attr = H ] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 14/07/2007 19:43:22 | Attr = ] Downloads -> %SystemDrive%\Downloads -> [Folder | Modified Date = 26/07/2007 15:49:52 | Attr = ] DRIVERS -> %SystemDrive%\DRIVERS -> [Folder | Modified Date = 14/07/2007 19:44:30 | Attr = H ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 259575808 bytes | Modified Date = 28/07/2007 10:10:56 | Attr = HS] hijackthis -> %SystemDrive%\hijackthis -> [Folder | Modified Date = 16/07/2007 18:17:02 | Attr = ] Kaspersky -> %SystemDrive%\Kaspersky -> [Folder | Modified Date = 18/07/2007 09:48:56 | Attr = ] PNP -> %SystemDrive%\PNP -> [Folder | Modified Date = 14/07/2007 17:58:46 | Attr = H ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 27/07/2007 22:40:42 | Attr = R ] QooBox -> %SystemDrive%\QooBox -> [Folder | Modified Date = 27/07/2007 22:14:56 | Attr = ] RECYCLER -> %SystemDrive%\RECYCLER -> [Folder | Modified Date = 14/07/2007 20:12:42 | Attr = HS] Sohbet Chat.lnk -> %SystemDrive%\Sohbet Chat.lnk -> [Ver = | Size = 496 bytes | Modified Date = 28/07/2007 10:32:38 | Attr = ] Sohbet-Script -> %SystemDrive%\Sohbet-Script -> [Folder | Modified Date = 28/07/2007 10:36:10 | Attr = ] sohbet.exe -> %SystemDrive%\sohbet.exe -> [Ver = | Size = 1801415 bytes | Modified Date = 28/07/2007 10:32:32 | Attr = ] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 23/07/2007 22:02:54 | Attr = HS] UPDFLOP.TAG -> %SystemDrive%\UPDFLOP.TAG -> [Ver = | Size = 0 bytes | Modified Date = 14/07/2007 18:00:32 | Attr = ] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 27/07/2007 23:04:40 | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 27/07/2007 20:15:44 | Attr = H ] $MSI31Uninstall_KB893803v2$ -> %SystemRoot%\$MSI31Uninstall_KB893803v2$ -> [Folder | Modified Date = 24/07/2007 10:10:04 | Attr = H ] $NtUninstallKB833987$ -> %SystemRoot%\$NtUninstallKB833987$ -> [Folder | Modified Date = 16/07/2007 22:54:20 | Attr = H ] $NtUninstallKB835409$ -> %SystemRoot%\$NtUninstallKB835409$ -> [Folder | Modified Date = 23/07/2007 16:15:26 | Attr = H ] $NtUninstallKB835732$ -> %SystemRoot%\$NtUninstallKB835732$ -> [Folder | Modified Date = 27/07/2007 20:18:26 | Attr = H ] $NtUninstallKB840987$ -> %SystemRoot%\$NtUninstallKB840987$ -> [Folder | Modified Date = 16/07/2007 22:58:52 | Attr = H ] $NtUninstallKB842773$ -> %SystemRoot%\$NtUninstallKB842773$ -> [Folder | Modified Date = 24/07/2007 10:10:54 | Attr = H ] $NtUninstallKB873339$ -> %SystemRoot%\$NtUninstallKB873339$ -> [Folder | Modified Date = 27/07/2007 20:17:18 | Attr = H ] $NtUninstallKB885835$ -> %SystemRoot%\$NtUninstallKB885835$ -> [Folder | Modified Date = 24/07/2007 10:13:46 | Attr = H ] $NtUninstallKB885836$ -> %SystemRoot%\$NtUninstallKB885836$ -> [Folder | Modified Date = 27/07/2007 20:18:52 | Attr = H ] $NtUninstallKB888302$ -> %SystemRoot%\$NtUninstallKB888302$ -> [Folder | Modified Date = 27/07/2007 20:10:50 | Attr = H ] $NtUninstallKB890046$ -> %SystemRoot%\$NtUninstallKB890046$ -> [Folder | Modified Date = 27/07/2007 20:13:12 | Attr = H ] $NtUninstallKB890859$ -> %SystemRoot%\$NtUninstallKB890859$ -> [Folder | Modified Date = 27/07/2007 20:05:56 | Attr = H ] $NtUninstallKB891781$ -> %SystemRoot%\$NtUninstallKB891781$ -> [Folder | Modified Date = 27/07/2007 20:13:30 | Attr = H ] $NtUninstallKB893756$ -> %SystemRoot%\$NtUninstallKB893756$ -> [Folder | Modified Date = 27/07/2007 20:17:44 | Attr = H ] $NtUninstallKB896358$ -> %SystemRoot%\$NtUninstallKB896358$ -> [Folder | Modified Date = 24/07/2007 10:08:56 | Attr = H ] $NtUninstallKB896423$ -> %SystemRoot%\$NtUninstallKB896423$ -> [Folder | Modified Date = 24/07/2007 10:11:30 | Attr = H ] $NtUninstallKB896424$ -> %SystemRoot%\$NtUninstallKB896424$ -> [Folder | Modified Date = 24/07/2007 10:12:12 | Attr = H ] $NtUninstallKB896428$ -> %SystemRoot%\$NtUninstallKB896428$ -> [Folder | Modified Date = 27/07/2007 20:09:18 | Attr = H ] $NtUninstallKB898458$ -> %SystemRoot%\$NtUninstallKB898458$ -> [Folder | Modified Date = 24/07/2007 10:08:20 | Attr = H ] $NtUninstallKB898461$ -> %SystemRoot%\$NtUninstallKB898461$ -> [Folder | Modified Date = 23/07/2007 16:19:52 | Attr = H ] $NtUninstallKB899587$ -> %SystemRoot%\$NtUninstallKB899587$ -> [Folder | Modified Date = 24/07/2007 10:14:42 | Attr = H ] $NtUninstallKB899591$ -> %SystemRoot%\$NtUninstallKB899591$ -> [Folder | Modified Date = 24/07/2007 10:12:30 | Attr = H ] $NtUninstallKB900725$ -> %SystemRoot%\$NtUninstallKB900725$ -> [Folder | Modified Date = 23/07/2007 16:19:22 | Attr = H ] $NtUninstallKB901017$ -> %SystemRoot%\$NtUninstallKB901017$ -> [Folder | Modified Date = 27/07/2007 20:18:08 | Attr = H ] $NtUninstallKB901214$ -> %SystemRoot%\$NtUninstallKB901214$ -> [Folder | Modified Date = 27/07/2007 20:11:52 | Attr = H ] $NtUninstallKB902400$ -> %SystemRoot%\$NtUninstallKB902400$ -> [Folder | Modified Date = 27/07/2007 20:14:02 | Attr = H ] $NtUninstallKB904706$ -> %SystemRoot%\$NtUninstallKB904706$ -> [Folder | Modified Date = 23/07/2007 16:22:44 | Attr = H ] $NtUninstallKB905414$ -> %SystemRoot%\$NtUninstallKB905414$ -> [Folder | Modified Date = 23/07/2007 16:22:08 | Attr = H ] $NtUninstallKB905495$ -> %SystemRoot%\$NtUninstallKB905495$ -> [Folder | Modified Date = 27/07/2007 20:15:22 | Attr = H ] $NtUninstallKB905749$ -> %SystemRoot%\$NtUninstallKB905749$ -> [Folder | Modified Date = 27/07/2007 20:09:34 | Attr = H ] $NtUninstallKB908519$ -> %SystemRoot%\$NtUninstallKB908519$ -> [Folder | Modified Date = 27/07/2007 20:08:56 | Attr = H ] $NtUninstallKB908531$ -> %SystemRoot%\$NtUninstallKB908531$ -> [Folder | Modified Date = 23/07/2007 16:17:04 | Attr = H ] $NtUninstallKB910437$ -> %SystemRoot%\$NtUninstallKB910437$ -> [Folder | Modified Date = 27/07/2007 20:15:48 | Attr = H ] $NtUninstallKB911280$ -> %SystemRoot%\$NtUninstallKB911280$ -> [Folder | Modified Date = 24/07/2007 10:11:50 | Attr = H ] $NtUninstallKB911562$ -> %SystemRoot%\$NtUninstallKB911562$ -> [Folder | Modified Date = 27/07/2007 20:17:32 | Attr = H ] $NtUninstallKB911564$ -> %SystemRoot%\$NtUninstallKB911564$ -> [Folder | Modified Date = 23/07/2007 16:27:04 | Attr = H ] $NtUninstallKB911567-OE6SP1-20060316.165634$ -> %SystemRoot%\$NtUninstallKB911567-OE6SP1-20060316.165634$ -> [Folder | Modified Date = 27/07/2007 20:09:56 | Attr = H ] $NtUninstallKB911927$ -> %SystemRoot%\$NtUninstallKB911927$ -> [Folder | Modified Date = 24/07/2007 10:13:04 | Attr = H ] $NtUninstallKB912919$ -> %SystemRoot%\$NtUninstallKB912919$ -> [Folder | Modified Date = 27/07/2007 20:10:28 | Attr = H ] $NtUninstallKB913580$ -> %SystemRoot%\$NtUninstallKB913580$ -> [Folder | Modified Date = 23/07/2007 16:16:16 | Attr = H ] $NtUninstallKB914388$ -> %SystemRoot%\$NtUninstallKB914388$ -> [Folder | Modified Date = 27/07/2007 20:12:52 | Attr = H ] $NtUninstallKB914389$ -> %SystemRoot%\$NtUninstallKB914389$ -> [Folder | Modified Date = 27/07/2007 20:07:42 | Attr = H ] $NtUninstallKB917344$ -> %SystemRoot%\$NtUninstallKB917344$ -> [Folder | Modified Date = 27/07/2007 20:12:30 | Attr = H ] $NtUninstallKB917422$ -> %SystemRoot%\$NtUninstallKB917422$ -> [Folder | Modified Date = 27/07/2007 20:11:28 | Attr = H ] $NtUninstallKB917734_WMP8$ -> %SystemRoot%\$NtUninstallKB917734_WMP8$ -> [Folder | Modified Date = 23/07/2007 16:21:38 | Attr = H ] $NtUninstallKB917953$ -> %SystemRoot%\$NtUninstallKB917953$ -> [Folder | Modified Date = 27/07/2007 20:12:10 | Attr = H ] $NtUninstallKB918439-IE6SP1-20060530.145346$ -> %SystemRoot%\$NtUninstallKB918439-IE6SP1-20060530.145346$ -> [Folder | Modified Date = 27/07/2007 20:16:10 | Attr = H ] $NtUninstallKB918899-IE6SP1-20060725.123917$ -> %SystemRoot%\$NtUninstallKB918899-IE6SP1-20060725.123917$ -> [Folder | Modified Date = 23/07/2007 16:18:04 | Attr = H ] $NtUninstallKB919007$ -> %SystemRoot%\$NtUninstallKB919007$ -> [Folder | Modified Date = 23/07/2007 16:23:20 | Attr = H ] $NtUninstallKB920670$ -> %SystemRoot%\$NtUninstallKB920670$ -> [Folder | Modified Date = 23/07/2007 16:25:58 | Attr = H ] $NtUninstallKB920683$ -> %SystemRoot%\$NtUninstallKB920683$ -> [Folder | Modified Date = 23/07/2007 16:14:36 | Attr = H ] $NtUninstallKB920685$ -> %SystemRoot%\$NtUninstallKB920685$ -> [Folder | Modified Date = 27/07/2007 20:17:56 | Attr = H ] $NtUninstallKB921883$ -> %SystemRoot%\$NtUninstallKB921883$ -> [Folder | Modified Date = 27/07/2007 20:18:40 | Attr = H ] $NtUninstallKB922616$ -> %SystemRoot%\$NtUninstallKB922616$ -> [Folder | Modified Date = 24/07/2007 10:12:46 | Attr = H ] $NtUninstallKB922819$ -> %SystemRoot%\$NtUninstallKB922819$ -> [Folder | Modified Date = 24/07/2007 10:14:18 | Attr = H ] $NtUninstallKB923191$ -> %SystemRoot%\$NtUninstallKB923191$ -> [Folder | Modified Date = 23/07/2007 16:20:18 | Attr = H ] $NtUninstallKB923414$ -> %SystemRoot%\$NtUninstallKB923414$ -> [Folder | Modified Date = 24/07/2007 10:13:22 | Attr = H ] $NtUninstallKB924191$ -> %SystemRoot%\$NtUninstallKB924191$ -> [Folder | Modified Date = 27/07/2007 20:20:20 | Attr = H ] $NtUninstallKB924496$ -> %SystemRoot%\$NtUninstallKB924496$ -> [Folder | Modified Date = 27/07/2007 20:17:02 | Attr = H ] $NtUninstallKB925486-IE6SP1-20060918.120000$ -> %SystemRoot%\$NtUninstallKB925486-IE6SP1-20060918.120000$ -> [Folder | Modified Date = 24/07/2007 10:10:34 | Attr = H ] $NtUninstallQ327979$ -> %SystemRoot%\$NtUninstallQ327979$ -> [Folder | Modified Date = 14/07/2007 19:11:52 | Attr = H ] $NtUninstallq330512$ -> %SystemRoot%\$NtUninstallq330512$ -> [Folder | Modified Date = 14/07/2007 19:12:02 | Attr = H ] $NtUninstallQ330909$ -> %SystemRoot%\$NtUninstallQ330909$ -> [Folder | Modified Date = 14/07/2007 19:12:10 | Attr = H ] $NtUninstallQ331060$ -> %SystemRoot%\$NtUninstallQ331060$ -> [Folder | Modified Date = 14/07/2007 19:12:16 | Attr = H ] $NtUninstallQ331816$ -> %SystemRoot%\$NtUninstallQ331816$ -> [Folder | Modified Date = 14/07/2007 19:12:24 | Attr = H ] $NtUninstallQ810020$ -> %SystemRoot%\$NtUninstallQ810020$ -> [Folder | Modified Date = 14/07/2007 19:12:30 | Attr = H ] $NtUninstallQ815411$ -> %SystemRoot%\$NtUninstallQ815411$ -> [Folder | Modified Date = 14/07/2007 19:12:36 | Attr = H ] AcrobatSetupStatus.ini -> %SystemRoot%\AcrobatSetupStatus.ini -> [Ver = | Size = 72 bytes | Modified Date = 14/07/2007 19:23:18 | Attr = ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 28/07/2007 10:11:00 | Attr = S] catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 109056 bytes | Modified Date = 20/07/2007 00:47:24 | Attr = ] CDE CX6600FGD.ini -> %SystemRoot%\CDE CX6600FGD.ini -> [Ver = | Size = 25 bytes | Modified Date = 14/07/2007 23:12:48 | Attr = ] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 27/07/2007 20:19:04 | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 23/07/2007 16:25:26 | Attr = S] Drivers -> %SystemRoot%\Drivers -> [Folder | Modified Date = 14/07/2007 19:15:48 | Attr = ] erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 27/07/2007 22:18:36 | Attr = ] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 17/07/2007 09:12:30 | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1374 bytes | Modified Date = 27/07/2007 20:19:00 | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 27/07/2007 23:06:16 | Attr = H ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 14/07/2007 20:19:52 | Attr = HS] Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 27/07/2007 22:58:22 | Attr = ] Modio -> %SystemRoot%\Modio -> [Folder | Modified Date = 14/07/2007 19:13:00 | Attr = ] msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 27/07/2007 20:25:08 | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 26/07/2007 18:47:54 | Attr = ] Profiles -> %SystemRoot%\Profiles -> [Folder | Modified Date = 14/07/2007 19:23:12 | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 24/07/2007 11:09:06 | Attr = ] RegisteredPackages -> %SystemRoot%\RegisteredPackages -> [Folder | Modified Date = 14/07/2007 19:15:34 | Attr = ] Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 14/07/2007 19:42:14 | Attr = ] REGLOCS.OLD -> %SystemRoot%\REGLOCS.OLD -> [Ver = | Size = 8192 bytes | Modified Date = 14/07/2007 19:29:02 | Attr = ] RESTORE.INS -> %SystemRoot%\RESTORE.INS -> [Ver = | Size = 1501198 bytes | Modified Date = 14/07/2007 19:26:26 | Attr = ] security -> %SystemRoot%\security -> [Folder | Modified Date = 24/07/2007 10:17:26 | Attr = ] setupapi.log.0.old -> %SystemRoot%\setupapi.log.0.old -> [Ver = | Size = 1595275 bytes | Modified Date = 16/07/2007 22:55:14 | Attr = ] smscfg.ini -> %SystemRoot%\smscfg.ini -> [Ver = | Size = 61 bytes | Modified Date = 14/07/2007 19:26:50 | Attr = ] SoftwareDistribution -> %SystemRoot%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:30 | Attr = ] system -> %SystemRoot%\system -> [Folder | Modified Date = 14/07/2007 19:26:26 | Attr = ] system.ini -> %SystemRoot%\system.ini -> [Ver = | Size = 231 bytes | Modified Date = 14/07/2007 19:29:10 | Attr = ] system32 -> %System32% -> [Folder | Modified Date = 28/07/2007 10:12:00 | Attr = ] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 28/07/2007 10:26:30 | Attr = ] twain_32 -> %SystemRoot%\twain_32 -> [Folder | Modified Date = 14/07/2007 23:13:24 | Attr = ] Web -> %SystemRoot%\Web -> [Folder | Modified Date = 17/07/2007 14:41:56 | Attr = R ] win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 620 bytes | Modified Date = 27/07/2007 22:56:14 | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 23/07/2007 16:20:26 | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 26/07/2007 17:49:30 | Attr = H ] $ncsp$.inf -> %System32%\$ncsp$.inf -> [Ver = | Size = 333 bytes | Modified Date = 14/07/2007 19:26:46 | Attr = ] $winnt$.inf -> %System32%\$winnt$.inf -> [Ver = | Size = 497 bytes | Modified Date = 14/07/2007 19:43:10 | Attr = ] bdod.bin -> %System32%\bdod.bin -> [Ver = | Size = 81984 bytes | Modified Date = 28/07/2007 10:26:50 | Attr = ] bits -> %System32%\bits -> [Folder | Modified Date = 24/07/2007 10:10:56 | Attr = ] CatRoot -> %System32%\CatRoot -> [Folder | Modified Date = 27/07/2007 20:18:28 | Attr = ] CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 27/07/2007 23:07:36 | Attr = ] Com -> %System32%\Com -> [Folder | Modified Date = 27/07/2007 20:14:10 | Attr = ] config -> %System32%\config -> [Folder | Modified Date = 27/07/2007 22:18:42 | Attr = ] dllcache -> %System32%\dllcache -> [Folder | Modified Date = 27/07/2007 20:20:22 | Attr = RHS] drivers -> %System32%\drivers -> [Folder | Modified Date = 27/07/2007 22:38:34 | Attr = ] EPPRTDRV.CAB -> %System32%\EPPRTDRV.CAB -> [Ver = | Size = 288201 bytes | Modified Date = 14/07/2007 23:14:06 | Attr = ] EPSETUP.CAB -> %System32%\EPSETUP.CAB -> [Ver = | Size = 443573 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ] EPSTP32U.CAB -> %System32%\EPSTP32U.CAB -> [Ver = | Size = 591071 bytes | Modified Date = 14/07/2007 23:14:02 | Attr = ] eps_icon.avi -> %System32%\eps_icon.avi -> [Ver = | Size = 8284 bytes | Modified Date = 14/07/2007 23:14:04 | Attr = ] FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 90296 bytes | Modified Date = 24/07/2007 10:56:36 | Attr = ] Macromed -> %System32%\Macromed -> [Folder | Modified Date = 14/07/2007 19:24:36 | Attr = ] perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 39992 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ] perfc00C.dat -> %System32%\perfc00C.dat -> [Ver = | Size = 48616 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ] perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 311604 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ] perfh00C.dat -> %System32%\perfh00C.dat -> [Ver = | Size = 367658 bytes | Modified Date = 14/07/2007 19:43:42 | Attr = ] PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 775034 bytes | Modified Date = 14/07/2007 19:43:40 | Attr = ] PreInstall -> %System32%\PreInstall -> [Folder | Modified Date = 23/07/2007 16:19:58 | Attr = ] QuickTime -> %System32%\QuickTime -> [Folder | Modified Date = 14/07/2007 19:24:06 | Attr = ] ReinstallBackups -> %System32%\ReinstallBackups -> [Folder | Modified Date = 14/07/2007 19:13:08 | Attr = ] Restore -> %System32%\Restore -> [Folder | Modified Date = 23/07/2007 22:02:54 | Attr = ] SoftwareDistribution -> %System32%\SoftwareDistribution -> [Folder | Modified Date = 17/07/2007 09:12:22 | Attr = ] spupdsvc.inf -> %System32%\spupdsvc.inf -> [Ver = | Size = 170 bytes | Modified Date = 24/07/2007 10:12:04 | Attr = ] swreg.exe -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ] wmpscheme.xml -> %System32%\wmpscheme.xml -> [Ver = | Size = 25065 bytes | Modified Date = 14/07/2007 19:43:30 | Attr = ] wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1170 bytes | Modified Date = 26/07/2007 10:42:02 | Attr = ] etc -> %System32%\drivers\etc -> [Folder | Modified Date = 27/07/2007 22:20:40 | Attr = ] [File String Scan - Non-Microsoft Only] PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41131 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ] UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 22/07/2007 18:39:28 | Attr = ] winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 30/08/2002 13:00:00 | Attr = ] PTech , -> %System32%\drivers\mtlstrm.sys -> [Ver = 3.00.01 | Size = 1805544 bytes | Modified Date = 18/04/2002 09:58:02 | Attr = ] < End of report > Chose importante: nous avons besoin d'analyser un fichier suspect : le même qu'angélique ta demandé de faire analyser en ligne en fait! je le fait et je reposte Est ce que ton pc est en réseau ? non -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Une fois que tu as effectué le scan avec ComboFix, fais aussi stp un nouveau rapport DiagHelp car celui que tu as posté n'est pas complêt. Voila tout ce que j'ai. L'écran est rouge et qd je fais entrée cela reboote le pc, et je n'ai que ça dans le fichier catchme; D'autre part j'ai des messages ""erreur sérieuse" qui apparaissent, et mon pc met 2 heures pour afficher une page internet. Dixit ?? catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-27 22:56:28 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden files: 0 -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
salut, voici le log combofix : - 2007-07-27 22:13:19 - ComboFix 07-07-23.6 - Service Pack 1 NTFS ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\poof ((((((((((((((((((((((((( Files Created from 2007-06-27 to 2007-07-27 ))))))))))))))))))))))))))))))) 2007-07-27 22:12 51,200 --a------ C:\WINDOWS\nircmd.exe 2007-07-26 23:17 4,096 --a------ C:\WINDOWS\system32\drivers\KProcCheck.sys 2007-07-26 18:45 <REP> d-------- C:\Program Files\RegCleaner 2007-07-26 16:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy 2007-07-26 10:54 1,006,592 --a------ C:\WINDOWS\system32\esent.dll 2007-07-24 11:09 <REP> d-------- C:\WINDOWS\pss 2007-07-24 10:10 <REP> d-------- C:\WINDOWS\system32\bits 2007-07-23 22:42 <REP> d-------- C:\Program Files\a-squared Anti-Malware 2007-07-23 16:24 947,472 --a------ C:\WINDOWS\system32\msjava.dll 2007-07-23 16:24 63,248 --a------ C:\WINDOWS\system32\javaprxy.dll 2007-07-23 16:24 6,550 --a------ C:\WINDOWS\jautoexp.dat 2007-07-23 16:24 49,424 --a------ C:\WINDOWS\system32\clspack.exe 2007-07-23 16:24 46,352 --a------ C:\WINDOWS\setdebug.exe 2007-07-23 16:24 404,752 --a------ C:\WINDOWS\system32\javart.dll 2007-07-23 16:24 313,856 --a------ C:\WINDOWS\system32\dx3j.dll 2007-07-23 16:24 286,992 --a------ C:\WINDOWS\system32\vmhelper.dll 2007-07-23 16:24 21,264 --a------ C:\WINDOWS\system32\msjdbc10.dll 2007-07-23 16:24 187,152 --a------ C:\WINDOWS\system32\javacypt.dll 2007-07-23 16:24 172,304 --a------ C:\WINDOWS\system32\jview.exe 2007-07-23 16:24 171,792 --a------ C:\WINDOWS\system32\wjview.exe 2007-07-23 16:24 171,280 --a------ C:\WINDOWS\system32\jit.dll 2007-07-23 16:24 154,384 --a------ C:\WINDOWS\system32\msawt.dll 2007-07-23 16:24 15,120 --a------ C:\WINDOWS\system32\jdbgmgr.exe 2007-07-23 16:24 139,536 --a------ C:\WINDOWS\system32\javaee.dll 2007-07-23 16:24 113 --a------ C:\WINDOWS\system32\zonedon.reg 2007-07-23 16:24 113 --a------ C:\WINDOWS\system32\zonedoff.reg 2007-07-23 16:19 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-07-23 16:19 <REP> d-------- C:\WINDOWS\system32\PreInstall 2007-07-23 16:14 <REP> d--h----- C:\WINDOWS\$hf_mig$ 2007-07-19 13:46 95,232 --a------ C:\WINDOWS\system32\6to4svc.dll 2007-07-19 13:46 93,184 --a------ C:\WINDOWS\system32\cscdll.dll 2007-07-19 13:46 86,016 --a------ C:\WINDOWS\system32\netsh.exe 2007-07-19 13:46 70,656 --a------ C:\WINDOWS\system32\ws2_32.dll 2007-07-19 13:46 54,272 --a------ C:\WINDOWS\system32\ipv6mon.dll 2007-07-19 13:46 49,152 --a------ C:\WINDOWS\system32\ipv6.exe 2007-07-19 13:46 31,232 --a------ C:\WINDOWS\system32\inetmib1.dll 2007-07-19 13:46 285,184 --a------ C:\WINDOWS\system32\kerberos.dll 2007-07-19 13:46 13,312 --a------ C:\WINDOWS\system32\wship6.dll 2007-07-19 13:46 11,776 --a------ C:\WINDOWS\system32\drivers\tunmp.sys 2007-07-19 13:45 64,000 --a------ C:\WINDOWS\system32\webclnt.dll 2007-07-19 13:44 82,944 --a------ C:\WINDOWS\system32\fldrclnr.dll 2007-07-19 13:44 72,704 --a------ C:\WINDOWS\system32\hlink.dll 2007-07-19 13:44 704,512 --a------ C:\WINDOWS\system32\sxs.dll 2007-07-19 13:44 16,384 --a------ C:\WINDOWS\system32\linkinfo.dll 2007-07-19 13:44 154,624 --a------ C:\WINDOWS\system32\netman.dll 2007-07-18 10:53 99,328 --a------ C:\WINDOWS\system32\polstore.dll 2007-07-18 10:53 368,640 --a------ C:\WINDOWS\system32\ipsmsnap.dll 2007-07-18 10:53 346,624 --a------ C:\WINDOWS\system32\ipsecsnp.dll 2007-07-18 10:53 29,184 --a------ C:\WINDOWS\system32\winipsec.dll 2007-07-18 10:53 258,560 --a------ C:\WINDOWS\system32\oakley.dll 2007-07-18 10:53 25,600 --------- C:\WINDOWS\system32\verclsid.exe 2007-07-18 10:53 161,280 --a------ C:\WINDOWS\system32\ipsecsvc.dll 2007-07-18 10:52 83,456 --a------ C:\WINDOWS\system32\mtxoci.dll 2007-07-18 10:52 64,512 --a------ C:\WINDOWS\system32\mtxclu.dll 2007-07-18 10:52 53,248 --a------ C:\WINDOWS\system32\spoolsv.exe 2007-07-17 15:35 <REP> d-------- C:\Downloads 2007-07-17 15:35 <REP> d-------- C:\Bases 2007-07-17 15:33 <REP> d-------- C:\Kaspersky 2007-07-17 09:15 7,680 --------- C:\WINDOWS\system32\bitsprx2.dll 2007-07-17 09:15 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll 2007-07-17 09:15 331,776 --a------ C:\WINDOWS\system32\winhttp.dll 2007-07-17 09:15 17,408 --a------ C:\WINDOWS\system32\qmgrprxy.dll 2007-07-17 09:12 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution 2007-07-17 09:11 <REP> d-------- C:\WINDOWS\SoftwareDistribution 2007-07-17 09:10 549,720 --a------ C:\WINDOWS\system32\wuapi.dll 2007-07-17 09:10 33,624 --a------ C:\WINDOWS\system32\wups.dll 2007-07-17 09:10 325,976 --a------ C:\WINDOWS\system32\wucltui.dll 2007-07-17 09:10 203,096 --a------ C:\WINDOWS\system32\wuweb.dll 2007-07-17 09:10 187,160 --a------ C:\WINDOWS\system32\wuaueng1.dll 2007-07-17 09:10 170,776 --a------ C:\WINDOWS\system32\wuauclt1.exe 2007-07-16 22:57 92,608 --a------ C:\WINDOWS\system32\krnl386.exe 2007-07-16 22:57 35,648 --a------ C:\WINDOWS\system32\ntio411.sys 2007-07-16 22:57 35,424 --a------ C:\WINDOWS\system32\ntio412.sys 2007-07-16 22:57 34,560 --a------ C:\WINDOWS\system32\ntio804.sys 2007-07-16 22:57 34,560 --a------ C:\WINDOWS\system32\ntio404.sys 2007-07-16 22:57 34,000 --a------ C:\WINDOWS\system32\ntio.sys 2007-07-16 22:57 246,784 --a------ C:\WINDOWS\system32\wow32.dll 2007-07-16 22:57 23,040 --a------ C:\WINDOWS\system32\vdmdbg.dll 2007-07-16 22:57 13,312 --a------ C:\WINDOWS\system32\ntvdmd.dll 2007-07-16 22:54 593,408 --a------ C:\WINDOWS\system32\h323msp.dll 2007-07-16 22:54 552,448 --a------ C:\WINDOWS\system32\rtcdll.dll 2007-07-16 22:54 441,344 --a------ C:\WINDOWS\system32\ipnathlp.dll 2007-07-16 22:54 36,864 --a------ C:\WINDOWS\system32\mf3216.dll 2007-07-16 22:54 <REP> d-------- C:\1d445837b1976b19ea6acbd2c817 2007-07-16 17:23 <REP> d-------- C:\Program Files\Lavalys 2007-07-16 17:20 <REP> d-------- C:\hijackthis 2007-07-16 09:28 <REP> d---s---- C:\DOCUME~1\romestan\UserData 2007-07-15 09:55 79,654 --a------ C:\WINDOWS\system32\E_FLM9EE.DLL 2007-07-15 09:55 64,000 --a------ C:\WINDOWS\system32\E_FBCB9EE.DLL 2007-07-15 09:55 34,304 --a------ C:\WINDOWS\system32\E_FBCH9EE.DLL 2007-07-15 09:55 31,744 --a------ C:\WINDOWS\system32\E_DCINST.DLL 2007-07-15 09:54 28,160 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys 2007-07-15 09:54 24,960 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-07-15 09:54 14,208 --a------ C:\WINDOWS\system32\drivers\usbscan.sys 2007-07-14 23:14 6,390 -ra------ C:\WINDOWS\system32\EPSTP32U.DAT 2007-07-14 23:13 46,080 --a------ C:\WINDOWS\system32\escimgd.dll 2007-07-14 23:13 29,696 --a------ C:\WINDOWS\system32\escwiad.dll 2007-07-14 23:13 22,528 --a------ C:\WINDOWS\system32\esccmd.dll 2007-07-14 23:13 <REP> d-------- C:\Program Files\epson 2007-07-14 20:31 18,848 -ra------ C:\WINDOWS\system32\drivers\fbxusb.sys (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-23 14:39:21 -------- d-----w C:\Program Files\Messenger 2007-07-17 07:11:07 -------- d--h--w C:\Program Files\WindowsUpdate 2007-07-14 17:43:40 48,616 ----a-w C:\WINDOWS\system32\perfc00C.dat 2007-07-14 17:43:40 367,658 ----a-w C:\WINDOWS\system32\perfh00C.dat 2002-08-30 11:00:00 585,728 --sh--r C:\WINDOWS\2pack.exe ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35] "BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2007-07-14 21:32] "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=sockspy.dll ************************************************************************** catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-27 22:20:44 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden processes ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-27 22:26:21 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-07-27 22:25 --- E O F --- Est ce que tu as bien désinstallé antivir? je ne l'avais pas fait. C'est fait maintenant. Est ce que tu reçois encore des alertes concernant le fichier C:\1.vbs ? oui il est tjs infecté par trojan.dowloader.1 ou .AB ou autre Une fois que tu as effectué le scan avec ComboFix, fais aussi stp un nouveau rapport DiagHelp car celui que tu as posté n'est pas complêt. j'essaie de le refaire et je le poste. mais cela a fait rebooter le pc la dernière fois et puis plus rien ... -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Bonsoir désolée mais impossible de me connecter au net aujourd'hui. Est-ce ce rapport dont tu as besoin ?? Des que j'ai appuyé sur une touche, ça m'a rebooté l'ordi, cest-ce normal ?? DiagHelp version v1.1.2 - http://www.malekal.com excute le 26/07/2007 à 23:25:26,76 Liste des derniers fichies modifies/crees dans windir\system32 C:\WINDOWS\System32/drivers\avipbb.sys -->20/03/2007 09:55:45 C:\WINDOWS\System32/drivers\ssmdrv.sys -->01/03/2007 10:34:36 C:\WINDOWS\System32/drivers\avgntdd.sys -->27/02/2007 15:18:30 C:\WINDOWS\System32/drivers\avgntmgr.sys -->22/11/2006 14:30:31 C:\WINDOWS\System32/drivers\tcpip6.sys -->16/08/2006 11:28:57 C:\WINDOWS\System32/drivers\tunmp.sys -->16/08/2006 11:27:12 C:\WINDOWS\System32/drivers\srv.sys -->14/08/2006 10:59:20 C:\WINDOWS\System32\bdod.bin -->26/07/2007 23:23:53 C:\WINDOWS\System32\bdss.log -->26/07/2007 23:18:37 C:\WINDOWS\System32\wpa.dbl -->26/07/2007 10:42:00 C:\WINDOWS\System32\x -->24/07/2007 18:49:32 C:\WINDOWS\System32\FNTCACHE.DAT -->24/07/2007 10:56:34 C:\WINDOWS\System32\spupdsvc.inf -->24/07/2007 10:12:03 C:\WINDOWS\System32\o -->15/07/2007 22:53:47 C:\WINDOWS\System32\EPPRTDRV.CAB -->14/07/2007 23:14:05 C:\WINDOWS\System32\eps_icon.avi -->14/07/2007 23:14:03 C:\WINDOWS\System32\EPSETUP.CAB -->14/07/2007 23:14:03 C:\WINDOWS\System32\EPSTP32U.CAB -->14/07/2007 23:14:00 C:\WINDOWS\System32\perfh00C.dat -->14/07/2007 19:43:40 C:\WINDOWS\System32\perfh009.dat -->14/07/2007 19:43:40 C:\WINDOWS\System32\perfc00C.dat -->14/07/2007 19:43:40 C:\WINDOWS\System32\perfc009.dat -->14/07/2007 19:43:40 C:\WINDOWS\System32\PerfStringBackup.INI -->14/07/2007 19:43:39 C:\WINDOWS\System32\wmpscheme.xml -->14/07/2007 19:43:28 C:\WINDOWS\System32\$winnt$.inf -->14/07/2007 19:43:09 C:\WINDOWS\System32\$ncsp$.inf -->14/07/2007 19:26:44 C:\WINDOWS\System32\qtplugin.log -->14/07/2007 19:24:13 C:\WINDOWS\System32\wups.dll -->16/04/2007 22:47:36 C:\WINDOWS\System32\wuaucpl.cpl.mui -->16/04/2007 22:47:26 C:\WINDOWS\System32\wuapi.dll.mui -->16/04/2007 22:46:54 C:\WINDOWS\System32\wuaueng.dll -->16/04/2007 22:45:54 C:\WINDOWS\System32\wuapi.dll -->16/04/2007 22:45:48 C:\WINDOWS.log -->26/07/2007 23:18:55 C:\WINDOWS\WindowsUpdate.log -->26/07/2007 23:18:40 C:\WINDOWS\wiaservc.log -->26/07/2007 23:18:37 C:\WINDOWS\wiadebug.log -->26/07/2007 23:18:37 C:\WINDOWS\bootstat.dat -->26/07/2007 23:17:32 C:\WINDOWS\win.ini -->26/07/2007 22:55:53 C:\WINDOWS\ntbtlog.txt -->26/07/2007 22:39:00 C:\WINDOWS\KB873339.log -->26/07/2007 10:58:46 C:\WINDOWS\KB924191.log -->26/07/2007 10:58:37 C:\WINDOWS\KB885836.log -->26/07/2007 10:58:24 C:\WINDOWS\KB890046.log -->26/07/2007 10:58:20 C:\WINDOWS\KB917344.log -->26/07/2007 10:58:09 C:\WINDOWS\KB912919.log -->26/07/2007 10:57:53 C:\WINDOWS\KB920685.log -->26/07/2007 10:57:47 C:\WINDOWS\KB905495.log -->26/07/2007 10:57:35 Le volume dans le lecteur C s'appelle HDD Le numéro de série du volume est 6C2E-CFA4 Répertoire de C:\WINDOWS\system32 30/08/2002 13:00 4 096 csrss.exe 1 fichier(s) 4 096 octets 0 Rép(s) 33 394 917 376 octets libres Contenu de Downloaded Program Files Le volume dans le lecteur C s'appelle HDD Le numéro de série du volume est 6C2E-CFA4 Répertoire de C:\WINDOWS\Downloaded Program Files 23/07/2007 16:25 <REP> . 23/07/2007 16:25 <REP> .. 30/09/2002 13:03 65 desktop.ini 14/10/1997 18:52 697 DirectAnimation Java Classes.osd 20/01/2000 15:25 1 162 Microsoft XML Parser for Java.osd 11/06/2007 12:21 5 021 swflash.inf 4 fichier(s) 6 945 octets Total des fichiers listés : 4 fichier(s) 6 945 octets 2 Rép(s) 33 394 917 376 octets libres Recherche de rootkit! (Merci S!Ri) Recherche d'infections connues Export des clefs sensibles.. Liste des fichiers en exception sur le pare-feu XP SP2 Export de la clef SharedTaskScheduler [sharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" Rechercher adresses sensibles dans le fichier HOSTS... -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Merci pour ta réponse et désolée pour l'éparpillage, je me suis sentie larguée... voici le rapport, par contre, qd j'ai fait entrée, ça m'a rebooté le pc, et le rapport était ensuite sur le bureau ??? bizarre ? catchme 0.3.1066 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-26 23:26:21 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden files: 0 -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Bonjour à tous, voici donc le post envoyé il y a qq heures, si vous aviez la gentillesse d'envoyer qq mots pour me sortir du caca, ce serait super sympa : bonjour, aprés 2 procédure de prénettoyage d'un pc infecté (environ 6 virus détectés par bit defender), je me retrouve tjs avec un ficher 1.vbs impossible à éradiquer et infecté par Trojan.Downloader.VBS.1. Visiblement il appelle ses potes, donc c'est le serpent qui se mord la queue, et j'ai la vive impression que je suis pas sortie de l'auberge . Merci pour votre l'analyse : hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 22:57:49, on 26/07/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\WINDOWS\System32\devldr32.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Documents and Settings\romestan\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600" O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: ChanService (ChanSirv) - Unknown owner - C:\WINDOWS\2pack.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Pr le fameux fichier 1.vbs est sous c:\ et fait 1 ko. Impossible à éditer. Merci d'avance pour votre aide -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
bonjour, aprés 2 procédure de prénettoyage d'un pc infecté (environ 6 virus détectés par bit defender), je me retrouve tjs avec un ficher 1.vbs impossible à éradiquer. Je pense qu'il appelle ses potes, donc c'est le serpent qui se mord la queue. Merci pour votre l'analyse : hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 18:34:41, on 26/07/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\romestan\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600" O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: ChanService (ChanSirv) - Unknown owner - C:\WINDOWS\2pack.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) et escan de kapersky : File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\edition 1.txt infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\WINDOWS\system\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. le fameux fichier 1.vbs est sous c:\ et fait 1 ko. Impossible à éditer. Merci d'avance pour votre aide -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
hello y'a qq'un ?? mes rapports sont là. Et malgré ttes ces manip, j'ai un message d'infection toutes les 3 minutes de virus divers et variés, trojan... qq peut m'aider ? ou me donner la manip exacte pour faire un formatage bas niveau ??? merci en tous cas pour toutes vos interventions et à + -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
hello, voilà donc le rapport de escan : File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\1.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP1\A0000219.EXE tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP4\A0001372.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP6\A0016611.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP6\A0017635.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\WINDOWS\system\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\1.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP1\A0000219.EXE tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP4\A0001372.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP6\A0016611.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP6\A0017635.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\WINDOWS\system\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP4\A0001372.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP6\A0016611.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP6\A0017635.vbs infected by "Trojan-Downloader.VBS.Small.az" Virus. Action Taken: File Deleted. File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. File C:\WINDOWS\system\RESTORE.INS tagged as not-a-virus:NetTool.Win32.PsKill.a. No Action Taken. et le nouveau d'hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 19:42:46, on 18/07/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE C:\WINDOWS\System32\devldr32.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\romestan\Bureau\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600" O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: ChanService (ChanSirv) - Unknown owner - C:\WINDOWS\2pack.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) pour le fichier 1.VBS, qd je fais modifier le bloc note s'ouvre vide et un message dit "un périphérique ne fonctionne pas correctement" L'antivirus avait apparemment supprimé ce fichier, mais il est tjs là... qu'estce que je fais à présent ?? -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
bonjour Zonk; effectivement mon ordi gèle et plus rien à faire. si je veux répondre à vos posts, il faut que je redemarre par ce bouton, je n'en ai qu'un en façade avec le symbole O/I, et tout de suite lancer internet, sinon ça regèle...super pratique hein ?? Angélique je vais faire toutes tes manips mais vu ce que je viens de dire plus haut ça va prendre du temps... merci, je fais au plus vite... -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
[/b]et tu donnes le resultat stp!! File: 2pack.exe Status: POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.) MD5: 77655ec6d0e805ec0daeed79b8edb2dc Packers detected: ARMADILLO Bit9 reports: File not found Scanner results Scan taken on 16 Jul 2007 20:26:33 (GMT) A-Squared Found nothing AntiVir Found PCK/Armadillo ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing Panda Antivirus Found nothing Rising Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing ** tu donne le chemin excat stp et le nom. c'est bien c:\1.vbs taille 1 ko je suis obligée d'éteindre et de rallumer le pc au bouton M/A est-ce que çà ne va pas le flinguer ?? -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Merci pour ton analyse Angélique, voici la bonne version d'hijackthis : Logfile of HijackThis v1.99.1 Scan saved at 18:38:46, on 16/07/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE C:\WINDOWS\System32\devldr32.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\Documents and Settings\romestan\Local Settings\Temp\Répertoire temporaire 2 pour hijackthis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600" O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: ChanService (ChanSirv) - Unknown owner - C:\WINDOWS\2pack.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing) O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Merci Zonk, voici le rapport hijack this. J'ai également un message de mémoire virtuelle minimale insuffisante. Est-ce que c'est une conséquence des virus ?? Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 17:22:00, on 16/07/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Softwin\BitDefender10\bdmcon.exe C:\Program Files\Softwin\BitDefender10\bdagent.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE C:\WINDOWS\System32\devldr32.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe C:\Program Files\Softwin\BitDefender10\vsserv.exe C:\WINDOWS\System32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\hijackthis\HiJackThis_v2.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe" R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Apps\Adobe\Acrobat 5.1\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe" O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600" O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: ChanService (ChanSirv) - Unknown owner - C:\WINDOWS\2pack.exe O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe O23 - Service: DDE réseau (NetDDE) - Unknown owner - C:\WINDOWS\system32\netdde.exe O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - C:\WINDOWS\system32\netdde.exe O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Prise en charge des cartes à puces (SCardDrv) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 5592 bytes -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Merci Spyker, j'ai fait la desinfection, mais apparement il ne trouve rien. Alors là je ne comprends plus...pourtant tous les symptomes correspondaient bien -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
Bonjour et merci pour la réponse. Désolée je suis assez nulle en PC. Pas trouvé sur le site de NEC comment faire pour une mise à zéro. J'ai 2 CD de restauration fournis par NEC et une disquette rouge mais mon lecteur ne marche plus. Qu'est-ce que je dois faire ? Merci, j'ai fait la desinfection, mais apparement il ne trouve rien. Alors là je ne comprends plus...pourtant tous les symptomes correspondaient bien -
Infection par trojan et ver ?
crissou a répondu à un(e) sujet de crissou dans Analyses et éradication malwares
-
Bonjour, Tout a commencé par des blocages réguliers sur le bureau Windows, impossible de démarrer les programmes etc... Bit Defender a détecté 5 virus différents. J'ai repéré un fichier 1.VBS sous C: impossible à enlever. Après votre procédure de pré-nettoyage avec Antivir, démarrage en mode sans échec etc... rien de changé. J'ai donc formaté mon disque. Tout était super jusqu'à ma 1ère connexion internet (l'anvirus étant déjà réinstallé). Je me demande si ce n'est pas ma Freebox qui est verellée ?? Maintenant j'ai un ver (d'après mes recherches sur le net) qui me donne 1 min pour sauvegarder avant de fermer (arrêt initié par autorité Nt system...) et impossible de lancer mes programmes et même d'arrêter le PC, je suis obligée de le faire au bouton, pas bon. Avez-vous une solution ??? s'il vous plait je craque...Merci d'avance...