Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Depuis plusieurs semaines, j'essaie de me débarrasser du malware SmitFraud. :P

J'ai essayé divers méthodes (SmitFraudFix, Vundo, KillBot).

J'utilise régulièrement SpyBot, AVG (antivirus et antispyware) et ZoneAlarm (Firewall).

 

Je n'ai apparemment aucun dégât si ce n'est la détection récurrente de SmitFraud et quelques autres spywares.

 

Help ! :P

 

Ci-dessous le rapport HiJackThis sur mon PC :

 

Logfile of HijackThis v1.99.1

Scan saved at 13:22:53, on 08/05/2007

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

E:\PROGRA~1\AVGANT~1\avgamsvr.exe

E:\PROGRA~1\AVGANT~1\avgupsvc.exe

E:\PROGRA~1\AVGANT~1\avgemc.exe

C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\system32\ZoneLabs\vsmon.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\Explorer.EXE

E:\PROGRA~1\AVGANT~1\avgcc.exe

C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

E:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\iPod\bin\iPodService.exe

E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe

E:\program files\quicktime\qttask.exe

E:\Program Files\Spybot\TeaTimer.exe

E:\Program Files\OutClock\OutClock.exe

C:\Program Files\Mozilla Firefox\firefox.exe

E:\Program Files\Money\System\urlmap.exe

E:\Program Files\HiJackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: 0 - {152EA473-8787-4521-CD90-F50A046DCA04} - C:\Program Files\ACDSee32\lavugabi.dll (file missing)

O2 - BHO: (no name) - {16CB6EC6-FC89-48FA-B74A-10D35816F95E} - C:\Program Files\Fichiers communs\hokemo.dll (file missing)

O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINNT\system32\BhoECart.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\Spybot\SDHelper.dll

O2 - BHO: (no name) - {66AD0D21-37A8-4FAC-9B37-FE17E1F06D16} - C:\WINNT\system32\qomji.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

O2 - BHO: (no name) - {E1DAC82B-1C81-41B2-AC1B-6AE2653965E0} - C:\WINNT\system32\awtqnkh.dll (file missing)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - E:\Program Files\Money\System\mnyviewer.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\AVGANT~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [MoneyStartUp10.0] "E:\Program Files\Money\System\Activation.exe"

O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

O4 - HKLM\..\Run: [scan Detector] E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe

O4 - HKLM\..\Run: [spybotSnD] "E:\Program Files\Spybot\SpybotSD.exe" /autocheck /autofix /waitstart /waitmore

O4 - HKLM\..\Run: [spooler SubSystem App] C:\WINNT\system32\spooIsv.exe

O4 - HKLM\..\Run: [Windows Explorer] C:\WINNT\system32\explorer.exe

O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\system32\logon.exe

O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINNT\system32\algs.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\quicktime\qttask.exe" -atboottime

O4 - HKLM\..\RunOnce: [spybotSnD] "E:\Program Files\Spybot\SpybotSD.exe" /autocheck /autofix /waitstart /waitmore

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot\TeaTimer.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

O4 - Startup: OutClock (2).lnk = E:\Program Files\OutClock\OutClock.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - E:\Program Files\Money\System\mnyviewer.dll

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo\YPager.exe (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo\YPager.exe (file missing)

O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab

O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -

O16 - DPF: {CAFECAFE-0013-0001-0014-ABCDEFABCDEF} -

O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)

O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgemc.exe

O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

O23 - Service: Service de télécopie (Fax) - Unknown owner - C:\WINNT\system32\faxsvc.exe (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

 

Merci pour tous les conseils et l'aide que vous pourriez m'apporter.

Posté(e)

salut et bienvenue :P

 

Commence comme ceci stp >

 

Elimine la copie de VundoFix que tu possèdes et télécharge celle ci >

 

Télécharge VundoFix.exe (par Atribune) sur ton Bureau.

  • Double-clique VundoFix.exe afin de le lancer
  • Clique sur le bouton Scan for Vundo
  • Lorsque le scan est complété, clique sur le bouton Remove Vundo
  • Une invite te demandera si tu veux supprimer les fichiers, clique YES
  • Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
  • Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
  • Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse

Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

Posté(e)

Merci

Je viens d'appliquer la procédure et voici les deux rapports :

 

 

Rapport VundoFix :

 

 

VundoFix V6.3.21

 

Checking Java version...

 

Java version is 1.5.0.6

Old versions of java are exploitable and should be removed.

 

Scan started at 18:25:41 08/05/2007

 

Listing files found while scanning....

 

C:\WINNT\system32\awtqnkh.dll

C:\WINNT\system32\ywmjnbmd.dll

 

Beginning removal...

 

Performing Repairs to the registry.

Done!

 

 

 

 

Rapport HiJackThis :

 

Logfile of HijackThis v1.99.1

Scan saved at 18:44:00, on 08/05/2007

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

E:\PROGRA~1\AVGANT~1\avgamsvr.exe

E:\PROGRA~1\AVGANT~1\avgupsvc.exe

E:\PROGRA~1\AVGANT~1\avgemc.exe

C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\system32\ZoneLabs\vsmon.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\Explorer.EXE

E:\PROGRA~1\AVGANT~1\avgcc.exe

C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

E:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\iPod\bin\iPodService.exe

E:\Program Files\Spybot\TeaTimer.exe

C:\Program Files\Mozilla Firefox\firefox.exe

E:\Program Files\Money\System\urlmap.exe

E:\Program Files\HiJackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: 0 - {152EA473-8787-4521-CD90-F50A046DCA04} - C:\Program Files\ACDSee32\lavugabi.dll (file missing)

O2 - BHO: (no name) - {16CB6EC6-FC89-48FA-B74A-10D35816F95E} - C:\Program Files\Fichiers communs\hokemo.dll (file missing)

O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINNT\system32\BhoECart.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\Spybot\SDHelper.dll

O2 - BHO: (no name) - {66AD0D21-37A8-4FAC-9B37-FE17E1F06D16} - C:\WINNT\system32\qomji.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

O2 - BHO: (no name) - {C318CD44-E327-4377-A28E-6EC16A921AE8} - (no file)

O2 - BHO: (no name) - {E1DAC82B-1C81-41B2-AC1B-6AE2653965E0} - (no file)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - E:\Program Files\Money\System\mnyviewer.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\AVGANT~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [MoneyStartUp10.0] "E:\Program Files\Money\System\Activation.exe"

O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

O4 - HKLM\..\Run: [scan Detector] E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe

O4 - HKLM\..\Run: [spybotSnD] "E:\Program Files\Spybot\SpybotSD.exe" /autocheck /autofix /waitstart /waitmore

O4 - HKLM\..\Run: [spooler SubSystem App] C:\WINNT\system32\spooIsv.exe

O4 - HKLM\..\Run: [Windows Explorer] C:\WINNT\system32\explorer.exe

O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\system32\logon.exe

O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINNT\system32\algs.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\quicktime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot\TeaTimer.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

O4 - Startup: OutClock (2).lnk = E:\Program Files\OutClock\OutClock.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - E:\Program Files\Money\System\mnyviewer.dll

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo\YPager.exe (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo\YPager.exe (file missing)

O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab

O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -

O16 - DPF: {CAFECAFE-0013-0001-0014-ABCDEFABCDEF} -

O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)

O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll

O20 - Winlogon Notify: rpcc - C:\WINNT\

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgemc.exe

O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

O23 - Service: Service de télécopie (Fax) - Unknown owner - C:\WINNT\system32\faxsvc.exe (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

 

 

Est-ce que les nouvelles sont bonnes ?

Posté(e)

salut :P

 

En fait il y a une infection Vundo sur le pc mais aussi du SDBot entre autres!! ne t'nquiêtes pas, on va nettoyer ca :P

 

Au passage, j'ai l'impression que le Tea Timer de Spybot a interféré durant le nettoyage de VundoFix!! Aussi on va continuer comme ceci >

 

1) Trés important: Désactive le teatimer de Spybot en passant par les options de Spybot: il faut une fois le logiciel lancé, aller dans le menu"Mode" =>coche "Mode avancé" => "Outils"(en bas de page)=> "Résident" => et tu décoches cette case: "Résident Teatimer" . Tu ne doit plus voir l'icône du Teatimer dans la barre de tâches!

 

2) Démarre Hijackthis et clique sur la case "Do a system scan only",puis coche les lignes suivantes :

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)

 

O2 - BHO: 0 - {152EA473-8787-4521-CD90-F50A046DCA04} - C:\Program Files\ACDSee32\lavugabi.dll (file missing)

O2 - BHO: (no name) - {16CB6EC6-FC89-48FA-B74A-10D35816F95E} - C:\Program Files\Fichiers communs\hokemo.dll (file missing)

O2 - BHO: (no name) - {66AD0D21-37A8-4FAC-9B37-FE17E1F06D16} - C:\WINNT\system32\qomji.dll (file missing)

O2 - BHO: (no name) - {C318CD44-E327-4377-A28E-6EC16A921AE8} - (no file)

O2 - BHO: (no name) - {E1DAC82B-1C81-41B2-AC1B-6AE2653965E0} - (no file)

 

 

O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe

O4 - HKLM\..\Run: [spybotSnD] "E:\Program Files\Spybot\SpybotSD.exe" /autocheck /autofix /waitstart /waitmore *

O4 - HKLM\..\Run: [spooler SubSystem App] C:\WINNT\system32\spooIsv.exe

O4 - HKLM\..\Run: [Windows Explorer] C:\WINNT\system32\explorer.exe

O4 - HKLM\..\Run: [Windows Logon Application] C:\WINNT\system32\logon.exe

O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINNT\system32\algs.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot\TeaTimer.exe *

 

 

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -

O16 - DPF: {CAFECAFE-0013-0001-0014-ABCDEFABCDEF} -

 

O20 - Winlogon Notify: awtqnkh - awtqnkh.dll (file missing)

O20 - Winlogon Notify: rpcc - C:\WINNT\

-Ferme tous les programmes et clique sur "Fix Checked"

 

* Note: je te fais désactiver Spybot pour le moment car il empêche les modifications dans la base de registre et gêne la désinfection! On rétablira ca plus tard.

 

3) Relance stp VundoFix exactement comme tu l'as fait précédemment.

 

4) Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.

Déroule la liste des instructions ci-dessous :

  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

5) A présent lance cet utilitaire (qui nous permet de voir ce qu'il reste) >

 

Télécharge et lance DiagHelp comme montré dans ce tutoriel> http://www.malekal.com/DiagHelp/DiagHelp.php

Ne lance que l'option 1 et poste le rapport stp.Attention: n'oublie pas d'appuyer sur une touche lorsque cela te sera demandé à la fin du rapport Catchme.

 

Voilà ca fait en tout 4 rapports >

 

- le rapport VundoFix

- le rapport SDFix

- le rapport hijackthis

- le rapport DiagHelp

 

Courage! et suis bien les manips dans l'ordre :P

Posté(e)

J'ai fait dans l'ordre les opérations que tu m'as indiqué mais je n'ai pas pu aller au bout.

 

En mode sans échec, dans le répertoire SDFix, en cliquant sur RunThis.bat, voici le message qui s'est affiché :

 

---------------------------

C:\SDFix\RunThis.bat

---------------------------

Le fichier 'C:\SDFix\RunThis.bat' (ou un de ses composants) est introuvable. Vérifiez que le chemin et le nom de fichier sont corrects, et que toutes les bibliothèques requises sont disponibles.

---------------------------

OK

---------------------------

 

Je n'ai donc pas pu effectuer la moindre des opérations de la procédure et aucun rapport Report.txt n'a été généré.

 

La même chose s'est produite avec l'utilitaire DiagHelp, le même message s'est affiché :

 

---------------------------

C:\Documents and Settings\admin\Bureau\DiagHelp\go.cmd

---------------------------

Le fichier 'C:\Documents and Settings\admin\Bureau\DiagHelp\go.cmd' (ou un de ses composants) est introuvable. Vérifiez que le chemin et le nom de fichier sont corrects, et que toutes les bibliothèques requises sont disponibles.

---------------------------

OK

---------------------------

 

 

A tout hasard, voici les rapports VundoFix et HiJackThis

 

 

Rapport VundoFix (aucun fichier infecté)

 

 

VundoFix V6.3.21

 

Checking Java version...

 

Java version is 1.5.0.6

Old versions of java are exploitable and should be removed.

 

Scan started at 22:04:48 09/05/2007

 

Listing files found while scanning....

 

No infected files were found.

 

 

 

 

Rapport HiJackThis

 

Logfile of HijackThis v1.99.1

Scan saved at 22:30:27, on 09/05/2007

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

E:\PROGRA~1\AVGANT~1\avgamsvr.exe

E:\PROGRA~1\AVGANT~1\avgupsvc.exe

E:\PROGRA~1\AVGANT~1\avgemc.exe

C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\system32\ZoneLabs\vsmon.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\Explorer.EXE

E:\PROGRA~1\AVGANT~1\avgcc.exe

C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

E:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\Program Files\iPod\bin\iPodService.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe

E:\program files\quicktime\qttask.exe

E:\Program Files\OutClock\OutClock.exe

E:\Program Files\Money\System\urlmap.exe

E:\Program Files\HiJackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINNT\system32\BhoECart.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\Spybot\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - E:\Program Files\Money\System\mnyviewer.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\AVGANT~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [MoneyStartUp10.0] "E:\Program Files\Money\System\Activation.exe"

O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

O4 - HKLM\..\Run: [scan Detector] E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [QuickTime Task] "E:\program files\quicktime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

O4 - Startup: OutClock (2).lnk = E:\Program Files\OutClock\OutClock.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - E:\Program Files\Money\System\mnyviewer.dll

O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo\YPager.exe (file missing)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\PROGRA~1\Yahoo\YPager.exe (file missing)

O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab

O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab

O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgupsvc.exe

O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - E:\PROGRA~1\AVGANT~1\avgemc.exe

O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

O23 - Service: Service de télécopie (Fax) - Unknown owner - C:\WINNT\system32\faxsvc.exe (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

 

 

 

Y a-t-il une explication toute simple à ces problèmes ou est-ce mauvais signe ?

 

Merci

 

Beginning removal...

Posté(e)

salut cehor :P

 

Je vais me renseigner pour savoir d'où vient cette erreur! en attendant, peux tu stp poster un rapport fait avec cet utilitaire stp? >

 

Télécharge WinPFind3U.exe sur ton bureau.

  • Double clique sur le fichier téléchargé : un dossier nommé WinPFind3U va apparaitre sur ton bureau.
  • Ouvre le dossier et double clique sur le fichier WinPFind3U.exe pour lancer le programme.
  • Sous le groupe Files Created Within sélectionne 90 days
  • Sous le groupe Files Modified Within sélectionne 90 days
  • Sous le groupe String Search sélectionne Non-Microsoft
  • Sur le panneau de droite, sous Additional Scans coche les cases>
    File Associations
    Security Settings
    Uninstall List
  • A présent clique sur le bouton Run Scan (en haut à gauche)
  • Lorsque le scan est terminé,le bloc-notes s'ouvre et affiche le rapport.
  • Clique sur le menu "Format" et assure toi que la case "Retour automatique à la ligne" ne soit pas cochée.
  • Copie/Colle le contenu du rapport dans ta prochaine réponse.

Fais ce scan en ligne dès que tu peux >

 

Fais un scan en ligne avec Panda :

http://www.pandasoftware.fr/Activescan/Activescan.html .

Et poste le rapport qu'il t'affichera à la fin, pour cela, assure toi que IE est correctement configuré pour le scan en ligne comme indiqué ici : http://www.malekal.com/scan_Av_en_ligne.html#mozTocId898809 .

Si tu n'y arrives pas, le tuto est : http://www.malekal.com/scan_Av_en_ligne.html#mozTocId237368

 

Tu n'es pas obligé de donner ton email, tu peux utiliser une adresse jetable si tu le souhaites : http://www.jetable.org/fr/index

Posté(e)

Bonsoir

 

J'ai tout fait comme indiqué et voici les rapports WinPFind3U et ActiveScan.

 

Rapport WinPFind3U

__________________

 

WinPFind3 logfile created on: 10/05/2007 19:16:00

WinPFind3U by OldTimer - Version 1.0.36 Folder = C:\Documents and Settings\admin\Bureau\WinPFind3u\

Microsoft Windows 2000 Service Pack 4 (Version = 5.0.2195)

Internet Explorer (Version = 6.0.2800.1106)

 

254,23 Mb Total Physical Memory | 142,52 Mb Available Physical Memory | 56,06% Memory free

423,18 Mb Paging File | 182,61 Mb Available in Paging File | 43,15% Paging File free

Paging file location(s): C:\pagefile.sys 192 384;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files

Drive C: | 3,91 Gb Total Space | 1,30 Gb Free Space | 33,20% Space Free

D: Drive not present or media not loaded

Drive E: | 15,11 Gb Total Space | 9,15 Gb Free Space | 60,55% Space Free

F: Drive not present or media not loaded

 

Computer Name: DOC041

Current User Name: admin

Logged in as Administrator.

Current Boot Mode: Normal

 

 

[Processes - Non-Microsoft Only]

avgamsvr.exe -> E:\Program Files\AVG antivirus\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 22/04/2007 18:08:30 | Attr = ]

avgas.exe -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 07/10/2006 14:20:00 | Attr = ]

avgcc.exe -> E:\Program Files\AVG antivirus\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 416256 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

avgemc.exe -> E:\Program Files\AVG antivirus\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 351744 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

avgupsvc.exe -> E:\Program Files\AVG antivirus\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 01/12/2006 19:42:08 | Attr = ]

guard.exe -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 28/09/2006 16:13:20 | Attr = ]

ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 331776 bytes | Modified Date = 24/06/2005 16:16:26 | Attr = ]

ituneshelper.exe -> E:\Program Files\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 278528 bytes | Modified Date = 24/06/2005 16:16:42 | Attr = ]

jusched.exe -> %ProgramFiles%\Java\jre1.5.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Modified Date = 10/11/2005 14:03:52 | Attr = ]

lvcoms.exe -> %CommonProgramFiles%\Logitech\QCDriver\LVComS.exe -> Logitech Inc. [Ver = 6.0.0.1208 | Size = 98304 bytes | Modified Date = 24/09/2001 10:39:28 | Attr = ]

outclock.exe -> E:\Program Files\OutClock\OutClock.exe -> Alain TAUBER [Ver = 3.8.9.200 | Size = 2137600 bytes | Modified Date = 03/01/2007 04:09:00 | Attr = ]

pmxdetect.exe -> E:\Program Files\Primax\PowerTWAIN\Pmxdetect.exe -> PRIMAX International BV [Ver = 1.2.1USB | Size = 35328 bytes | Modified Date = 03/11/1998 21:20:10 | Attr = ]

qttask.exe -> E:\program files\quicktime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.3 | Size = 282624 bytes | Modified Date = 01/09/2006 15:57:48 | Attr = ]

realplay.exe -> %ProgramFiles%\Real\RealOne Player\realplay.exe -> RealNetworks, Inc. [Ver = 6.0.12.1348 | Size = 208941 bytes | Modified Date = 13/11/2005 13:26:10 | Attr = ]

realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3427 | Size = 180269 bytes | Modified Date = 13/11/2005 13:25:46 | Attr = ]

sagent2.exe -> %CommonProgramFiles%\EPSON\EBAPI\SAgent2.exe -> SEIKO EPSON CORPORATION [Ver = 1, 2, 0, 0 | Size = 114688 bytes | Modified Date = 17/11/2000 02:02:00 | Attr = ]

vsmon.exe -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 1693464 bytes | Modified Date = 16/03/2006 11:33:12 | Attr = ]

winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.36.0 | Size = 319488 bytes | Modified Date = 08/05/2007 19:48:10 | Attr = ]

zlclient.exe -> E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 755480 bytes | Modified Date = 16/03/2006 11:34:00 | Attr = ]

 

[Win32 Services - Non-Microsoft Only]

(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 28/09/2006 16:13:20 | Attr = ]

(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> E:\Program Files\AVG antivirus\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 22/04/2007 18:08:30 | Attr = ]

(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> E:\Program Files\AVG antivirus\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 01/12/2006 19:42:08 | Attr = ]

(AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> E:\Program Files\AVG antivirus\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 351744 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

(dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> VERITAS Software Corp. [Ver = 2195.6624.297.3 | Size = 147728 bytes | Modified Date = 19/06/2003 12:05:04 | Attr = ]

(EPSONStatusAgent2) EPSON Printer Status Agent2 [Win32_Own | Auto | Running] -> %CommonProgramFiles%\EPSON\EBAPI\SAgent2.exe -> SEIKO EPSON CORPORATION [Ver = 1, 2, 0, 0 | Size = 114688 bytes | Modified Date = 17/11/2000 02:02:00 | Attr = ]

(Fax) Service de télécopie [Win32_Own | On_Demand | Stopped] -> %System32%\faxsvc.exe -> File not found

(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 05/04/2007 22:22:42 | Attr = ]

(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 04/04/2005 01:41:10 | Attr = ]

(iPodService) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 331776 bytes | Modified Date = 24/06/2005 16:16:26 | Attr = ]

(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 1693464 bytes | Modified Date = 16/03/2006 11:33:12 | Attr = ]

 

[Registry - Non-Microsoft Only]

< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

!AVG Anti-Spyware -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 07/10/2006 14:20:00 | Attr = ]

AVG7_CC -> E:\Program Files\AVG antivirus\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 416256 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

iTunesHelper -> E:\Program Files\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 278528 bytes | Modified Date = 24/06/2005 16:16:42 | Attr = ]

LVCOMS -> %CommonProgramFiles%\Logitech\QCDriver\LVComS.exe -> Logitech Inc. [Ver = 6.0.0.1208 | Size = 98304 bytes | Modified Date = 24/09/2001 10:39:28 | Attr = ]

QuickTime Task -> E:\program files\quicktime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.3 | Size = 282624 bytes | Modified Date = 01/09/2006 15:57:48 | Attr = ]

Scan Detector -> E:\Program Files\Primax\PowerTWAIN\Pmxdetect.exe -> PRIMAX International BV [Ver = 1.2.1USB | Size = 35328 bytes | Modified Date = 03/11/1998 21:20:10 | Attr = ]

SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.5.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Modified Date = 10/11/2005 14:03:52 | Attr = ]

TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3427 | Size = 180269 bytes | Modified Date = 13/11/2005 13:25:46 | Attr = ]

vptray -> %ProgramFiles%\NavNT\vptray.exe -> File not found

Zone Labs Client -> E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 755480 bytes | Modified Date = 16/03/2006 11:34:00 | Attr = ]

< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\

IMAIL -> Installed = 1 ->

MAPI -> Installed = 1 ->

MSFS -> Installed = 1 ->

< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe -> File not found

< User Startup > -> C:\Documents and Settings\admin\Menu Démarrer\Programmes\Démarrage

%UserStartup%\OutClock (2).lnk -> E:\Program Files\OutClock\OutClock.exe -> Alain TAUBER [Ver = 3.8.9.200 | Size = 2137600 bytes | Modified Date = 03/01/2007 04:09:00 | Attr = ]

< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Modified Date = 28/09/2006 16:13:28 | Attr = ]

{E1DAC82B-1C81-41B2-AC1B-6AE2653965E0} [HKLM] -> Reg Data - Key not found [] -> File not found

< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders

< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

NavLogon -> %System32%\NavLogon.dll -> [Ver = | Size = 28672 bytes | Modified Date = 29/10/2000 22:39:52 | Attr = ]

< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\AdminComponent\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->

< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 149 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->

< Software Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\

HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\MRT\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\UserNameString -> Nom d'utilisateur : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\PasswordString -> Mot de passe : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\DomainString -> Domaine : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\CredentialsString -> Informations d'identification utilisées pour l'enregistrement Dynamique DNS : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\NetCache\ -> ->

< Software Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\policies\

HKEY_CURRENT_USER\Software\Policies\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> ->

< HOSTS File > (0 bytes) -> C:\WINNT\System32\drivers\etc\Hosts

< Internet Explorer Settings > ->

HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->

HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->

HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Start Page -> http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home ->

HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: Search\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->

HKLM: URLSearchHooks\\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found

HKCU: Local Page -> C:\WINNT\system32\blank.htm ->

HKCU: Search Bar -> http://search.msn.com/spbasic.htm ->

HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKCU: Start Page -> http://www.yahoo.fr/ ->

HKCU: SearchAssistant -> http://www.google.com/ie ->

HKCU: ProxyEnable -> 0 ->

< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 02/03/2001 12:02:04 | Attr = ]

{2E03C0FD-4C48-43A7-9A54-00240C70FF16} [HKLM] -> %System32%\BhoECart.dll [ECarteBleueBrowserHelper Class] -> Orbiscom Ltd. All rights reserved. [Ver = 2, 2, 1, 0, 93 | Size = 69632 bytes | Modified Date = 20/12/2002 10:15:04 | Attr = ]

{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> E:\Program Files\Spybot\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [sSVHelper Class] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 10/11/2005 14:22:10 | Attr = ]

{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\googletoolbar3.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 19/01/2007 23:56:04 | Attr = R ]

< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar

{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar3.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 19/01/2007 23:56:04 | Attr = R ]

< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar3.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 19/01/2007 23:56:04 | Attr = R ]

< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 69746 bytes | Modified Date = 10/11/2005 14:22:10 | Attr = ]

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 10/11/2005 14:22:10 | Attr = ]

{E023F504-0C5A-4750-A1E7-A9046DEA8A21} -> Reg Data - Value does not exist [buttonText: MoneySide] -> File not found

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -> E:\PROGRA~1\Yahoo\YPager.exe [buttonText: Yahoo! Messenger] -> File not found

< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\

&Google Search -> Reg Data - Value does not exist -> File not found

Pages liées -> Reg Data - Value does not exist -> File not found

Pages similaires -> Reg Data - Value does not exist -> File not found

Version de la page actuelle disponible dans le cache Google -> Reg Data - Value does not exist -> File not found

< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\

{298F40AB-8F27-4B8D-ACCE-08A6494BF95A} -> () ->

{9796EE23-146F-4F0B-BFF2-B64C320108AA} -> (Contrôleur Fast Ethernet intégré 3Com 3C920 (compatible 3C905C-TX)) ->

< Default Protocols [HKLM] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

shell -> shell protocol not assigned ->

< Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

shell -> shell protocol not assigned ->

< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\

ipp -> Reg Data - Key not found -> File not found

msdaipp -> Reg Data - Key not found -> File not found

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\

{33564D57-0000-0010-8000-00AA00389B71} -> - CodeBase = http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB ->

{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab ->

{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab ->

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab ->

{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab ->

DirectAnimation Java Classes -> - CodeBase = file://C:\WINNT\Java\classes\dajava.cab ->

fdjeux -> - CodeBase = https://www.fdjeux.net/classes/fdjeux.cab ->

Microsoft XML Parser for Java -> - CodeBase = file://C:\WINNT\Java\classes\xmldso.cab ->

teleir_cert -> - CodeBase = https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab ->

 

 

[Registry - Additional Scans - Non-Microsoft Only]

< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\

.bat [@ = batfile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.chm [@ = chm.file] -> PersistentHandler = Reg Data - Key not found ->

.cmd [@ = cmdfile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.com [@ = comfile] -> PersistentHandler = {098f2470-bae0-11cd-b579-08002b30bfeb} ->

.cpl [@ = cplfile] -> PersistentHandler = Reg Data - Key not found ->

.exe [@ = exefile] -> PersistentHandler = {098f2470-bae0-11cd-b579-08002b30bfeb} ->

.hlp [@ = hlpfile] -> PersistentHandler = Reg Data - Key not found ->

.hta [@ = htafile] -> PersistentHandler = {eec97550-47a9-11cf-b952-00aa0051fe20} ->

.html [@ = FirefoxHTML] -> PersistentHandler = {eec97550-47a9-11cf-b952-00aa0051fe20} ->

.inf [@ = inffile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.ini [@ = inifile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.url [@ = InternetShortcut] -> PersistentHandler = Reg Data - Key not found ->

.js [@ = JSFile] -> PersistentHandler = Reg Data - Key not found ->

.jse [@ = JSEFile] -> PersistentHandler = Reg Data - Key not found ->

.pif [@ = piffile] -> PersistentHandler = Reg Data - Key not found ->

.reg [@ = regfile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.scr [@ = scrfile] -> PersistentHandler = Reg Data - Key not found ->

.txt [@ = txtfile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.vbe [@ = VBEFile] -> PersistentHandler = Reg Data - Key not found ->

.vbs [@ = VBSFile] -> PersistentHandler = {5e941d80-bf96-11cd-b579-08002b30bfeb} ->

.wsf [@ = WSFFile] -> PersistentHandler = Reg Data - Key not found ->

.wsh [@ = WSHFile] -> PersistentHandler = Reg Data - Key not found ->

< Security Settings > ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center not found. -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Start -> 3 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ImagePath -> %SystemRoot%\system32\svchost.exe -k BITSgroup ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DisplayName -> Service de transfert intelligent en arrière-plan ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnService -> LanmanWorkstation;Rpcss;SENS;Wmi; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\\Description -> Transfère des fichiers en tâche de fond en utilisant la bande passante du réseau lors de ses périodes d'inactivité. Si le service est arrêté, des fonctionnalités qui dépendent de BITS, telles que Windows Update et MSN Explorer ne pourront plus télécharger automatiquement des programmes et d'autres informations. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Parameters\\ServiceDll -> C:\WINNT\system32\qmgr.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\ -> Root\LEGACY_BITS00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BITS\Enum\\NextInstance -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Type -> 288 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Start -> 3 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ImagePath -> %SystemRoot%\System32\svchost.exe -k netsvcs ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DisplayName -> Partage de connexion Internet ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnService -> RasMan; ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\DependOnGroup -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\\Description -> Assure la traduction des adresses de réseau, l'adressage et les services de résolution de nom pour tous les ordinateurs de votre réseau à domicile via une connexion à distance. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\\ServiceDll -> %SystemRoot%\System32\ipnathlp.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Description -> Active le téléchargement et l'installation de mises à jour Windows critiques. Si le service est désactivé, le système d'exploitation peut être mis à jour manuellement sur le site Web de Windows Update. ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\DisplayName -> Mises à jour automatiques ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ErrorControl -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ImagePath -> %systemroot%\system32\svchost.exe -k wugroup ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\ObjectName -> LocalSystem ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Start -> 2 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\\Type -> 32 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters\\ServiceDll -> C:\WINNT\System32\wuauserv.dll ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security\\Security ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\ -> Root\LEGACY_WUAUSERV00 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\Count -> 1 ->

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum\\NextInstance -> 1 ->

< Uninstall List > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\

{0A87023F-ACC0-4947-8506-D7D600929370} -> Fichiers programme Professional ->

{16A5A16B-241E-4FE7-B5A8-D5F56F1373EF} -> Aide sur la conception de bases de données ->

{17E27BFB-BD58-11d2-AFC1-00C04F72FB3E} -> VBA (2720.:P ->

{22AE875F-B8B3-46AF-856C-CE858538D912} -> Lexibase Pro ->

{2318C2B1-4965-11d4-9B18-009027A5CD4F} -> Google Toolbar for Internet Explorer ->

{30B7844C-31C8-4C57-B9FF-F39122E4A19C} -> Diagrammes réseau avancés ->

{3248F0A8-6813-11D6-A77B-00B0D0150060} -> J2SE Runtime Environment 5.0 Update 6 ->

{37F190BA-FE4F-454A-B143-F794564604B2} -> Aide sur les fichiers programme Professional ->

{47808F78-F178-49DC-B708-15FE538B16FF} -> iTunes ->

{5081528F-5DD5-49BA-8213-9A6A13502497} -> Sentinel System Driver 5.41.1 (32-bit) ->

{509291FD-CFC8-11D6-A285-00A0CC51B2FE} -> Sound Blaster PCI128 Drivers ->

{69ABFDE4-0826-4649-BA00-9991C110228D} -> Diagrammes Internet ->

{6F716DA0-398F-11D3-85E1-005004838609} -> WebFldrs ->

{701C5484-2321-4CE8-8576-007DE0C7376E} -> Conception de bases de données ->

{77E70C3C-DBB9-4C47-8663-1E1F81FEC623} -> Logitech QuickCam ->

{802360F1-F9E0-457C-A5DB-7078AAE20630} -> Aide sur les diagrammes réseau avancés ->

{83B62060-967B-45B9-BFF9-E06EF972AABA} -> Aide sur la conception de logiciels ->

{862E3E2D-1568-433D-002E-CC3850091700} -> Notes sur la version Professional ->

{88C02750-7811-11D3-B83B-00C04F58D527} -> Bordures et arrière-plans ->

{88C02751-7811-11D3-B83B-00C04F58D527} -> Affichage de dessins de CAO ->

{88C02752-7811-11D3-B83B-00C04F58D527} -> Légendes et liens ->

{88C02753-7811-11D3-B83B-00C04F58D527} -> Images clipart et symboles ->

{88C02754-7811-11D3-B83B-00C04F58D527} -> Editeur de propriétés personnalisées ->

{88C02755-7811-11D3-B83B-00C04F58D527} -> Assistant Bases de données ->

{88C02756-7811-11D3-B83B-00C04F58D527} -> Assistant Mise en page ->

{88C02758-7811-11D3-B83B-00C04F58D527} -> Assistant Rapport de propriétés ->

{88C02759-7811-11D3-B83B-00C04F58D527} -> Enregistrer sous HTML ->

{88C0275A-7811-11D3-B83B-00C04F58D527} -> Explorateur de formes ->

{88C0275D-7811-11D3-B83B-00C04F58D527} -> Aide sur les fichiers programme ->

{88C0275E-7811-11D3-B83B-00C04F58D527} -> Diagrammes de blocs ->

{88C0275F-7811-11D3-B83B-00C04F58D527} -> Diagrammes de flux ->

{88C02760-7811-11D3-B83B-00C04F58D527} -> Formulaires et graphiques ->

{88C02761-7811-11D3-B83B-00C04F58D527} -> Cartes ->

{88C02763-7811-11D3-B83B-00C04F58D527} -> Diagrammes réseau ->

{88C02764-7811-11D3-B83B-00C04F58D527} -> Agencement d'espaces ->

{88C02765-7811-11D3-B83B-00C04F58D527} -> Organigrammes ->

{88C02766-7811-11D3-B83B-00C04F58D527} -> Plannings de projet ->

{88C028B3-7811-11D3-B83B-00C04F58D527} -> Aide Shape Explorer ->

{88C02929-7811-11D3-B83B-00C04F58D527} -> Aide sur les diagrammes de flux ->

{8DF66342-77E4-11D3-B83B-00C04F58D527} -> Vérificateur d'orthographe ->

{8DF66343-77E4-11D3-B83B-00C04F58D527} -> Solutions ->

{8DF66345-77E4-11D3-B83B-00C04F58D527} -> Notes sur cette version ->

{8DF6634B-77E4-11D3-B83B-00C04F58D527} -> Programmes complémentaires ->

{9DA5448B-4127-11D3-8F79-00C04F8DD7E3} -> Aide sur les images clipart et les symboles ->

{9DA5448D-4127-11D3-8F79-00C04F8DD7E3} -> Aide sur les legendes et les liens ->

{9DA5448F-4127-11D3-8F79-00C04F8DD7E3} -> Aide sur les bordures et les arrière-plans ->

{A3B215CF-7A43-11D3-B83B-00C04F58D527} -> Aide sur les diagrammes de blocs ->

{A3B21615-7A43-11D3-B83B-00C04F58D527} -> Aide sur les formulaires et les graphiques ->

{A3B21665-7A43-11D3-B83B-00C04F58D527} -> Aides sur les cartes ->

{A3B21686-7A43-11D3-B83B-00C04F58D527} -> Aide sur les diagrammes réseau ->

{AC7A5F98-2BD1-444F-97EA-4559EC1F8768} -> Directory Services ->

{B197AE2C-8C94-44D8-8CD4-2ECEBF3B6100} -> Conception de logiciels ->

{B2C7C463-408C-11D3-8F79-00C04F8DD7E3} -> Aide sur Developing Visio Solutions ->

{B2C7C466-408C-11D3-8F79-00C04F8DD7E3} -> Aide sur les plannings de projet ->

{B2C7C469-408C-11D3-8F79-00C04F8DD7E3} -> Aide sur les organigrammes ->

{B2C7C46C-408C-11D3-8F79-00C04F8DD7E3} -> Aide sur l'agencement d'espaces ->

{B43357AA-3A6D-4D94-B56E-43C44D09E548} -> Microsoft .NET Framework (English) ->

{B51AFA85-23A2-4FE8-BB82-AFDA97F36F31} -> Studio Numérique de Lapin Malin ->

{B66F45DC-853B-11d3-83DE-00C04F3223C8} -> Visio 2000 (FR) ->

{B66F462A-853B-11d3-83DE-00C04F3223C8} -> Visio ->

{B66F464B-853B-11d3-83DE-00C04F3223C8} -> Help for Visio 2000 (HTML Help) ->

{B66F4695-853B-11d3-83DE-00C04F3223C8} -> Visio Core Files ->

{CF5193FB-6B37-11D5-B7D2-00AA00A204F1} -> Extension Système de Microsoft Money ->

{DA2EA0B2-0996-4682-B845-12F4FF3365D1} -> Aide sur les diagrammes Internet ->

{DF9925FC-C5F9-42D1-9DEE-F339D3046895} -> Aide sur les services d'annuaire ->

{E13AE282-1E35-412D-9D4B-9FE3B81D3813} -> Lapin Malin Initiation à l'anglais v2 ->

{E5430A11-6799-41E0-A9D5-F68BDC67AAD8} -> OpenOffice.org 2.1 ->

{E7298FDC-1386-11D5-8D6C-0050DAD32D95} -> Microsoft Money ->

{E8814A8F-3B06-11D3-8CD7-00C04F72C04D} -> Microsoft Visual Studio Service Pack 3 ->

{ED479ED4-A1C5-11d3-83E3-00C04F3223C8} -> Fichiers programme ->

{EEBC43D5-C84E-401D-84BC-D7DF882ED00D} -> Canon Camera TWAIN Driver ->

{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8} -> QuickTime ->

{F27E6293-F894-4562-B356-8726B89839FC} -> Filtres graphiques ->

ACDSee 32 -> ACDSee 32 ->

Adobe Acrobat 5.0 -> Adobe Acrobat 5.0 ->

AVG7Uninstall -> AVG Free Edition ->

AVGAntiSpyware75 -> AVG Anti-Spyware 7.5 ->

CameraWindowDVC5 -> Canon Camera Window DC_DV 5 for ZoomBrowser EX ->

CameraWindowDVC6 -> Canon Camera Window DC_DV 6 for ZoomBrowser EX ->

CameraWindowMC -> Canon Camera Window MC 6 for ZoomBrowser EX ->

Canon G.726 WMP-Decoder -> Canon G.726 WMP-Decoder ->

CANONBJ_Deinstall_CNMCP1U.DLL -> BJC-2000 ->

CCleaner -> CCleaner (remove only) ->

Childsplay_is1 -> Childsplay 0.84.0 ->

Compteur Horaire_is1 -> Compteur Horaire 1.5 ->

CSCLIB -> Canon Camera Support Core Library ->

EOS Utility -> Canon Utilities EOS Utility ->

EPSON Imprimante et utilitaires -> EPSON Logiciel imprimante ->

EPSON Printer and Utilities -> EPSON Logiciel imprimante ->

eureka -> Encyclopédie Hachette Multimédia (désinstallation) ->

FlatBed Scanner -> FlatBed Scanner ->

Free Mp3 Wma Converter_is1 -> Free Mp3 Wma Converter V 1.4.0 ->

FreePCvcR v0.5.3 -> FreePCvcR v0.5.3 ->

HijackThis -> HijackThis 1.99.1 ->

InstallShield_{47808F78-F178-49DC-B708-15FE538B16FF} -> iTunes ->

InstallShield_{EEBC43D5-C84E-401D-84BC-D7DF882ED00D} -> Canon Camera TWAIN Driver 6.6 ->

LeechFTP -> LeechFTP ->

Livre Album Fuji Photo_is1 -> Livre Album Fuji Photo ->

Macromedia Shockwave Player -> Macromedia Shockwave Player ->

Microsoft .NET Framework Full v1.0.3705 (1033) -> Microsoft .NET Framework (English) v1.0.3705 ->

MovieEditTask -> Canon MovieEdit Task for ZoomBrowser EX ->

Mozilla Firefox (2.0.0.3) -> Mozilla Firefox (2.0.0.3) ->

Mozilla Thunderbird (1.5) -> Mozilla Thunderbird (1.5) ->

OutClock -> OutClock ->

PhotoFiltre -> PhotoFiltre ->

PhotoStitch -> Canon Utilities PhotoStitch ->

Picasa2 -> Picasa 2 ->

Pingu - Le CD-Rom des petits pingouins -> Pingu - Le CD-Rom des petits pingouins ->

PowerArchiver -> PowerArchiver ->

PowerTWAIN -> Primax PowerTWAIN (CD nécessaire) ->

RAW Image Task -> Canon RAW Image Task for ZoomBrowser EX ->

RealPlayer 6.0 -> RealPlayer ->

RemoteCaptureTask -> Canon RemoteCapture Task for ZoomBrowser EX ->

Roxie's ABC Fish -> Roxie's ABC Fish ->

ShockwaveFlash -> Macromedia Flash Player 8 ->

Spybot - Search & Destroy_is1 -> Spybot - Search & Destroy 1.4 ->

UControl Scan and Remove -> UControl Scan and Remove ->

VLC media player -> VideoLAN VLC media player 0.8.4a ->

Windows 2000 Service Pack -> Windows 2000 Service Pack 4 ->

WMP7 -> Windows Media Player system update (9 Series) ->

ZoneAlarm -> ZoneAlarm ->

ZoomBrowser EX -> Canon Utilities ZoomBrowser EX ->

 

[Files/Folders - Created Within 90 days]

ccsetup131.exe -> %SystemDrive%\ccsetup131.exe -> Piriform Ltd [Ver = 1.31.0.325 | Size = 1458008 bytes | Created Date = 06/04/2007 17:47:54 | Attr = ]

SDFix -> %SystemDrive%\SDFix -> [Folder | Created Date = 09/05/2007 21:19:24 | Attr = ]

SmitfraudFix.zip -> %SystemDrive%\SmitfraudFix.zip -> [Ver = | Size = 787474 bytes | Created Date = 06/04/2007 17:47:30 | Attr = ]

VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Created Date = 08/05/2007 17:25:41 | Attr = ]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Created Date = 05/04/2007 21:08:00 | Attr = ]

QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 01/05/2007 13:03:19 | Attr = ]

QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 01/05/2007 13:03:19 | Attr = H ]

ahxhgnoe.exe -> %System32%\ahxhgnoe.exe -> [Ver = | Size = 78250 bytes | Created Date = 01/04/2007 16:57:12 | Attr = H ]

aqrxc.exe -> %System32%\aqrxc.exe -> [Ver = | Size = 26944 bytes | Created Date = 01/04/2007 18:58:03 | Attr = H ]

bund1 -> %System32%\bund1 -> [Folder | Created Date = 01/04/2007 19:21:40 | Attr = ]

cpuxfpd.exe -> %System32%\cpuxfpd.exe -> [Ver = | Size = 7812 bytes | Created Date = 01/04/2007 18:58:33 | Attr = H ]

ebenb.exe -> %System32%\ebenb.exe -> [Ver = | Size = 7964 bytes | Created Date = 01/04/2007 18:59:15 | Attr = H ]

egeqsylj.exe -> %System32%\egeqsylj.exe -> [Ver = | Size = 126464 bytes | Created Date = 01/04/2007 19:03:10 | Attr = H ]

euqbt.bat -> %System32%\euqbt.bat -> [Ver = | Size = 115 bytes | Created Date = 01/04/2007 18:01:36 | Attr = ]

gjpjiz.exe -> %System32%\gjpjiz.exe -> [Ver = | Size = 23552 bytes | Created Date = 01/04/2007 18:56:51 | Attr = H ]

hxigu.bat -> %System32%\hxigu.bat -> [Ver = | Size = 118 bytes | Created Date = 01/04/2007 19:21:58 | Attr = ]

ijmoq.bak1 -> %System32%\ijmoq.bak1 -> [Ver = | Size = 520673 bytes | Created Date = 05/04/2007 21:21:11 | Attr = HS]

ijmoq.bak2 -> %System32%\ijmoq.bak2 -> [Ver = | Size = 522536 bytes | Created Date = 13/04/2007 09:08:30 | Attr = HS]

ijmoq.ini -> %System32%\ijmoq.ini -> [Ver = | Size = 528817 bytes | Created Date = 05/04/2007 21:20:49 | Attr = HS]

izlh.bat -> %System32%\izlh.bat -> [Ver = | Size = 123 bytes | Created Date = 01/04/2007 17:57:51 | Attr = ]

jzhupsp.exe -> %System32%\jzhupsp.exe -> [Ver = | Size = 1024 bytes | Created Date = 01/04/2007 18:14:13 | Attr = H ]

mdgx.exe -> %System32%\mdgx.exe -> [Ver = | Size = 23872 bytes | Created Date = 01/04/2007 18:11:47 | Attr = H ]

micro1 -> %System32%\micro1 -> [Folder | Created Date = 01/04/2007 19:21:51 | Attr = ]

mylzul.exe -> %System32%\mylzul.exe -> [Ver = | Size = 16308 bytes | Created Date = 01/04/2007 19:01:18 | Attr = H ]

njswmaj.bat -> %System32%\njswmaj.bat -> [Ver = | Size = 129 bytes | Created Date = 01/04/2007 18:01:39 | Attr = ]

onjlhmk.exe -> %System32%\onjlhmk.exe -> [Ver = | Size = 50638 bytes | Created Date = 01/04/2007 17:57:33 | Attr = H ]

Perflib_Perfdata_3b0.dat -> %System32%\Perflib_Perfdata_3b0.dat -> [Ver = | Size = 16384 bytes | Created Date = 13/04/2007 09:08:23 | Attr = ]

pfphnuj.exe -> %System32%\pfphnuj.exe -> [Ver = | Size = 20480 bytes | Created Date = 01/04/2007 19:15:43 | Attr = H ]

pkta.bat -> %System32%\pkta.bat -> [Ver = | Size = 123 bytes | Created Date = 01/04/2007 19:21:14 | Attr = ]

pveps.bat -> %System32%\pveps.bat -> [Ver = | Size = 127 bytes | Created Date = 01/04/2007 18:27:41 | Attr = ]

used.exe -> %System32%\used.exe -> [Ver = | Size = 10240 bytes | Created Date = 01/04/2007 18:58:10 | Attr = H ]

vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 41108 bytes | Created Date = 05/04/2007 21:09:12 | Attr = ]

vsdata.dll -> %System32%\vsdata.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 83736 bytes | Created Date = 05/04/2007 21:08:00 | Attr = ]

vsdatant.sys -> %System32%\vsdatant.sys -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 372824 bytes | Created Date = 05/04/2007 21:09:17 | Attr = ]

vsinit.dll -> %System32%\vsinit.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 141080 bytes | Created Date = 05/04/2007 21:08:00 | Attr = ]

vsmonapi.dll -> %System32%\vsmonapi.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 104216 bytes | Created Date = 05/04/2007 21:09:17 | Attr = ]

vspubapi.dll -> %System32%\vspubapi.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 227096 bytes | Created Date = 05/04/2007 21:09:17 | Attr = ]

vsregexp.dll -> %System32%\vsregexp.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 71448 bytes | Created Date = 05/04/2007 21:09:37 | Attr = ]

vsutil.dll -> %System32%\vsutil.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 382744 bytes | Created Date = 05/04/2007 21:08:00 | Attr = ]

vsxml.dll -> %System32%\vsxml.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 100120 bytes | Created Date = 05/04/2007 21:09:20 | Attr = ]

vtqxqi.exe -> %System32%\vtqxqi.exe -> [Ver = | Size = 31324 bytes | Created Date = 01/04/2007 19:00:57 | Attr = H ]

wnvvmblm.exe -> %System32%\wnvvmblm.exe -> [Ver = | Size = 38522 bytes | Created Date = 01/04/2007 16:56:52 | Attr = H ]

ykjytxn.exe -> %System32%\ykjytxn.exe -> [Ver = | Size = 40900 bytes | Created Date = 01/04/2007 19:03:14 | Attr = H ]

ylnmfqtq.exe -> %System32%\ylnmfqtq.exe -> [Ver = | Size = 2048 bytes | Created Date = 01/04/2007 19:01:35 | Attr = H ]

zlcomm.dll -> %System32%\zlcomm.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 79640 bytes | Created Date = 05/04/2007 21:09:30 | Attr = ]

zlcommdb.dll -> %System32%\zlcommdb.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 71448 bytes | Created Date = 05/04/2007 21:09:30 | Attr = ]

ZoneLabs -> %System32%\ZoneLabs -> [Folder | Created Date = 05/04/2007 21:09:18 | Attr = ]

zzeyyu.exe -> %System32%\zzeyyu.exe -> [Ver = | Size = 78848 bytes | Created Date = 01/04/2007 19:03:07 | Attr = H ]

dvdplay.exe -> %System32%\dllcache\dvdplay.exe -> [Ver = 1, 0, 0, 1 | Size = 124688 bytes | Created Date = 01/04/2007 20:07:13 | Attr = ]

AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 16/04/2007 20:43:56 | Attr = ]

core.cache.dsk -> %System32%\drivers\core.cache.dsk -> [Ver = | Size = 161849 bytes | Created Date = 01/04/2007 19:21:54 | Attr = ]

core.sys -> %System32%\drivers\core.sys -> [Ver = | Size = 72320 bytes | Created Date = 01/04/2007 19:21:54 | Attr = ]

 

[Files/Folders - Modified Within 90 days]

$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 07/05/2007 21:11:54 | Attr = RH ]

ccsetup131.exe -> %SystemDrive%\ccsetup131.exe -> Piriform Ltd [Ver = 1.31.0.325 | Size = 1458008 bytes | Modified Date = 06/04/2007 08:46:46 | Attr = ]

My Music -> %SystemDrive%\My Music -> [Folder | Modified Date = 01/05/2007 14:02:46 | Attr = ]

Program Files -> %ProgramFiles% -> [Folder | Modified Date = 14/04/2007 13:39:02 | Attr = R ]

SDFix -> %SystemDrive%\SDFix -> [Folder | Modified Date = 09/05/2007 22:29:44 | Attr = ]

SmitfraudFix.zip -> %SystemDrive%\SmitfraudFix.zip -> [Ver = | Size = 787474 bytes | Modified Date = 06/04/2007 08:37:38 | Attr = ]

VundoFix Backups -> %SystemDrive%\VundoFix Backups -> [Folder | Modified Date = 08/05/2007 18:40:44 | Attr = ]

WINNT -> %SystemRoot% -> [Folder | Modified Date = 10/05/2007 18:02:12 | Attr = ]

A6W.INI -> %SystemRoot%\A6W.INI -> [Ver = | Size = 35 bytes | Modified Date = 10/05/2007 17:45:28 | Attr = ]

A6W_DATA -> %SystemRoot%\A6W_DATA -> [Folder | Modified Date = 10/05/2007 18:01:06 | Attr = ]

CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 08/05/2007 18:39:02 | Attr = HS]

Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 10/05/2007 08:48:28 | Attr = ]

Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 01/05/2007 18:22:34 | Attr = HS]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 09/05/2007 20:38:10 | Attr = ]

Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 07/05/2007 22:24:26 | Attr = ]

pmxpower.INI -> %SystemRoot%\pmxpower.INI -> [Ver = | Size = 73 bytes | Modified Date = 17/04/2007 23:16:48 | Attr = ]

QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 01/05/2007 14:04:20 | Attr = ]

QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 07/05/2007 22:40:56 | Attr = H ]

Run32A60.mch -> %SystemRoot%\Run32A60.mch -> [Ver = | Size = 87638 bytes | Modified Date = 10/05/2007 18:02:12 | Attr = ]

security -> %SystemRoot%\security -> [Folder | Modified Date = 10/05/2007 12:37:54 | Attr = ]

system32 -> %System32% -> [Folder | Modified Date = 10/05/2007 08:48:16 | Attr = ]

Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 10/05/2007 18:29:22 | Attr = ]

wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 229 bytes | Modified Date = 02/04/2007 18:49:20 | Attr = ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 10/05/2007 08:47:48 | Attr = H ]

ahxhgnoe.exe -> %System32%\ahxhgnoe.exe -> [Ver = | Size = 78250 bytes | Modified Date = 01/04/2007 17:57:34 | Attr = H ]

aqrxc.exe -> %System32%\aqrxc.exe -> [Ver = | Size = 26944 bytes | Modified Date = 01/04/2007 19:59:20 | Attr = H ]

bund1 -> %System32%\bund1 -> [Folder | Modified Date = 01/04/2007 20:21:52 | Attr = ]

cpuxfpd.exe -> %System32%\cpuxfpd.exe -> [Ver = | Size = 7812 bytes | Modified Date = 01/04/2007 19:58:56 | Attr = H ]

d3d9caps.dat -> %System32%\d3d9caps.dat -> [Ver = | Size = 1204 bytes | Modified Date = 07/05/2007 23:43:04 | Attr = ]

dllcache -> %System32%\dllcache -> [Folder | Modified Date = 23/04/2007 18:41:24 | Attr = RHS]

drivers -> %System32%\drivers -> [Folder | Modified Date = 27/04/2007 18:16:12 | Attr = ]

ebenb.exe -> %System32%\ebenb.exe -> [Ver = | Size = 7964 bytes | Modified Date = 01/04/2007 19:59:22 | Attr = H ]

egeqsylj.exe -> %System32%\egeqsylj.exe -> [Ver = | Size = 126464 bytes | Modified Date = 01/04/2007 20:03:34 | Attr = H ]

euqbt.bat -> %System32%\euqbt.bat -> [Ver = | Size = 115 bytes | Modified Date = 01/04/2007 19:01:38 | Attr = ]

gjpjiz.exe -> %System32%\gjpjiz.exe -> [Ver = | Size = 23552 bytes | Modified Date = 01/04/2007 19:58:58 | Attr = H ]

hxigu.bat -> %System32%\hxigu.bat -> [Ver = | Size = 118 bytes | Modified Date = 01/04/2007 20:22:00 | Attr = ]

ijmoq.bak1 -> %System32%\ijmoq.bak1 -> [Ver = | Size = 520673 bytes | Modified Date = 05/04/2007 22:21:12 | Attr = HS]

ijmoq.bak2 -> %System32%\ijmoq.bak2 -> [Ver = | Size = 522536 bytes | Modified Date = 13/04/2007 10:08:32 | Attr = HS]

ijmoq.ini -> %System32%\ijmoq.ini -> [Ver = | Size = 528817 bytes | Modified Date = 16/04/2007 21:09:46 | Attr = HS]

izlh.bat -> %System32%\izlh.bat -> [Ver = | Size = 123 bytes | Modified Date = 01/04/2007 18:57:52 | Attr = ]

jzhupsp.exe -> %System32%\jzhupsp.exe -> [Ver = | Size = 1024 bytes | Modified Date = 01/04/2007 19:14:18 | Attr = H ]

Mc3_Data.cst -> %System32%\Mc3_Data.cst -> [Ver = | Size = 78086 bytes | Modified Date = 20/04/2007 16:40:58 | Attr = H ]

mdgx.exe -> %System32%\mdgx.exe -> [Ver = | Size = 23872 bytes | Modified Date = 01/04/2007 19:12:02 | Attr = H ]

micro1 -> %System32%\micro1 -> [Folder | Modified Date = 23/04/2007 18:53:30 | Attr = ]

mylzul.exe -> %System32%\mylzul.exe -> [Ver = | Size = 16308 bytes | Modified Date = 01/04/2007 20:01:38 | Attr = H ]

njswmaj.bat -> %System32%\njswmaj.bat -> [Ver = | Size = 129 bytes | Modified Date = 01/04/2007 19:01:40 | Attr = ]

NtmsData -> %System32%\NtmsData -> [Folder | Modified Date = 10/05/2007 08:48:36 | Attr = ]

onjlhmk.exe -> %System32%\onjlhmk.exe -> [Ver = | Size = 50638 bytes | Modified Date = 01/04/2007 18:58:06 | Attr = H ]

Perflib_Perfdata_3b0.dat -> %System32%\Perflib_Perfdata_3b0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 13/04/2007 10:08:28 | Attr = ]

pfphnuj.exe -> %System32%\pfphnuj.exe -> [Ver = | Size = 20480 bytes | Modified Date = 01/04/2007 20:16:18 | Attr = H ]

pkta.bat -> %System32%\pkta.bat -> [Ver = | Size = 123 bytes | Modified Date = 01/04/2007 20:21:16 | Attr = ]

pveps.bat -> %System32%\pveps.bat -> [Ver = | Size = 127 bytes | Modified Date = 01/04/2007 19:27:42 | Attr = ]

QuickTime.qtp -> %System32%\QuickTime.qtp -> [Ver = | Size = 63253 bytes | Modified Date = 01/05/2007 14:04:12 | Attr = ]

used.exe -> %System32%\used.exe -> [Ver = | Size = 10240 bytes | Modified Date = 01/04/2007 19:58:22 | Attr = H ]

vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 41108 bytes | Modified Date = 10/05/2007 08:48:30 | Attr = ]

vtqxqi.exe -> %System32%\vtqxqi.exe -> [Ver = | Size = 31324 bytes | Modified Date = 01/04/2007 20:01:40 | Attr = H ]

wnvvmblm.exe -> %System32%\wnvvmblm.exe -> [Ver = | Size = 38522 bytes | Modified Date = 01/04/2007 17:57:34 | Attr = H ]

ykjytxn.exe -> %System32%\ykjytxn.exe -> [Ver = | Size = 40900 bytes | Modified Date = 01/04/2007 20:03:38 | Attr = H ]

ylnmfqtq.exe -> %System32%\ylnmfqtq.exe -> [Ver = | Size = 2048 bytes | Modified Date = 01/04/2007 20:01:38 | Attr = H ]

zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Modified Date = 05/04/2007 22:12:22 | Attr = H ]

ZoneLabs -> %System32%\ZoneLabs -> [Folder | Modified Date = 05/04/2007 22:09:48 | Attr = ]

zzeyyu.exe -> %System32%\zzeyyu.exe -> [Ver = | Size = 78848 bytes | Modified Date = 01/04/2007 20:03:36 | Attr = H ]

avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 27/04/2007 18:15:40 | Attr = ]

avg7rsnt.sys -> %System32%\drivers\avg7rsnt.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 26944 bytes | Modified Date = 24/02/2007 19:08:08 | Attr = ]

avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Modified Date = 24/02/2007 19:08:08 | Attr = ]

core.cache.dsk -> %System32%\drivers\core.cache.dsk -> [Ver = | Size = 161849 bytes | Modified Date = 01/04/2007 20:21:56 | Attr = ]

core.sys -> %System32%\drivers\core.sys -> [Ver = | Size = 72320 bytes | Modified Date = 01/04/2007 20:21:56 | Attr = ]

 

[File String Scan - Non-Microsoft Only]

Thawte Consulting , -> %SystemDrive%\ccsetup131.exe -> Piriform Ltd [Ver = 1.31.0.325 | Size = 1458008 bytes | Modified Date = 06/04/2007 08:46:46 | Attr = ]

winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 07/12/1999 15:00:00 | Attr = ]

UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 27/04/2007 18:15:40 | Attr = ]

PEC2 , -> %System32%\drivers\winacpci.sys -> Conexant [Ver = 2.1.2.164.010 | Size = 900528 bytes | Modified Date = 03/11/1999 18:26:50 | Attr = ]

 

< End of report >

_______________

 

Rapport Panda ActiveScan

 

 

Incident Statut Analyse

 

Adware:adware/whenusearch No Désinfecté c:\program files\fichiers communs\WhenU

Adware:adware/ucontrol No Désinfecté Registre Windows

Outil indésirable:Application/Processor No Désinfecté C:\Documents and Settings\admin\Bureau\SDFix.exe[sDFix\apps\Process.exe]

Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\admin\Cookies\admin@xiti[1].txt

Virus:Trj/Downloader.NUS Désinfecté C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\K58RERYJ\axqnnnky[1].html

Virus:Trj/Downloader.NUS Désinfecté C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\K58RERYJ\fagdnnxh[1].html

Adware:Adware/Ucontrol No Désinfecté C:\Program Files\Fichiers communs\WhenU\UControlScanAndRemove.ocx

Outil indésirable:Application/Processor No Désinfecté C:\RECYCLER\S-1-5-21-583907252-1993962763-839522115-1000\Dc3\SDFix\apps\Process.exe

Outil indésirable:Application/Processor No Désinfecté C:\SDFix\apps\Process.exe

Outil indésirable:Application/Processor No Désinfecté C:\SmitfraudFix.zip[smitfraudFix/Process.exe]

Virus:Trj/Shutdown.Z Désinfecté C:\SmitfraudFix.zip[smitfraudFix/restart.exe]

Virus:W32/Rinbot.O.worm Désinfecté C:\WINNT\system32\ahxhgnoe.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\aqrxc.exe

Spyware:Spyware/New.net No Désinfecté C:\WINNT\system32\bund1\ClientBundle1.exe[a1.exe]

Adware:Adware/WebBuying No Désinfecté C:\WINNT\system32\bund1\ClientBundle1.exe[web2.exe]

Adware:Adware/TTC No Désinfecté C:\WINNT\system32\bund1\ClientBundle1.exe[a3.exe]

Adware:Adware/DeluxeComunications No Désinfecté C:\WINNT\system32\bund1\ClientBundle1.exe[a4.exe]

Adware:Adware/DeluxeComunications No Désinfecté C:\WINNT\system32\bund1\ClientBundle1.exe[win5.exe]

Adware:Adware/Ucmore No Désinfecté C:\WINNT\system32\bund1\ClientBundle1.exe[a6.exe]

Hacktool:Rootkit/NTRootkit.AJ No Désinfecté C:\WINNT\system32\drivers\core.sys

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\ebenb.exe

Virus:Bck/Poebot.MA Désinfecté C:\WINNT\system32\egeqsylj.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\gjpjiz.exe

Virus:W32/Sdbot.ftp.worm Désinfecté C:\WINNT\system32\i

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\mdgx.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\mylzul.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\onjlhmk.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\pfphnuj.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\used.exe

Virus:W32/RxBot.KG.worm Désinfecté C:\WINNT\system32\vtqxqi.exe

Virus:W32/RxBot.KU.worm Désinfecté C:\WINNT\system32\ykjytxn.exe

Virus:W32/Sdbot.KFG.worm Désinfecté C:\WINNT\system32\zzeyyu.exe

_________________

 

Tout ça ne m'a pas l'air super-rassurant :P

 

Merci infiniment de ton aide

Posté(e) (modifié)

Va jusqu'au bout et si tu rencontres un problème, n'hésite pas à me le dire :P

 

Tu as deux possiblités pour consulter les instructions qui suivent:

 

-Soit tu copie/colles le contenu de la procédure dans un fichier texte(que tu met sur le bureau) pour pouvoir le consulter en mode sans échec(tu n'auras pas accès à internet!).

 

-Tu peux également enregistrer la page web complète, sur laquelle se trouve la procédure,

en le faisant à partir de ton navigateur :

 

-Aller en haut de page et cliquer sur le menu"Fichier" : une liste apparait=>

-Choisis "Enregistrer sous" et choisis "Bureau".

-Ensuite cliquer sur le bouton "Enregistrer" à droite du champs "nom du fichier".

 

Pour lire la procédure en mode sans échec, tu n'auras qu'à double cliquer sur le fichier Infection SmitFraud sous Windows 2000 (avec l'icone de ton navigateur) situé sur le bureau.(tu noteras qu'un nouveau dossier va se créer sur le bureau en plus du fichier : c'est normal!) De cette manière, tu conserveras toutes les mises en formes et les couleurs de la procédure, et cela permettra de t'y retrouver.

--------------------------------------------------------------------------------------------------------------------------

 

La procédure:

 

-Télécharge ATF Cleaner by Atribune sur ton bureau.

 

-Lance AVG Anti-Spyware : il faut mettre le programme à jour.

  • Sur l'écran principal sélectionne le menu "Mise à jour", puis clique sur le bouton "Commencer la mise à jour" sous "Mise à jour manuelle".
  • La mise à jour va commencer(il est possible que tu reçoives une alerte de ton parefeu: accepte la connexion au serveur).
  • Une fois la mise à jour faite, sélectionne le menu "Analyse" puis clique sur l'onglet "Paramètres".
  • Sous "Comment réagir", choisis "Quarantaine"
  • Sous "Rapports" clique sur "Générer un rapport après chaque analyse".
    décoche la case "Uniquement en cas de menace".
  • Ferme AVG Anti-Spyware et ne lance pas de scan maintenant!

-Démarre WinPFind3U en double cliquant sur WinPFind3U.exe et copie/colle le texte ci dessous (ne copie pas le mot code)

dans le Panneau Paste fix here , puis clique sur le bouton Run Fix.

[unregister Dlls]

[ Extra Files ]

C:\Program Files\Fichiers communs\WhenU\UControlScanAndRemove.ocx

C:\WINNT\system32\drivers\core.sys

C:\WINNT\system32\drivers\core.cache.dsk

C:\WINNT\system32\ylnmfqtq.exe

C:\WINNT\system32\bund1

C:\WINNT\system32\micro1

C:\WINNT\system32\wnvvmblm.exe

C:\WINNT\system32\cpuxfpd.exe

C:\WINNT\system32\mdgx.exe

C:\WINNT\system32\jzhupsp.exe

C:\WINNT\system32\Mc3_Data.cst

C:\WINNT\system32\ijmoq.ini

C:\WINNT\system32\ijmoq.bak1

C:\WINNT\system32\ijmoq.bak2

C:\WINNT\system32\hxigu.bat

C:\WINNT\system32\izlh.bat

C:\WINNT\system32\pveps.bat

C:\WINNT\system32\pkta.bat

C:\WINNT\system32\euqbt.bat

C:\WINNT\system32\njswmaj.bat

C:\WINNT\Run32A60.mch

C:\SDFix

C:\SmitfraudFix.zip

C:\VundoFix Backups

c:\program files\fichiers communs\WhenU

[Empty Temp Folders]

[Reboot]

Le Fix va se faire rapidement,puis il te sera demandé de redémarrer ton pc : accepte en cliquant sur Yes

 

Étape 1:

 

*Redémarre le PC, impérativement en mode sans échec,(au démarrage, tapoter immédiatement la touche F8,puis apparaitra un écran avec choix de démarrages : choisir "Mode sans échec" avec les flèches du clavier, puis valider avec "Entrée".

Choisir le compte usuel (et non Administrateur).

 

(n'ayant pas accès à Internet, tu as préalablement copié ces instructions dans un fichier texte)

 

Étape 2:

 

-Passe par "Ajouter ou Supprimer des Programmes"(Panneau de Configuration) et désinstalle les programmes suivant:

 

UControl Scan and Remove

 

Étape 3:

 

* Double-clique ATF Cleaner afin de lancer le programme.

  • Sous l'onglet Main, choisis : Select All
    Clique sur le bouton Empty Selected
     
    Si tu utilises le navigateur Firefox :
     
     
  • Clique Firefox au haut et choisis : Select All
    Clique le bouton Empty Selected
    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
     
    Si tu utilises le navigateur Opera :
     
     
  • Clique Opera au haut et choisis : Select All
    Clique le bouton Empty Selected
    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
     
    Clique Exit, du menu prinicipal, afin de fermer le programme.

* Si l'onglet "Firefox" est grisé dans ATF,nettoie le cache et les cookies dans Firefox comme ceci :

  • Ouvre Firefox et clique sur Outils=> Options
  • Clique sur l'onglet Vie Privée
  • clique sur le bouton Vider le cache dans l'onglet "Historique"
  • clique sur le bouton Supprimer les cookies dans l'onglet "Cookies"
  • clique sur le bouton Vider le cache dans l'onglet "Cache"
  • clique sur le bouton Ok pour fermer la fenêtre des options et valider tes choix.

Étape 4:

 

Lance AVG Anti-Spyware en double-cliquant sur son icône.

 

IMPORTANT:ne lance aucun autre programme pendant qu' AVG Anti-Spyware scanne le pc.

  • Sélectionne le menu "Analyse" puis sous l'onglet "Analyser", choisis "Analyse complête du système".
  • AVG Anti-Spyware va scanner ton (tes) disque dur(s).Le scan prendra un certain temps, donc sois patient.
  • Une fois le scan terminé,en bas de page, assure toi de voir "Quarantaine" 'à droite de "Configurer tous les", sinon fais ce choix manuellement. (c'est important!)
  • Clique sur le bouton "Appliquer toutes les actions".
  • Maintenant clique sur "Enregistrer le rapport" puis "Enregistrer le rapport sous" et choisis le Bureau.

Étape 5:

 

Redémarre normalement et stp poste :

 

- le rapport de Avg AS

- un rapport hijackthis fait comme ceci >

 

Lance HijackThis.

Clique sur Open Misc Tools Section

Assure toi que les deux cases de droite sont bien cochées:

* List all minor sections(Full)

* List Empty Sections(Complete)

Clique sur Generate StartupList Log

Click sur "oui" lorsque l'on te le demande.

Cela va générer un rapport,copie le et poste le ici.

 

- Poste le rapport qui se trouve dans le dossier WinPFind3u( c'est un rapport qui a pour nom la date du jour\mois\année\heure).

- Relance WinPFind3u et poste le nouveau rapport.

 

Voilà, ca fait 4 rapports!fais deux messages pour poster les rapports s'il le faut :P

Modifié par charles ingals
Posté(e)

N'étant pas là ce week-end, j'ai un peu tardé !

 

La procédure s'est déroulée sans aucun accroc.

 

Voici les rapports AVG AS, Hijackthis, et WinPFind3U (avant et après) :

 

 

 

Rapport AVG AS :

 

---------------------------------------------------------

AVG Anti-Spyware - Rapport d'analyse

---------------------------------------------------------

 

+ Créé à: 19:01:59 13/05/2007

 

+ Résultat de l'analyse:

 

 

 

C:\Documents and Settings\admin\Bureau\WinPFind3u\MovedFiles\WINNT\system32\drivers\core.sys -> Rootkit.Agent.eq : Nettoyé et sauvegardé (mise en quarantaine).

 

 

Fin du rapport

 

---------------------------------------------------------

 

Rapport Hijackthis :

 

StartupList report, 13/05/2007, 19:09:42

StartupList version: 1.52.2

Started from : E:\Program Files\HiJackThis\HijackThis.EXE

Detected: Windows 2000 SP4 (WinNT 5.00.2195)

Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)

* Using default options

* Including empty and uninteresting sections

* Showing rarely important sections

==================================================

 

Running processes:

 

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe

E:\PROGRA~1\AVGANT~1\avgamsvr.exe

E:\PROGRA~1\AVGANT~1\avgupsvc.exe

E:\PROGRA~1\AVGANT~1\avgemc.exe

C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\system32\ZoneLabs\vsmon.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\Explorer.EXE

E:\PROGRA~1\AVGANT~1\avgcc.exe

C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

E:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\iPod\bin\iPodService.exe

E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe

E:\program files\quicktime\qttask.exe

C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

E:\Program Files\OutClock\OutClock.exe

E:\Program Files\HiJackThis\HijackThis.exe

 

--------------------------------------------------

 

Listing of startup folders:

 

Shell folders Startup:

[C:\Documents and Settings\admin\Menu Démarrer\Programmes\Démarrage]

OutClock (2).lnk = E:\Program Files\OutClock\OutClock.exe

 

Shell folders AltStartup:

*Folder not found*

 

User shell folders Startup:

*Folder not found*

 

User shell folders AltStartup:

*Folder not found*

 

Shell folders Common Startup:

[C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage]

*No files*

 

Shell folders Common AltStartup:

*Folder not found*

 

User shell folders Common Startup:

*Folder not found*

 

User shell folders Alternate Common Startup:

*Folder not found*

 

--------------------------------------------------

 

Checking Windows NT UserInit:

 

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

UserInit = C:\WINNT\system32\userinit.exe,

 

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]

*Registry key not found*

 

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

*Registry value not found*

 

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

 

Synchronization Manager = mobsync.exe /logon

AVG7_CC = E:\PROGRA~1\AVGANT~1\avgcc.exe /STARTUP

MoneyStartUp10.0 = "E:\Program Files\Money\System\Activation.exe"

LVCOMS = C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE

Scan Detector = E:\PROGRA~1\PRIMAX\POWERT~1\Pmxdetect.exe

TkBellExe = "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

iTunesHelper = "E:\Program Files\iTunes\iTunesHelper.exe"

vptray = C:\Program Files\NavNT\vptray.exe

SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

Zone Labs Client = E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

!AVG Anti-Spyware = "E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe" /minimized

QuickTime Task = "E:\program files\quicktime\qttask.exe" -atboottime

SpybotSnD = "E:\Program Files\Spybot\SpybotSD.exe" /autocheck /autofix

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

 

swg = C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

 

--------------------------------------------------

 

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

 

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

 

*No values found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

 

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

 

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

 

[OptionalComponents]

*No values found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No subkeys found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries in Registry subkeys of:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

 

--------------------------------------------------

 

File association entry for .EXE:

HKEY_CLASSES_ROOT\exefile\shell\open\command

 

(Default) = "%1" %*

 

--------------------------------------------------

 

File association entry for .COM:

HKEY_CLASSES_ROOT\comfile\shell\open\command

 

(Default) = "%1" %*

 

--------------------------------------------------

 

File association entry for .BAT:

HKEY_CLASSES_ROOT\batfile\shell\open\command

 

(Default) = "%1" %*

 

--------------------------------------------------

 

File association entry for .PIF:

HKEY_CLASSES_ROOT\piffile\shell\open\command

 

(Default) = "%1" %*

 

--------------------------------------------------

 

File association entry for .SCR:

HKEY_CLASSES_ROOT\scrfile\shell\open\command

 

(Default) = "%1" /S

 

--------------------------------------------------

 

File association entry for .HTA:

HKEY_CLASSES_ROOT\htafile\shell\open\command

 

(Default) = C:\WINNT\System32\mshta.exe "%1" %*

 

--------------------------------------------------

 

File association entry for .TXT:

HKEY_CLASSES_ROOT\txtfile\shell\open\command

 

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

 

--------------------------------------------------

 

Enumerating Active Setup stub paths:

HKLM\Software\Microsoft\Active Setup\Installed Components

(* = disabled by HKCU twin)

 

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]

StubPath = C:\WINNT\inf\unregmp2.exe /ShowWMP

 

[>{26923b43-4d38-484f-9b9e-de460746276c}]

StubPath = "C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigIE

 

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *

StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

 

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]

StubPath = "C:\WINNT\System32\shmgrate.exe" OCInstallUserConfigOE

 

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *

StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

 

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *

StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

 

[{6A5110B5-E14B-4268-A065-EF89FF33C325}] *

StubPath = regsvr32.exe /s /n /i:"S 2 true 3 true 4 true 5 true 6 true 7 true" initpki.dll

 

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *

StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\wmp.inf,PerUserStub

 

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *

StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

 

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *

StubPath = regsvr32.exe /s /n /i:U shell32.dll

 

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *

StubPath = %SystemRoot%\System32\ie4uinit.exe

 

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *

StubPath = %SystemRoot%\System32\updcrl.exe -e -u %SystemRoot%\System32\verisignpub1.crl

 

--------------------------------------------------

 

Enumerating ICQ Agent Autostart apps:

HKCU\Software\Mirabilis\ICQ\Agent\Apps

 

*Registry key not found*

 

--------------------------------------------------

 

Load/Run keys from C:\WINNT\WIN.INI:

 

load=*INI section not found*

run=*INI section not found*

 

Load/Run keys from Registry:

 

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*

HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*

HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*

HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*

HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*

HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*

HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*

HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*

HKCU\..\Windows NT\CurrentVersion\Windows: load=

HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*

HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*

HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*

HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

 

--------------------------------------------------

 

Shell & screensaver key from C:\WINNT\SYSTEM.INI:

 

Shell=*INI section not found*

SCRNSAVE.EXE=*INI section not found*

drivers=*INI section not found*

 

Shell & screensaver key from Registry:

 

Shell=Explorer.exe

SCRNSAVE.EXE=*Registry value not found*

drivers=*Registry value not found*

 

Policies Shell key:

 

HKCU\..\Policies: Shell=*Registry value not found*

HKLM\..\Policies: Shell=*Registry value not found*

 

--------------------------------------------------

 

Checking for EXPLORER.EXE instances:

 

C:\WINNT\Explorer.exe: PRESENT!

 

C:\Explorer.exe: not present

C:\WINNT\Explorer\Explorer.exe: not present

C:\WINNT\System\Explorer.exe: not present

C:\WINNT\System32\Explorer.exe: not present

C:\WINNT\Command\Explorer.exe: not present

C:\WINNT\Fonts\Explorer.exe: not present

 

--------------------------------------------------

 

Checking for superhidden extensions:

 

.lnk: HIDDEN! (arrow overlay: yes)

.pif: HIDDEN! (arrow overlay: yes)

.exe: not hidden

.com: not hidden

.bat: not hidden

.hta: not hidden

.scr: not hidden

.shs: HIDDEN!

.shb: HIDDEN!

.vbs: not hidden

.vbe: not hidden

.wsh: not hidden

.scf: HIDDEN! (arrow overlay: NO!)

.url: HIDDEN! (arrow overlay: yes)

.js: not hidden

.jse: not hidden

 

--------------------------------------------------

 

Verifying REGEDIT.EXE integrity:

 

- Regedit.exe found in C:\WINNT

- .reg open command is normal (regedit.exe %1)

- Regedit.exe has no CompanyName property! It is either missing or named something else.

- Regedit.exe has no OriginalFilename property! It is either missing or named something else.

- Regedit.exe has no FileDescription property! It is either missing or named something else.

 

Registry check failed!

 

--------------------------------------------------

 

Enumerating Browser Helper Objects:

 

(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

e-Carte Bleue Browser Helper Object - C:\WINNT\system32\BhoECart.dll - {2E03C0FD-4C48-43A7-9A54-00240C70FF16}

(no name) - E:\PROGRA~1\Spybot\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}

(no name) - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

(no name) - c:\program files\google\googletoolbar3.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}

(no name) - E:\Program Files\Money\System\mnyviewer.dll - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC}

 

--------------------------------------------------

 

Enumerating Task Scheduler jobs:

 

*No jobs found*

 

--------------------------------------------------

 

Enumerating Download Program Files:

 

[DirectAnimation Java Classes]

CODEBASE = file://C:\WINNT\Java\classes\dajava.cab

OSD = C:\WINNT\Downloaded Program Files\DirectAnimation Java Classes.osd

 

[fdjeux]

CODEBASE = https://www.fdjeux.net/classes/fdjeux.cab

OSD = C:\WINNT\Downloaded Program Files\fdjeux.osd

 

[Microsoft XML Parser for Java]

CODEBASE = file://C:\WINNT\Java\classes\xmldso.cab

OSD = C:\WINNT\Downloaded Program Files\Microsoft XML Parser for Java.osd

 

[teleir_cert]

CODEBASE = https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab

OSD = C:\WINNT\Downloaded Program Files\teleir_cert.osd

 

[{33564D57-0000-0010-8000-00AA00389B71}]

CODEBASE = http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB

 

[Java Plug-in]

InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

 

[ActiveScan Installer Class]

InProcServer32 = C:\WINNT\Downloaded Program Files\asinst.dll

CODEBASE = http://acs.pandasoftware.com/activescan/as5free/asinst.cab

 

[Java Plug-in]

InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

 

[Java Plug-in 1.5.0_06]

InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll

CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

 

[shockwave Flash Object]

InProcServer32 = C:\WINNT\system32\Macromed\Flash\Flash8b.ocx

CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab

 

--------------------------------------------------

 

Enumerating Winsock LSP files:

 

NameSpace #1: C:\WINNT\System32\rnr20.dll

NameSpace #2: C:\WINNT\System32\winrnr.dll

Protocol #1: C:\WINNT\system32\msafd.dll

Protocol #2: C:\WINNT\system32\msafd.dll

Protocol #3: C:\WINNT\system32\msafd.dll

Protocol #4: C:\WINNT\system32\rsvpsp.dll

Protocol #5: C:\WINNT\system32\rsvpsp.dll

Protocol #6: C:\WINNT\system32\msafd.dll

Protocol #7: C:\WINNT\system32\msafd.dll

Protocol #8: C:\WINNT\system32\msafd.dll

Protocol #9: C:\WINNT\system32\msafd.dll

Protocol #10: C:\WINNT\system32\msafd.dll

Protocol #11: C:\WINNT\system32\msafd.dll

Protocol #12: C:\WINNT\system32\msafd.dll

Protocol #13: C:\WINNT\system32\msafd.dll

Protocol #14: C:\WINNT\system32\msafd.dll

Protocol #15: C:\WINNT\system32\msafd.dll

Protocol #16: C:\WINNT\system32\msafd.dll

Protocol #17: C:\WINNT\system32\msafd.dll

 

--------------------------------------------------

 

Enumerating Windows NT/2000/XP services

 

Pilote ACPI Microsoft: System32\DRIVERS\ACPI.sys (system)

Environnement de prise en charge de réseau AFD: \SystemRoot\System32\drivers\afd.sys (autostart)

Avertissement: %SystemRoot%\System32\services.exe (manual start)

Gestion d'applications: %SystemRoot%\system32\services.exe (manual start)

Pilote de média asynchrone RAS: System32\DRIVERS\asyncmac.sys (manual start)

Contrôleur de disque dur IDE/ESDI standard: System32\DRIVERS\atapi.sys (system)

Protocole client ATM ARP: System32\DRIVERS\atmarpc.sys (manual start)

Pilote audio Stub: System32\DRIVERS\audstub.sys (manual start)

AVG Anti-Spyware Driver: \??\E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.sys (system)

AVG Anti-Spyware Guard: E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe (autostart)

AVG7 Alert Manager Server: E:\PROGRA~1\AVGANT~1\avgamsvr.exe (autostart)

AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)

AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsnt.sys (system)

AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)

AVG7 Update Service: E:\PROGRA~1\AVGANT~1\avgupsvc.exe (autostart)

AVG Anti-Spyware Clean Driver: System32\DRIVERS\AvgAsCln.sys (system)

AVG7 Clean Driver: \SystemRoot\System32\Drivers\avgclean.sys (system)

AVG E-mail Scanner: E:\PROGRA~1\AVGANT~1\avgemc.exe (autostart)

AVG Network Redirector: \SystemRoot\System32\Drivers\avgtdi.sys (autostart)

Service de transfert intelligent en arrière-plan: %SystemRoot%\system32\svchost.exe -k BITSgroup (manual start)

Explorateur d'ordinateur: %SystemRoot%\System32\services.exe (autostart)

Décodeur sous-titre fermé: system32\drivers\ccdecode.sys (manual start)

Pilote de CD-ROM: System32\DRIVERS\cdrom.sys (system)

Service d'indexation: C:\WINNT\System32\cisvc.exe (manual start)

Gestionnaire de l'Album: %SystemRoot%\system32\clipsrv.exe (manual start)

core: system32\drivers\core.sys (system)

Pilote Creative SB16/AWE32/AWE64 (WDM): system32\drivers\ctlsb16.sys (manual start)

Client DHCP: %SystemRoot%\System32\services.exe (autostart)

Pilote de disque: System32\DRIVERS\disk.sys (system)

Service d'administration du Gestionnaire de disque logique: %SystemRoot%\System32\dmadmin.exe /com (manual start)

dmboot: System32\drivers\dmboot.sys (disabled)

Pilote de Gestionnaire de disque logique: System32\drivers\dmio.sys (system)

dmload: System32\drivers\dmload.sys (system)

Gestionnaire de disque logique: %SystemRoot%\System32\services.exe (autostart)

Synthé logiciel Microsoft DirectMusic (WDM): system32\drivers\DMusic.sys (manual start)

Client DNS: %SystemRoot%\System32\services.exe (autostart)

Pilote de carte 3Com EtherLink XL B/C: System32\DRIVERS\el90xbc5.sys (manual start)

EPSON Printer Status Agent2: C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe (autostart)

Creative AudioPCI (ES1371,ES1373) (WDM): system32\drivers\es1371mp.sys (manual start)

Journal des événements: %SystemRoot%\system32\services.exe (autostart)

Système d'événements de COM+: C:\WINNT\System32\svchost.exe -k netsvcs (manual start)

Service de télécopie: %systemroot%\system32\faxsvc.exe (manual start)

Pilote de contrôleur de lecteur de disquettes: System32\DRIVERS\fdc.sys (manual start)

Pilote de lecteur de disquettes: System32\DRIVERS\flpydisk.sys (manual start)

Pilote du Gestionnaire de volume: System32\DRIVERS\ftdisk.sys (system)

Game Port Enumerator: System32\DRIVERS\gameenum.sys (manual start)

GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)

giveio: \??\C:\WINNT\system32\giveio.sys (system)

Classificateur de paquets générique: System32\DRIVERS\msgpc.sys (manual start)

Google Updater Service: "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" (manual start)

Pilote pour clavier i8042 et souris sur port PS/2: System32\DRIVERS\i8042prt.sys (system)

i81x: System32\DRIVERS\i81xnt5.sys (manual start)

InstallDriver Table Manager: C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe (manual start)

IntelIde: System32\DRIVERS\intelide.sys (system)

Pilote de filtre de trafic IP: System32\DRIVERS\ipfltdrv.sys (manual start)

Pilote de tunnelage IP dans IP: System32\DRIVERS\ipinip.sys (manual start)

Traducteur d'adresses réseau IP: System32\DRIVERS\ipnat.sys (manual start)

iPod Service: C:\Program Files\iPod\bin\iPodService.exe (manual start)

Pilote IPSEC: System32\DRIVERS\ipsec.sys (manual start)

IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)

Pilote de bus Plug-and-Play ISA/EISA: System32\DRIVERS\isapnp.sys (system)

Pilote de la classe Clavier: System32\DRIVERS\kbdclass.sys (system)

Mélangeur audio Wave de noyau Microsoft: system32\drivers\kmixer.sys (manual start)

Serveur: %SystemRoot%\System32\services.exe (autostart)

Station de travail: %SystemRoot%\System32\services.exe (autostart)

Service d'application d'assistance TCP/IP NetBIOS: %SystemRoot%\System32\services.exe (autostart)

LVBulk Service: system32\DRIVERS\LVBulk.sys (manual start)

Affichage des messages: %SystemRoot%\System32\services.exe (disabled)

Partage de Bureau à distance NetMeeting: C:\WINNT\System32\mnmsrvc.exe (manual start)

Périphérique de filtrage de flux Unimodem: system32\drivers\MODEMCSA.sys (manual start)

Pilote de la classe Souris: System32\DRIVERS\mouclass.sys (system)

BDA MPE Filter: system32\DRIVERS\MPE.sys (manual start)

MRXSMB: System32\DRIVERS\mrxsmb.sys (system)

Distributed Transaction Coordinator: C:\WINNT\System32\msdtc.exe (manual start)

Windows Installer: C:\WINNT\System32\MsiExec.exe /V (manual start)

Proxy de service de répartition Microsoft: system32\drivers\MSKSSRV.sys (manual start)

Proxy d'horloge de répartition Microsoft: system32\drivers\MSPCLOCK.sys (manual start)

Proxy de gestion de qualité de répartition Microsoft: system32\drivers\MSPQM.sys (manual start)

Convertisseur en T/site-à-site de répartition Microsoft: system32\drivers\MSTEE.sys (manual start)

NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)

Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)

Pilote TAPI NDIS d'accès à distance: System32\DRIVERS\ndistapi.sys (manual start)

NDIS Protocole mode utilisateur E/S: System32\DRIVERS\ndisuio.sys (manual start)

Pilote réseau étendu NDIS d'accès à distance: System32\DRIVERS\ndiswan.sys (manual start)

Interface NetBIOS: System32\DRIVERS\netbios.sys (system)

NetBIOS sur TCP/IP: System32\DRIVERS\netbt.sys (system)

DDE réseau: %SystemRoot%\system32\netdde.exe (manual start)

DSDM DDE réseau: %SystemRoot%\system32\netdde.exe (manual start)

NetDetect: \SystemRoot\system32\drivers\netdtect.sys (manual start)

Ouverture de session réseau: %SystemRoot%\System32\lsass.exe (autostart)

Connexions réseau: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)

Fournisseur de la prise en charge de sécurité LM NT: %SystemRoot%\System32\lsass.exe (manual start)

Médias amovibles: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)

Pilote de filtre de trafic IPX: System32\DRIVERS\nwlnkflt.sys (manual start)

Pilote de transfert de trafic IPX: System32\DRIVERS\nwlnkfwd.sys (manual start)

Pilote de classe parallèle: System32\DRIVERS\parallel.sys (manual start)

Pilote de port parallèle: System32\DRIVERS\parport.sys (system)

Pilote de bus PCI: System32\DRIVERS\pci.sys (system)

PfModNT: \??\C:\WINNT\system32\PfModNT.sys (autostart)

Logitech ClickSmart 310(PID_0900_V): system32\DRIVERS\LV551AV.sys (manual start)

Plug-and-Play: %SystemRoot%\system32\services.exe (autostart)

USB Flatbed Scanner Driver: system32\DRIVERS\usbscan.sys (manual start)

Agent de stratégie IPSEC: %SystemRoot%\System32\lsass.exe (autostart)

Miniport réseau étendu (PPTP): System32\DRIVERS\raspptp.sys (manual start)

Star Force copy protection driver v4: \SystemRoot\System32\drivers\prodrv04.sys (system)

Emplacement protégé: %SystemRoot%\system32\services.exe (autostart)

Pilote de liaison parallèle directe: System32\DRIVERS\ptilink.sys (manual start)

PxHelp20: System32\Drivers\PxHelp20.sys (system)

Pilote de connexion automatique d'accès distant: System32\DRIVERS\rasacd.sys (system)

Gestionnaire de connexion automatique d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)

Miniport réseau étendu (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)

Gestionnaire de connexions d'accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)

Parallèle direct: System32\DRIVERS\raspti.sys (manual start)

Microsoft Streaming Network Raw Channel Access: system32\drivers\RCA.sys (manual start)

Rdbss: System32\DRIVERS\rdbss.sys (system)

Pilote de filtre de lecture digitale de CD audio: System32\DRIVERS\redbook.sys (system)

Routage et accès distant: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)

Service d'accès à distance au Registre: %SystemRoot%\system32\regsvc.exe (autostart)

Microsoft Legacy Modem Driver: System32\Drivers\RootMdm.sys (manual start)

Localisateur d'appels de procédure distante (RPC): %SystemRoot%\System32\locator.exe (manual start)

Appel de procédure distante (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)

QoS RSVP: %SystemRoot%\System32\rsvp.exe -s (manual start)

Gestionnaire de comptes de sécurité: %SystemRoot%\system32\lsass.exe (autostart)

SB PCI Family Audio Driver (WDM): system32\drivers\sbpci.sys (manual start)

Prise en charge des cartes à puces: %SystemRoot%\System32\SCardSvr.exe (manual start)

Carte à puce: %SystemRoot%\System32\SCardSvr.exe (manual start)

Planificateur de tâches: %SystemRoot%\system32\MSTask.exe (autostart)

Secdrv: \??\C:\WINNT\system32\drivers\SECDRV.SYS (manual start)

Service d'exécution par délégation: %SystemRoot%\system32\services.exe (autostart)

Notification d'événement système: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)

Sentinel: \SystemRoot\System32\Drivers\SENTINEL.SYS (autostart)

Pilote de filtre Serenum: System32\DRIVERS\serenum.sys (manual start)

Pilote de port série: System32\DRIVERS\serial.sys (system)

Partage de connexion Internet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)

BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)

Spouleur d'impression: %SystemRoot%\system32\spoolsv.exe (autostart)

srescan: system32\ZoneLabs\srescan.sys (system)

Srv: System32\DRIVERS\srv.sys (manual start)

Still Image Service: %systemroot%\system32\stisvc.exe (autostart)

BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)

Pilote de bus logiciel: System32\DRIVERS\swenum.sys (manual start)

Synthétiseur de table de sons GC noyau Microsoft: system32\drivers\swmidi.sys (manual start)

Périphérique audio système Microsoft: system32\drivers\sysaudio.sys (manual start)

Journaux et alertes de performance: %SystemRoot%\system32\smlogsvc.exe (manual start)

Téléphonie: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)

Pilote du protocole TCP/IP: System32\DRIVERS\tcpip.sys (system)

Telnet: %SystemRoot%\system32\tlntsvr.exe (manual start)

Client de suivi de lien distribué: %SystemRoot%\system32\services.exe (autostart)

Pilote de contrôleur hôte universel USB Microsoft: System32\DRIVERS\uhcd.sys (manual start)

Pilote de mise à jour microcode: System32\DRIVERS\update.sys (manual start)

Onduleur: %SystemRoot%\System32\ups.exe (manual start)

Pilote de concentrateur standard USB Microsoft: System32\DRIVERS\usbhub.sys (manual start)

Pilote de scanneur USB: System32\DRIVERS\usbscan.sys (manual start)

Pilote de stockage de masse USB: System32\DRIVERS\USBSTOR.SYS (manual start)

Gestionnaire d'utilitaires: %SystemRoot%\System32\UtilMan.exe (manual start)

VgaSave: \SystemRoot\System32\drivers\vga.sys (system)

vsdatant: System32\vsdatant.sys (system)

TrueVector Internet Monitor: C:\WINNT\system32\ZoneLabs\vsmon.exe -service (autostart)

Horloge Windows: %SystemRoot%\System32\services.exe (autostart)

Pilote ARP IP d'accès à distance: System32\DRIVERS\wanarp.sys (manual start)

Pilote WINMM de compatibilité audio WDM Microsoft: system32\drivers\wdmaud.sys (manual start)

Winacpci: system32\DRIVERS\winacpci.sys (manual start)

Infrastructure de gestion Windows: %SystemRoot%\System32\WBEM\WinMgmt.exe (autostart)

Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)

Extensions du pilote WMI: %SystemRoot%\system32\Services.exe (manual start)

World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)

Mises à jour automatiques: %systemroot%\system32\svchost.exe -k wugroup (autostart)

Configuration sans fil: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)

 

 

--------------------------------------------------

 

Enumerating Windows NT logon/logoff scripts:

*No scripts set to run*

 

Windows NT checkdisk command:

BootExecute = autocheck autochk *

 

Windows NT 'Wininit.ini':

PendingFileRenameOperations: *Registry value not found*

 

--------------------------------------------------

 

Enumerating ShellServiceObjectDelayLoad items:

 

Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll

WebCheck: C:\WINNT\System32\webcheck.dll

SysTray: stobject.dll

 

--------------------------------------------------

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

 

*Registry key not found*

 

--------------------------------------------------

 

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

 

*No values found*

 

--------------------------------------------------

 

End of report, 32 177 bytes

Report generated in 0,481 seconds

 

Command line options:

/verbose - to add additional info on each section

/complete - to include empty sections and unsuspicious data

/full - to include several rarely-important sections

/force9x - to include Win9x-only startups even if running on WinNT

/forcent - to include WinNT-only startups even if running on Win9x

/forceall - to include all Win9x and WinNT startups, regardless of platform

/history - to list version history only

 

--------------------------------------------------

 

Rapport WinPFind3U (avant) :

 

[ Extra Files ]

C:\Program Files\Fichiers communs\WhenU\UControlScanAndRemove.ocx unregistered successfully.

C:\Program Files\Fichiers communs\WhenU\UControlScanAndRemove.ocx moved successfully.

File move failed. C:\WINNT\system32\drivers\core.sys scheduled to be moved on reboot.

File move failed. C:\WINNT\system32\drivers\core.cache.dsk scheduled to be moved on reboot.

C:\WINNT\system32\ylnmfqtq.exe moved successfully.

C:\WINNT\system32\bund1 moved successfully.

C:\WINNT\system32\micro1 moved successfully.

C:\WINNT\system32\wnvvmblm.exe moved successfully.

C:\WINNT\system32\cpuxfpd.exe moved successfully.

File/Folder C:\WINNT\system32\mdgx.exe not found.

C:\WINNT\system32\jzhupsp.exe moved successfully.

C:\WINNT\system32\Mc3_Data.cst moved successfully.

C:\WINNT\system32\ijmoq.ini moved successfully.

C:\WINNT\system32\ijmoq.bak1 moved successfully.

C:\WINNT\system32\ijmoq.bak2 moved successfully.

C:\WINNT\system32\hxigu.bat moved successfully.

C:\WINNT\system32\izlh.bat moved successfully.

C:\WINNT\system32\pveps.bat moved successfully.

C:\WINNT\system32\pkta.bat moved successfully.

C:\WINNT\system32\euqbt.bat moved successfully.

C:\WINNT\system32\njswmaj.bat moved successfully.

C:\WINNT\Run32A60.mch moved successfully.

C:\SDFix\apps\Replace moved successfully.

C:\SDFix\apps moved successfully.

C:\SDFix moved successfully.

C:\SmitfraudFix.zip moved successfully.

C:\VundoFix Backups moved successfully.

c:\program files\fichiers communs\WhenU moved successfully.

[Empty Temp Folders]

C:\DOCUME~1\admin\LOCALS~1\Temp\ -> emptied.

C:\Documents and Settings\admin\Local Settings\Temporary Internet Files\Content.IE5\ -> emptied

RecycleBin -> emptied.

< End of log >

Created on 05/13/2007 18:27:09

 

---------------------------------------------------------

 

Rapport WinPFind3U (après) :

 

WinPFind3 logfile created on: 13/05/2007 19:11:46

WinPFind3U by OldTimer - Version 1.0.36 Folder = C:\Documents and Settings\admin\Bureau\WinPFind3u\

Microsoft Windows 2000 Service Pack 4 (Version = 5.0.2195)

Internet Explorer (Version = 6.0.2800.1106)

 

254,23 Mb Total Physical Memory | 72,72 Mb Available Physical Memory | 28,60% Memory free

423,17 Mb Paging File | 195,45 Mb Available in Paging File | 46,19% Paging File free

Paging file location(s): C:\pagefile.sys 192 384;

 

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files

Drive C: | 3,91 Gb Total Space | 1,32 Gb Free Space | 33,70% Space Free

D: Drive not present or media not loaded

Drive E: | 15,11 Gb Total Space | 9,15 Gb Free Space | 60,54% Space Free

F: Drive not present or media not loaded

 

Computer Name: DOC041

Current User Name: admin

Logged in as Administrator.

Current Boot Mode: Normal

 

 

[Processes - Non-Microsoft Only]

avgamsvr.exe -> E:\Program Files\AVG antivirus\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 22/04/2007 18:08:30 | Attr = ]

avgas.exe -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 07/10/2006 14:20:00 | Attr = ]

avgcc.exe -> E:\Program Files\AVG antivirus\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 416256 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

avgemc.exe -> E:\Program Files\AVG antivirus\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 351744 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

avgupsvc.exe -> E:\Program Files\AVG antivirus\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 01/12/2006 19:42:08 | Attr = ]

googletoolbarnotifier.exe -> %ProgramFiles%\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 1, 2, 1128, 5462 | Size = 171448 bytes | Modified Date = 05/04/2007 22:23:04 | Attr = ]

guard.exe -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 28/09/2006 16:13:20 | Attr = ]

ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 331776 bytes | Modified Date = 24/06/2005 16:16:26 | Attr = ]

ituneshelper.exe -> E:\Program Files\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 278528 bytes | Modified Date = 24/06/2005 16:16:42 | Attr = ]

jusched.exe -> %ProgramFiles%\Java\jre1.5.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Modified Date = 10/11/2005 14:03:52 | Attr = ]

lvcoms.exe -> %CommonProgramFiles%\Logitech\QCDriver\LVComS.exe -> Logitech Inc. [Ver = 6.0.0.1208 | Size = 98304 bytes | Modified Date = 24/09/2001 10:39:28 | Attr = ]

outclock.exe -> E:\Program Files\OutClock\OutClock.exe -> Alain TAUBER [Ver = 3.8.9.200 | Size = 2137600 bytes | Modified Date = 03/01/2007 04:09:00 | Attr = ]

pmxdetect.exe -> E:\Program Files\Primax\PowerTWAIN\Pmxdetect.exe -> PRIMAX International BV [Ver = 1.2.1USB | Size = 35328 bytes | Modified Date = 03/11/1998 21:20:10 | Attr = ]

qttask.exe -> E:\program files\quicktime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.3 | Size = 282624 bytes | Modified Date = 01/09/2006 15:57:48 | Attr = ]

realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3427 | Size = 180269 bytes | Modified Date = 13/11/2005 13:25:46 | Attr = ]

sagent2.exe -> %CommonProgramFiles%\EPSON\EBAPI\SAgent2.exe -> SEIKO EPSON CORPORATION [Ver = 1, 2, 0, 0 | Size = 114688 bytes | Modified Date = 17/11/2000 02:02:00 | Attr = ]

vsmon.exe -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 1693464 bytes | Modified Date = 16/03/2006 11:33:12 | Attr = ]

winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.36.0 | Size = 319488 bytes | Modified Date = 08/05/2007 19:48:10 | Attr = ]

zlclient.exe -> E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 755480 bytes | Modified Date = 16/03/2006 11:34:00 | Attr = ]

 

[Win32 Services - Non-Microsoft Only]

(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\guard.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 204800 bytes | Modified Date = 28/09/2006 16:13:20 | Attr = ]

(Avg7Alrt) AVG7 Alert Manager Server [Win32_Own | Auto | Running] -> E:\Program Files\AVG antivirus\avgamsvr.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.453 | Size = 353280 bytes | Modified Date = 22/04/2007 18:08:30 | Attr = ]

(Avg7UpdSvc) AVG7 Update Service [Win32_Own | Auto | Running] -> E:\Program Files\AVG antivirus\avgupsvc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.420 | Size = 49664 bytes | Modified Date = 01/12/2006 19:42:08 | Attr = ]

(AVGEMS) AVG E-mail Scanner [Win32_Own | Auto | Running] -> E:\Program Files\AVG antivirus\avgemc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 351744 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

(dmadmin) Service d'administration du Gestionnaire de disque logique [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> VERITAS Software Corp. [Ver = 2195.6624.297.3 | Size = 147728 bytes | Modified Date = 19/06/2003 12:05:04 | Attr = ]

(EPSONStatusAgent2) EPSON Printer Status Agent2 [Win32_Own | Auto | Running] -> %CommonProgramFiles%\EPSON\EBAPI\SAgent2.exe -> SEIKO EPSON CORPORATION [Ver = 1, 2, 0, 0 | Size = 114688 bytes | Modified Date = 17/11/2000 02:02:00 | Attr = ]

(Fax) Service de télécopie [Win32_Own | On_Demand | Stopped] -> %System32%\faxsvc.exe -> File not found

(gusvc) Google Updater Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Google\Common\Google Updater\GoogleUpdaterService.exe -> Google [Ver = 2.0.734.29932.beta | Size = 138168 bytes | Modified Date = 05/04/2007 22:22:42 | Attr = ]

(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 04/04/2005 01:41:10 | Attr = ]

(iPodService) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 331776 bytes | Modified Date = 24/06/2005 16:16:26 | Attr = ]

(vsmon) TrueVector Internet Monitor [Win32_Own | Auto | Running] -> %System32%\ZoneLabs\vsmon.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 1693464 bytes | Modified Date = 16/03/2006 11:33:12 | Attr = ]

 

[Registry - Non-Microsoft Only]

< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

!AVG Anti-Spyware -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 50 | Size = 6266880 bytes | Modified Date = 07/10/2006 14:20:00 | Attr = ]

AVG7_CC -> E:\Program Files\AVG antivirus\avgcc.exe -> GRISOFT, s.r.o. [Ver = 7.5.0.460 | Size = 416256 bytes | Modified Date = 22/04/2007 18:08:32 | Attr = ]

iTunesHelper -> E:\Program Files\iTunes\iTunesHelper.exe -> Apple Computer, Inc. [Ver = 4.9.0.17 | Size = 278528 bytes | Modified Date = 24/06/2005 16:16:42 | Attr = ]

LVCOMS -> %CommonProgramFiles%\Logitech\QCDriver\LVComS.exe -> Logitech Inc. [Ver = 6.0.0.1208 | Size = 98304 bytes | Modified Date = 24/09/2001 10:39:28 | Attr = ]

QuickTime Task -> E:\program files\quicktime\qttask.exe -> Apple Computer, Inc. [Ver = 7.1.3 | Size = 282624 bytes | Modified Date = 01/09/2006 15:57:48 | Attr = ]

Scan Detector -> E:\Program Files\Primax\PowerTWAIN\Pmxdetect.exe -> PRIMAX International BV [Ver = 1.2.1USB | Size = 35328 bytes | Modified Date = 03/11/1998 21:20:10 | Attr = ]

SpybotSnD -> E:\Program Files\Spybot\SpybotSD.exe -> Safer Networking Limited [Ver = 1.4.0.3 | Size = 4393096 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ]

SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.5.0_06\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 36975 bytes | Modified Date = 10/11/2005 14:03:52 | Attr = ]

TkBellExe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> RealNetworks, Inc. [Ver = 0.1.0.3427 | Size = 180269 bytes | Modified Date = 13/11/2005 13:25:46 | Attr = ]

vptray -> %ProgramFiles%\NavNT\vptray.exe -> File not found

Zone Labs Client -> E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 755480 bytes | Modified Date = 16/03/2006 11:34:00 | Attr = ]

< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\

IMAIL -> Installed = 1 ->

MAPI -> Installed = 1 ->

MSFS -> Installed = 1 ->

< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

swg -> %ProgramFiles%\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe -> Google Inc. [Ver = 1, 2, 1128, 5462 | Size = 171448 bytes | Modified Date = 05/04/2007 22:23:04 | Attr = ]

< User Startup > -> C:\Documents and Settings\admin\Menu Démarrer\Programmes\Démarrage

%UserStartup%\OutClock (2).lnk -> E:\Program Files\OutClock\OutClock.exe -> Alain TAUBER [Ver = 3.8.9.200 | Size = 2137600 bytes | Modified Date = 03/01/2007 04:09:00 | Attr = ]

< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKLM] -> E:\Program Files\AVG antispyware\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> Anti-Malware Development a.s. [Ver = 7, 5, 0, 47 | Size = 73728 bytes | Modified Date = 28/09/2006 16:13:28 | Attr = ]

{E1DAC82B-1C81-41B2-AC1B-6AE2653965E0} [HKLM] -> Reg Data - Key not found [] -> File not found

< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders

< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

NavLogon -> %System32%\NavLogon.dll -> [Ver = | Size = 28672 bytes | Modified Date = 29/10/2000 22:39:52 | Attr = ]

< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\AdminComponent\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->

< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 149 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\CDRAutoRun -> 0 ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 ->

< Software Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\policies\

HKEY_LOCAL_MACHINE\SOFTWARE\policies\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Conferencing\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\MRT\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\UserNameString -> Nom d'utilisateur : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\PasswordString -> Mot de passe : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\DomainString -> Domaine : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\System\DNSclient\\CredentialsString -> Informations d'identification utilisées pour l'enregistrement Dynamique DNS : ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\ -> ->

HKEY_LOCAL_MACHINE\SOFTWARE\policies\Microsoft\Windows\NetCache\ -> ->

< Software Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\policies\

HKEY_CURRENT_USER\Software\Policies\ -> ->

HKEY_CURRENT_USER\Software\Policies\Microsoft\ -> ->

< HOSTS File > (0 bytes) -> C:\WINNT\System32\drivers\etc\Hosts

< Internet Explorer Settings > ->

HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->

HKLM: Main\\Default_Search_URL -> http://www.google.com/ie ->

HKLM: Local Page -> %SystemRoot%\system32\blank.htm ->

HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch ->

HKLM: Start Page -> http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home ->

HKLM: CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->

HKLM: Search\\Default_Search_URL -> http://www.google.com/ie ->

HKLM: SearchAssistant -> http://www.google.com/ie ->

HKLM: URLSearchHooks\\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found

HKCU: Local Page -> C:\WINNT\system32\blank.htm ->

HKCU: Search Bar -> http://www.google.com/ie ->

HKCU: Search Page -> http://www.google.com ->

HKCU: Start Page -> http://www.yahoo.fr/ ->

HKCU: SearchAssistant -> http://www.google.com/ie ->

HKCU: ProxyEnable -> 0 ->

< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> %ProgramFiles%\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [AcroIEHlprObj Class] -> [Ver = 1, 0, 0, 1 | Size = 37808 bytes | Modified Date = 02/03/2001 12:02:04 | Attr = ]

{2E03C0FD-4C48-43A7-9A54-00240C70FF16} [HKLM] -> %System32%\BhoECart.dll [ECarteBleueBrowserHelper Class] -> Orbiscom Ltd. All rights reserved. [Ver = 2, 2, 1, 0, 93 | Size = 69632 bytes | Modified Date = 20/12/2002 10:15:04 | Attr = ]

{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> E:\Program Files\Spybot\SDHelper.dll [] -> Safer Networking Limited [Ver = 1, 4, 0, 0 | Size = 853672 bytes | Modified Date = 31/05/2005 01:04:00 | Attr = ]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [sSVHelper Class] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 10/11/2005 14:22:10 | Attr = ]

{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> %ProgramFiles%\Google\googletoolbar3.dll [Google Toolbar Helper] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 19/01/2007 23:56:04 | Attr = R ]

< Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar

{2318C2B1-4965-11d4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar3.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 19/01/2007 23:56:04 | Attr = R ]

< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\

WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> %ProgramFiles%\Google\googletoolbar3.dll [&Google] -> Google Inc. [Ver = 4, 0, 1601, 4978 | Size = 2436160 bytes | Modified Date = 19/01/2007 23:56:04 | Attr = R ]

< Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.5.0_06\bin\npjpi150_06.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 69746 bytes | Modified Date = 10/11/2005 14:22:10 | Attr = ]

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKCU] -> %ProgramFiles%\Java\jre1.5.0_06\bin\ssv.dll [MenuText: Console Java (Sun)] -> Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 184423 bytes | Modified Date = 10/11/2005 14:22:10 | Attr = ]

{E023F504-0C5A-4750-A1E7-A9046DEA8A21} -> Reg Data - Value does not exist [buttonText: MoneySide] -> File not found

{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -> E:\PROGRA~1\Yahoo\YPager.exe [buttonText: Yahoo! Messenger] -> File not found

< Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\

&Google Search -> Reg Data - Value does not exist -> File not found

Pages liées -> Reg Data - Value does not exist -> File not found

Pages similaires -> Reg Data - Value does not exist -> File not found

Version de la page actuelle disponible dans le cache Google -> Reg Data - Value does not exist -> File not found

< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\

{298F40AB-8F27-4B8D-ACCE-08A6494BF95A} -> () ->

{9796EE23-146F-4F0B-BFF2-B64C320108AA} -> (Contrôleur Fast Ethernet intégré 3Com 3C920 (compatible 3C905C-TX)) ->

< Default Protocols [HKLM] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

shell -> shell protocol not assigned ->

< Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults

shell -> shell protocol not assigned ->

< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\

ipp -> Reg Data - Key not found -> File not found

msdaipp -> Reg Data - Key not found -> File not found

< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\

{33564D57-0000-0010-8000-00AA00389B71} -> - CodeBase = http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB ->

{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab ->

{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -> ActiveScan Installer Class - CodeBase = http://acs.pandasoftware.com/activescan/as5free/asinst.cab ->

{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab ->

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.5.0_06 - CodeBase = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab ->

{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://download.macromedia.com/pub/shockwa...ash/swflash.cab ->

DirectAnimation Java Classes -> - CodeBase = file://C:\WINNT\Java\classes\dajava.cab ->

fdjeux -> - CodeBase = https://www.fdjeux.net/classes/fdjeux.cab ->

Microsoft XML Parser for Java -> - CodeBase = file://C:\WINNT\Java\classes\xmldso.cab ->

teleir_cert -> - CodeBase = https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab ->

 

 

[Files/Folders - Created Within 90 days]

ccsetup131.exe -> %SystemDrive%\ccsetup131.exe -> Piriform Ltd [Ver = 1.31.0.325 | Size = 1458008 bytes | Created Date = 06/04/2007 17:47:54 | Attr = ]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Created Date = 05/04/2007 21:08:00 | Attr = ]

QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 01/05/2007 13:03:19 | Attr = ]

QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 01/05/2007 13:03:19 | Attr = H ]

ActiveScan -> %System32%\ActiveScan -> [Folder | Created Date = 10/05/2007 18:49:17 | Attr = ]

asuninst.exe -> %System32%\asuninst.exe -> Panda Software [Ver = 1, 0, 0, 2 | Size = 73728 bytes | Created Date = 10/05/2007 18:49:51 | Attr = ]

Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Created Date = 10/05/2007 18:49:22 | Attr = ]

pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Created Date = 10/05/2007 18:49:21 | Attr = ]

Perflib_Perfdata_3b0.dat -> %System32%\Perflib_Perfdata_3b0.dat -> [Ver = | Size = 16384 bytes | Created Date = 13/04/2007 09:08:23 | Attr = ]

Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Created Date = 10/05/2007 18:49:22 | Attr = ]

vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 41108 bytes | Created Date = 05/04/2007 21:09:12 | Attr = ]

vsdata.dll -> %System32%\vsdata.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 83736 bytes | Created Date = 05/04/2007 21:08:00 | Attr = ]

vsdatant.sys -> %System32%\vsdatant.sys -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 372824 bytes | Created Date = 05/04/2007 21:09:17 | Attr = ]

vsinit.dll -> %System32%\vsinit.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 141080 bytes | Created Date = 05/04/2007 21:08:00 | Attr = ]

vsmonapi.dll -> %System32%\vsmonapi.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 104216 bytes | Created Date = 05/04/2007 21:09:17 | Attr = ]

vspubapi.dll -> %System32%\vspubapi.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 227096 bytes | Created Date = 05/04/2007 21:09:17 | Attr = ]

vsregexp.dll -> %System32%\vsregexp.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 71448 bytes | Created Date = 05/04/2007 21:09:37 | Attr = ]

vsutil.dll -> %System32%\vsutil.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 382744 bytes | Created Date = 05/04/2007 21:08:00 | Attr = ]

vsxml.dll -> %System32%\vsxml.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 100120 bytes | Created Date = 05/04/2007 21:09:20 | Attr = ]

zlcomm.dll -> %System32%\zlcomm.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 79640 bytes | Created Date = 05/04/2007 21:09:30 | Attr = ]

zlcommdb.dll -> %System32%\zlcommdb.dll -> Zone Labs, LLC [Ver = 6.1.744.001 | Size = 71448 bytes | Created Date = 05/04/2007 21:09:30 | Attr = ]

ZoneLabs -> %System32%\ZoneLabs -> [Folder | Created Date = 05/04/2007 21:09:18 | Attr = ]

ZPORT4AS.dll -> %System32%\ZPORT4AS.dll -> [Ver = | Size = 11776 bytes | Created Date = 10/05/2007 18:49:51 | Attr = ]

dvdplay.exe -> %System32%\dllcache\dvdplay.exe -> [Ver = 1, 0, 0, 1 | Size = 124688 bytes | Created Date = 01/04/2007 20:07:13 | Attr = ]

AvgAsCln.sys -> %System32%\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 3968 bytes | Created Date = 16/04/2007 20:43:56 | Attr = ]

 

[Files/Folders - Modified Within 90 days]

$VAULT$.AVG -> %SystemDrive%\$VAULT$.AVG -> [Folder | Modified Date = 07/05/2007 21:11:54 | Attr = RH ]

ccsetup131.exe -> %SystemDrive%\ccsetup131.exe -> Piriform Ltd [Ver = 1.31.0.325 | Size = 1458008 bytes | Modified Date = 06/04/2007 08:46:46 | Attr = ]

My Music -> %SystemDrive%\My Music -> [Folder | Modified Date = 01/05/2007 14:02:46 | Attr = ]

Program Files -> %ProgramFiles% -> [Folder | Modified Date = 13/05/2007 18:29:48 | Attr = R ]

WINNT -> %SystemRoot% -> [Folder | Modified Date = 13/05/2007 19:02:42 | Attr = ]

A6W.INI -> %SystemRoot%\A6W.INI -> [Ver = | Size = 35 bytes | Modified Date = 10/05/2007 17:45:28 | Attr = ]

A6W_DATA -> %SystemRoot%\A6W_DATA -> [Folder | Modified Date = 10/05/2007 18:01:06 | Attr = ]

AppPatch -> %SystemRoot%\AppPatch -> [Folder | Modified Date = 10/05/2007 20:08:56 | Attr = ]

CSC -> %SystemRoot%\CSC -> [Folder | Modified Date = 08/05/2007 18:39:02 | Attr = HS]

Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 13/05/2007 19:05:18 | Attr = ]

Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 10/05/2007 20:09:22 | Attr = S]

inf -> %SystemRoot%\inf -> [Folder | Modified Date = 10/05/2007 19:49:58 | Attr = H ]

Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 01/05/2007 18:22:34 | Attr = HS]

Internet Logs -> %SystemRoot%\Internet Logs -> [Folder | Modified Date = 13/05/2007 17:46:52 | Attr = ]

Minidump -> %SystemRoot%\Minidump -> [Folder | Modified Date = 07/05/2007 22:24:26 | Attr = ]

pmxpower.INI -> %SystemRoot%\pmxpower.INI -> [Ver = | Size = 73 bytes | Modified Date = 17/04/2007 23:16:48 | Attr = ]

QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 01/05/2007 14:04:20 | Attr = ]

QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 07/05/2007 22:40:56 | Attr = H ]

Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 10/05/2007 20:14:32 | Attr = ]

security -> %SystemRoot%\security -> [Folder | Modified Date = 13/05/2007 18:27:34 | Attr = ]

system -> %SystemRoot%\system -> [Folder | Modified Date = 13/05/2007 18:29:48 | Attr = ]

system32 -> %System32% -> [Folder | Modified Date = 13/05/2007 19:04:54 | Attr = ]

Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 13/05/2007 19:04:32 | Attr = ]

win.ini -> %SystemRoot%\win.ini -> [Ver = | Size = 931 bytes | Modified Date = 10/05/2007 19:53:04 | Attr = ]

wininit.ini -> %SystemRoot%\wininit.ini -> [Ver = | Size = 229 bytes | Modified Date = 02/04/2007 18:49:20 | Attr = ]

SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 13/05/2007 19:04:22 | Attr = H ]

ActiveScan -> %System32%\ActiveScan -> [Folder | Modified Date = 10/05/2007 20:16:40 | Attr = ]

config -> %System32%\config -> [Folder | Modified Date = 10/05/2007 20:17:14 | Attr = ]

d3d9caps.dat -> %System32%\d3d9caps.dat -> [Ver = | Size = 1204 bytes | Modified Date = 07/05/2007 23:43:04 | Attr = ]

dllcache -> %System32%\dllcache -> [Folder | Modified Date = 23/04/2007 18:41:24 | Attr = RHS]

drivers -> %System32%\drivers -> [Folder | Modified Date = 13/05/2007 18:28:04 | Attr = ]

Help.ico -> %System32%\Help.ico -> [Ver = | Size = 1406 bytes | Modified Date = 10/05/2007 19:49:24 | Attr = ]

NtmsData -> %System32%\NtmsData -> [Folder | Modified Date = 13/05/2007 19:05:16 | Attr = ]

pavas.ico -> %System32%\pavas.ico -> [Ver = | Size = 30590 bytes | Modified Date = 10/05/2007 19:49:24 | Attr = ]

Perflib_Perfdata_3b0.dat -> %System32%\Perflib_Perfdata_3b0.dat -> [Ver = | Size = 16384 bytes | Modified Date = 13/04/2007 10:08:28 | Attr = ]

QuickTime.qtp -> %System32%\QuickTime.qtp -> [Ver = | Size = 63253 bytes | Modified Date = 01/05/2007 14:04:12 | Attr = ]

Uninstall.ico -> %System32%\Uninstall.ico -> [Ver = | Size = 2550 bytes | Modified Date = 10/05/2007 19:49:24 | Attr = ]

vsconfig.xml -> %System32%\vsconfig.xml -> [Ver = | Size = 41108 bytes | Modified Date = 13/05/2007 19:05:08 | Attr = ]

wbem -> %System32%\wbem -> [Folder | Modified Date = 10/05/2007 20:21:28 | Attr = ]

zllictbl.dat -> %System32%\zllictbl.dat -> [Ver = | Size = 4212 bytes | Modified Date = 05/04/2007 22:12:22 | Attr = H ]

ZoneLabs -> %System32%\ZoneLabs -> [Folder | Modified Date = 10/05/2007 20:21:42 | Attr = ]

avg7core.sys -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 27/04/2007 18:15:40 | Attr = ]

avg7rsnt.sys -> %System32%\drivers\avg7rsnt.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 26944 bytes | Modified Date = 24/02/2007 19:08:08 | Attr = ]

avg7rsxp.sys -> %System32%\drivers\avg7rsxp.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.442 | Size = 27776 bytes | Modified Date = 24/02/2007 19:08:08 | Attr = ]

 

[File String Scan - Non-Microsoft Only]

Thawte Consulting , -> %SystemDrive%\ccsetup131.exe -> Piriform Ltd [Ver = 1.31.0.325 | Size = 1458008 bytes | Modified Date = 06/04/2007 08:46:46 | Attr = ]

winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 07/12/1999 15:00:00 | Attr = ]

UPX! , FSG! , PEC2 , aspack , -> %System32%\drivers\avg7core.sys -> GRISOFT, s.r.o. [Ver = 7.5.0.467 | Size = 777984 bytes | Modified Date = 27/04/2007 18:15:40 | Attr = ]

PEC2 , -> %System32%\drivers\winacpci.sys -> Conexant [Ver = 2.1.2.164.010 | Size = 900528 bytes | Modified Date = 03/11/1999 18:26:50 | Attr = ]

 

< End of report >

 

 

Voilà.

Et encore merci de votre aide

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...