Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

[Résolu]Mon pc est infecté !!


Messages recommandés

Hi all,

 

Mon pc depuis quelques jours avait quelques problèmes, parmis lesquels:

1) 9/10 pendant mes surfs, je me trouvais avec des pages blanches, les sites ne s'affichaient pas

2) Une lenteur à tomber par terre et des plantages à répétition.

 

Voyant ceci, j'ai lancé un scan avec CounterSpy. Il avait détecté un trojan (appelé Trojan-Drooper si mes souvenirs sont bons). Dans le repertoire WINDOWS, le fichier mise en cause s'appelait update.exe. En le lançant, 3 autres fichiers sont apparus dans ce repertoire: zzzip.exe, rrrar.exe et cmd.exe. En fesant un CTRL ALT SUP, j'avais 3 fois zzzip.exe, 3 fois rrrar.exe et 6 fois cmd.exe. CounterSpy m'a bien effacé le update.exe mais le problème subsiste. Il y a une heure, ces 3 fichiers ont réapparu.

Voilà le résultat du scan de HijackThis:

 

Logfile of HijackThis v1.99.1

Scan saved at 20:11:41, on 25/05/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16441)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Program Files\Comodo\Firewall\cmdagent.exe

C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

C:\Program Files\BinarySense\HDDlife 3\hldasvc.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Comodo\Firewall\cpf.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\MSN Messenger\usnsvc.exe

C:\Program Files\MSN Messenger\livecall.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7Pro\IE7Pro.dll

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7Pro\IE7Pro.dll

O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7Pro\IE7Pro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll

O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll

O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Girafa - {78A7D3B4-23E3-11D4-A682-0050DA502650} - C:\Program Files\Girafa\GirafaBar.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1009841170265

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.touslesdrivers.com/fichiers/har...on.cab?version=

O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL

O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - "C:\Program Files\BinarySense\HDDlife 3\hlAPP.dll" (file missing)

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: HDDlife HDD Access service - BinarySense, Ltd. - C:\Program Files\BinarySense\HDDlife 3\hldasvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InstallShield Licensing Service - Macrovision - C:\Program Files\Fichiers communs\InstallShield Shared\Service\InstallShield Licensing Service.exe

O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe

O23 - Service: O&O CleverCache Agent (OOCleverCacheAgent) - O&O Software GmbH - C:\Program Files\OO Software\CleverCache\ooccag.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

O23 - Service: Windows Driver Framework - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

 

Voilà, je vous remercie par avance pour l'aide (En regardant ce log, je ne pense pas être infecté mais je suis sûr que je le suis encore)

 

Edit: Je viens à l'instant d'inspecter mon repertoire WINDOWS: Update.exe ainsi que zzzip.exe sont revenus malgrès le nettoyage de CounterSpy.

Modifié par Av3n4s
Lien vers le commentaire
Partager sur d’autres sites

re,

 

Si durant la procédure ci-dessous, il y a des étapes que tu n'as pas reussi a faire, merci de continuer la procédure jusqu'au bout et de les signaler dans ta prochaine reponse.

 

Je te conseille d'enregistrer la page web compléte sous Internet Explorer comme ceci :

 

* Clique sur Fichier/Enregistrer sous Dans Type, choisis : Archive web (fichier seul (*.mht) / Enregistre la sur le bureau,comme cela tu retrouvera la mise en forme ou imprime cette réponse. Une partie de la désinfection se déroulera en mode sans échec.

 

 

1/ Lance AVG AS puis clique sur Mise à jour

Ferme le programme.

 

 

 

2/Démarre en mode sans échec http://www.sosordi.net/Faq/Faq.2.html

 

 

3/fais:

demarer executer services.msc repere Windows Driver Framework

 

Double clic dessus :dans le champs Statut du service met le sur arrêté

dans le champs Type de démarrage met le sur désactivé puis

Appliquer puis ok .

 

 

4/

Démarrer/panneau de configuration/ajout et suppression de programmes et vérifie la présence de:

 

Girafa

 

Si ce programme est présent désinstalle-le.

 

 

5/Lance hijackthis en cliquant sur do a scan system only et coche ces lignes:

 

O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)

O9 - Extra button: Girafa - {78A7D3B4-23E3-11D4-A682-0050DA502650} - C:\Program Files\Girafa\GirafaBar.dll

 

Ferme toutes les fenêtres ouvertes sauf Hijackthis et clique sur fix checked

 

 

6/pour supprimer les fichiers nefastes on va tous les afficher en faisant comme ceci:

 

Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :

Cocher la case : Afficher les fichiers et dossiers cachés

 

Décocher la case : Masquer les extensions des fichiers dont le type est connu

 

Décocher la case : Masquer les fichiers protégés du système d'exploitation

 

cliquer sur "Appliquer"

 

cliquer sur le bouton "Appliquer à tous les dossiers" / OK

 

7/Supprime ce qui est en gras:

 

C:\Program Files\ Girafa<== tout le dossier

 

 

8/ Relance AVG AS puis choisis l'onglet Analyse

Puis l'onglet Paramètres

Sous la question Comment réagir ?, clique sur Actions recommandées et choisis Quarantaine

Reclique sur l'onglet Analyse puis réalise une Analyse complète du système

 

Si un fichier infecté est détecté en fin d'analyse

Clique sur Appliquer toutes les actions

 

Clique sur Enregistrer le rapport puis sur Enregistrer le rapport sous

Enregistre ce fichier texte sur ton bureau

 

 

9/Redémarre en mode normal

 

10/Poste le rapport d'AVG Anti spyware 7.5 ainsi qu'un nouveau log Hijackthis.

 

Bon courage, et si tu as la moindre question n'hésite surtout pas :P

 

@+

Lien vers le commentaire
Partager sur d’autres sites

Voici les 2 logs demandés:

 

1) Log AVG:

 

---------------------------------------------------------

AVG Anti-Spyware - Rapport d'analyse

---------------------------------------------------------

 

+ Créé à: 22:40:31 26/05/2007

 

+ Résultat de l'analyse:

 

 

 

 

C:\Documents and Settings\Dolc3\Bureau\SetupSwishpix15_FRA_Teaser\Main\ScreenSaver.scr -> Heuristic.Win32.Dialer : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Adbrite : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Adtech : Nettoyé.

:mozilla.48:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.

:mozilla.49:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.

:mozilla.50:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Advertising : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Bluestreak : Nettoyé.

:mozilla.24:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Doubleclick : Nettoyé.

:mozilla.59:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.

:mozilla.60:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.

:mozilla.61:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.

:mozilla.27:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.

:mozilla.28:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.

:mozilla.29:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.

:mozilla.25:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Ivwbox : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Live : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Nettoyé.

:mozilla.26:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé.

:mozilla.30:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Nettoyé.

:mozilla.53:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.

:mozilla.54:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.

:mozilla.55:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Smartadserver : Nettoyé.

:mozilla.62:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.

:mozilla.63:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.

:mozilla.64:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.

:mozilla.65:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.

:mozilla.66:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Tradedoubler : Nettoyé.

C:\Documents and Settings\ILYES\Cookies\[email protected][2].txt -> TrackingCookie.Tradedoubler : Nettoyé.

:mozilla.52:C:\Documents and Settings\Dolc3\Application Data\Mozilla\Firefox\Profiles\3z83n8rv.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Weborama : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Webtrends : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Nettoyé.

C:\Documents and Settings\Dolc3\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Nettoyé.

 

 

Fin du rapport

 

2) Log HiJackThis:

 

Logfile of HijackThis v1.99.1

Scan saved at 22:58:47, on 26/05/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16441)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Program Files\Comodo\Firewall\cmdagent.exe

C:\Program Files\BinarySense\HDDlife 3\hldasvc.exe

C:\WINDOWS\system32\msiexec.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\wwSecure.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\HijackThis\HijackThis.exe

C:\Program Files\MSN Messenger\livecall.exe

C:\Program Files\MSN Messenger\usnsvc.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: IE7pro - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IE7Pro\IE7Pro.dll

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [gfxtray] rundll32 ctccw32.dll,findwnd

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7Pro\IE7Pro.dll

O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7Pro\IE7Pro.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll

O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll

O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB

O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.2.100.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1009841170265

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://www.touslesdrivers.com/fichiers/har...on.cab?version=

O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL

O18 - Protocol: hddlife - {BD758015-47D9-477A-8873-4B688A2BC0E2} - "C:\Program Files\BinarySense\HDDlife 3\hlAPP.dll" (file missing)

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)

O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe

O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: HDDlife HDD Access service - BinarySense, Ltd. - C:\Program Files\BinarySense\HDDlife 3\hldasvc.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InstallShield Licensing Service - Macrovision - C:\Program Files\Fichiers communs\InstallShield Shared\Service\InstallShield Licensing Service.exe

O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe

O23 - Service: O&O CleverCache Agent (OOCleverCacheAgent) - O&O Software GmbH - C:\Program Files\OO Software\CleverCache\ooccag.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

 

 

Edit

 

Le nettoyage n'a rien arrangé. Il m'est encore impossible de naviguer. Les pages sont toujours blanches. Après vérification, les fichiers update.exe, zzzip.exe, rrrar.exe viennent d'apparaître dans le dossier WINDOWS. De plus dès que j'active mon firewall, j'arrive à naviguer. Les pages ne sont plus blanches.

Modifié par Av3n4s
Lien vers le commentaire
Partager sur d’autres sites

Re,

 

1. Télécharge combofix.exe (par sUBs) ici :

 

http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

 

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

sur ton Bureau.

 

2. Double clique combofix.exe et suis les invites.

3. Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

Lien vers le commentaire
Partager sur d’autres sites

Re,

 

1. Télécharge combofix.exe (par sUBs) ici :

 

http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

 

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

sur ton Bureau.

 

2. Double clique combofix.exe et suis les invites.

3. Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

 

 

Tout cela en mode sans echec ?

Lien vers le commentaire
Partager sur d’autres sites

Tout cela en mode sans echec ?

 

 

Voici le résultat du scan fait en mode sans echec:

 

"Dolc3" - 2007-05-27 11:49:41 Service Pack 2 [sAFE MODE]

ComboFix 07-05.27.V - Running from: "C:\Documents and Settings\Dolc3\Bureau\"

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-04-27 to 2007-05-27 ))))))))))))))))))))))))))))))))))

 

 

2007-05-26 12:28 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\IE7Pro

2007-05-25 22:13 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-05-25 14:33 5,888 --------- C:\WINDOWS\system32\drivers\imagedrv.sys

2007-05-25 14:33 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll

2007-05-25 14:33 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll

2007-05-25 14:33 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll

2007-05-25 14:33 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll

2007-05-25 14:33 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe

2007-05-25 14:33 127,488 --------- C:\WINDOWS\system32\drivers\imagesrv.sys

2007-05-25 14:33 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll

2007-05-25 14:33 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll

2007-05-24 14:43 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys

2007-05-24 13:44 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy

2007-05-24 00:00 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2007-05-24 00:00 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2007-05-24 00:00 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys

2007-05-23 23:46 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak

2007-05-23 20:45 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\Comodo

2007-05-23 16:14 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Comodo

2007-05-23 16:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo

2007-05-23 13:18 <REP> d-------- C:\Program Files\Comodo

2007-05-23 11:05 <REP> d-------- C:\Program Files\The_Jolly_Roger

2007-05-23 06:58 82,258 --a------ C:\WINDOWS\system32\drivers\klin.dat

2007-05-23 06:58 82,258 --a------ C:\WINDOWS\system32\drivers\klick.dat

2007-05-23 06:57 98,592 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat

2007-05-23 06:57 7,241,504 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat

2007-05-23 06:46 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files

2007-05-22 18:43 <REP> d-------- C:\Program Files\Dictionnaire Fran‡ais

2007-05-22 18:42 0 -rahs---- C:\MSDOS.SYS

2007-05-22 18:42 0 -rahs---- C:\IO.SYS

2007-05-21 22:59 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Abexo

2007-05-21 21:54 0 --a------ C:\WINDOWS\system32\SBRC.dat

2007-05-21 21:54 0 --a------ C:\WINDOWS\system32\SBFC.dat

2007-05-21 20:02 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\Thunderbird

2007-05-21 17:24 <REP> d-------- C:\DOCUME~1\ILYES\Bureau

2007-05-21 10:01 257 --a------ C:\WINDOWS\msdres.bin

2007-05-21 10:00 25,600 --a------ C:\WINDOWS\system32\ctccw32.dll

2007-05-21 09:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip

2007-05-21 00:52 <REP> d-------- C:\Programmi

2007-05-20 23:55 <REP> d-------- C:\Program Files\Dictionnaire

2007-05-20 16:16 <REP> d-------- C:\Program Files\Hard Disk Sentinel

2007-05-20 14:52 <REP> d-------- C:\Program Files\WinPcap

2007-05-20 14:35 <REP> d-------- C:\Program Files\regshot1_7_2

2007-05-20 14:16 <REP> d-------- C:\DOCUME~1\ALLUSE~1\ModÙ¹les

2007-05-20 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared

2007-05-20 13:09 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet

2007-05-20 08:39 <REP> d-------- C:\Program Files\NewsSearcher

2007-05-20 07:24 <REP> d-------- C:\Program Files\Generalia Multimedia

2007-05-20 06:45 <REP> d-------- C:\Program Files\IDA Freeware 4.3

2007-05-20 04:07 <REP> d-------- C:\Program Files\ISTool

2007-05-20 04:07 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\ISTool

2007-05-20 03:55 <REP> d-------- C:\Program Files\Far

2007-05-19 22:37 206,352 --a------ C:\WINDOWS\system32\klogon.dll

2007-05-19 22:36 22,354 --a------ C:\WINDOWS\system32\drivers\klop.dat

2007-05-18 23:27 <REP> d-------- C:\Program Files\TechnoLogismiki

2007-05-18 00:54 <REP> d-------- C:\Program Files\CrazyPixels

2007-05-17 06:19 <REP> d-------- C:\Program Files\inSpeak

2007-05-16 23:37 200 --a------ C:\WINDOWS\QUIC2007.dat

2007-05-16 23:37 <REP> d-------- C:\Program Files\QuickTranslator 2007

2007-05-16 21:47 <REP> d-------- C:\RkUnhooker

2007-05-16 07:22 <REP> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\IE7Pro

2007-05-16 07:21 <REP> d-------- C:\Program Files\Diskeeper Corporation

2007-05-16 07:21 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Diskeeper Corporation

2007-05-16 06:59 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\IE7Pro

2007-05-16 06:56 <REP> d-------- C:\Program Files\IE7Pro

2007-05-16 06:07 <REP> d-------- C:\Program Files\Smart PC Solutions

2007-05-16 03:59 <REP> d-------- C:\Dic01

2007-05-15 04:50 <REP> d-------- C:\Program Files\EmuLe

2007-05-15 04:42 <REP> d-------- C:\WINDOWS\EmuLe

2007-05-15 03:15 <REP> d-------- C:\WINDOWS\Skype

2007-05-14 05:53 <REP> d-------- C:\Program Files\LeechGet 2006

2007-05-13 21:24 10,298 --a------ C:\WINDOWS\CODER.DAT

2007-05-13 21:23 <REP> d-------- C:\EARAB

2007-05-13 21:10 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\DivX

2007-05-13 21:09 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\IDM

2007-05-12 14:22 <REP> d-------- C:\Program Files\Microsoft Bootvis

2007-05-12 06:37 <REP> d-------- C:\Program Files\Teleport Pro

2007-05-12 06:09 <REP> d-------- C:\Program Files\ToniArts

2007-05-12 06:00 <REP> d-------- C:\WINDOWS\Screensaver

2007-05-12 06:00 <REP> d-------- C:\Program Files\Samurize

2007-05-12 01:16 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\IndigoRose

2007-05-12 01:04 <REP> d-------- C:\WINDOWS\Setup Factory 7.0 Trial

2007-05-12 01:04 <REP> d-------- C:\Program Files\Setup Factory 7.0 Trial

2007-05-11 20:52 <REP> d-------- C:\Program Files\1200livres

2007-05-11 18:23 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\DMCache

2007-05-11 17:58 <REP> d-------- C:\Program Files\Úºéê袠، Úºé¬ÚºêéØŒ

2007-05-11 15:18 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Caphyon

2007-05-11 15:15 <REP> d-------- C:\Program Files\Caphyon

2007-05-11 14:28 69,632 --a------ C:\WINDOWS\system32\xmltok.dll

2007-05-11 14:28 36,864 --a------ C:\WINDOWS\system32\xmlparse.dll

2007-05-11 14:28 26,096 --a------ C:\WINDOWS\system32\xmlinst.exe

2007-05-11 14:28 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll

2007-05-11 02:09 1,050,120 --a------ C:\WINDOWS\system32\oodag.exe

2007-05-11 02:08 2,512,392 --a------ C:\WINDOWS\system32\oodtray.exe

2007-05-11 02:08 194,056 --a------ C:\WINDOWS\system32\oodbs.exe

2007-05-11 02:06 542,216 --a------ C:\WINDOWS\system32\oodssrs.dll

2007-05-11 02:06 202,248 --a------ C:\WINDOWS\system32\oodtrrs.dll

2007-05-11 02:06 15,880 --a------ C:\WINDOWS\system32\oodagrs.dll

2007-05-11 02:06 15,880 --a------ C:\WINDOWS\system32\oodagmg.dll

2007-05-11 02:06 10,248 --a------ C:\WINDOWS\system32\oodbsrs.dll

2007-05-11 01:42 1,294,336 --a------ C:\WINDOWS\system32\ooscrsav.scr

2007-05-10 23:19 38,160 --a------ C:\WINDOWS\system32\drivers\oobctm.sys

2007-05-10 23:18 15,368 --a------ C:\WINDOWS\system32\ootmapi.dll

2007-05-10 15:02 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2007-05-09 23:59 <REP> d-------- C:\Program Files\Dorar

2007-05-09 13:45 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Nouveau dossier

2007-05-09 13:43 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\TrojanHunter

2007-05-09 12:31 53,248 --a------ C:\WINDOWS\system32\UNRAR.DLL

2007-05-09 12:31 216,064 --a------ C:\WINDOWS\system32\CP5DLL32.DLL

2007-05-09 12:31 160,256 --a------ C:\WINDOWS\system32\ShrLk21.dll

2007-05-09 12:31 <REP> d-------- C:\Program Files\Anti-Trojan-55

2007-05-09 12:05 302,592 --a------ C:\WINDOWS\unin040c.exe

2007-05-09 01:10 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2

2007-05-08 18:05 <REP> d-------- C:\Documents and Settings\Dolc3\My GCompris

2007-05-08 18:05 <REP> d-------- C:\Documents and Settings\Dolc3\.config

2007-05-08 18:05 <REP> d-------- C:\DOCUME~1\Dolc3\My GCompris

2007-05-08 18:05 <REP> d-------- C:\DOCUME~1\Dolc3\.config

2007-05-08 00:35 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\iolo

2007-05-08 00:04 <REP> d-------- C:\Program Files\iolo

2007-05-07 19:06 118,784 --a------ C:\WINDOWS\system32\CLKERN.DLL

2007-05-07 19:06 <REP> d-------- C:\Program Files\Cracklock

2007-05-07 14:33 <REP> d-------- C:\Program Files\WebAnim‚

2007-05-07 13:47 <REP> d-------- C:\Program Files\A4Desk

2007-05-06 14:32 20,480 --a------ C:\WINDOWS\system32\[email protected]@@k.DLL

2007-05-06 12:10 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys

2007-05-06 12:10 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys

2007-05-06 10:08 <REP> d-------- C:\Program Files\Spyware Doctor

2007-05-06 08:55 <REP> d-------- C:\Exemple

2007-05-05 20:27 <REP> d-------- C:\HijackThis

2007-05-05 10:08 298,496 --a------ C:\WINDOWS\uninst.exe

2007-05-03 23:15 <REP> d-------- C:\Program Files\GameSpy Arcade

2007-05-03 23:05 22,040 --a------ C:\DOCUME~1\ADMINI~1\APPLIC~1\addon.dat

2007-05-03 07:25 22,040 --a------ C:\DOCUME~1\Dolc3\APPLIC~1\addon.dat

2007-05-01 12:14 <REP> d-------- C:\WINDOWS\system32\oodag

2007-05-01 10:10 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Resource Tuner

2007-04-30 07:39 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pcgdemo

2007-04-29 15:17 <REP> d-------- C:\Program Files\PROnetworks

2007-04-29 11:49 <REP> d-------- C:\Program Files\PBA

2007-04-28 16:51 110,360 --a------ C:\WINDOWS\system32\drivers\kl1.sys

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-05-27 09:40:30 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\uTorrent

2007-05-26 19:47:03 -------- d-----w C:\Program Files\Ubisoft

2007-05-25 12:33:16 -------- d-----w C:\Program Files\Ahead

2007-05-25 12:33:14 -------- d-----w C:\Program Files\Fichiers communs\Ahead

2007-05-25 11:49:02 -------- d-----w C:\Program Files\Emule0.47c

2007-05-24 12:38:23 -------- d-----w C:\Program Files\Sunbelt Software

2007-05-23 21:48:19 -------- d-----w C:\Program Files\المكتبة الشاملة

2007-05-23 17:58:49 -------- d-----w C:\Program Files\Fichiers communs\InstallShield

2007-05-23 04:57:07 -------- d-----w C:\Program Files\Kaspersky Lab

2007-05-22 17:57:23 -------- d-----w C:\Program Files\Dictionnaire Français

2007-05-22 08:23:50 -------- d-----w C:\Program Files\Messenger Plus! Live

2007-05-21 13:37:54 -------- d-----w C:\Program Files\WinHex

2007-05-20 21:51:06 720,896 ----a-w C:\WINDOWS\iun6002ev.exe

2007-05-20 14:32:53 -------- d-----w C:\Program Files\Fichiers communs\ODBC

2007-05-20 14:31:43 -------- d-----w C:\Program Files\Microsoft Visual Studio 8

2007-05-20 12:28:25 -------- d-----w C:\Program Files\FreeGo

2007-05-20 12:10:04 -------- d--h--w C:\Program Files\InstallShield Installation Information

2007-05-20 12:10:04 -------- d-----w C:\Program Files\QuickTime

2007-05-20 12:10:04 -------- d-----w C:\Program Files\pspad

2007-05-20 12:10:04 -------- d-----w C:\Program Files\Mozilla Thunderbird

2007-05-20 12:10:02 -------- d-----w C:\Program Files\DivX

2007-05-20 12:10:02 -------- d-----w C:\Program Files\D-Tools

2007-05-20 12:09:04 -------- d-----w C:\Program Files\ISS

2007-05-20 12:09:04 -------- d-----w C:\Program Files\Fichiers communs\Symantec Shared

2007-05-20 12:09:02 -------- d-----w C:\Program Files\WebAnimé

2007-05-20 12:09:02 -------- d-----w C:\Program Files\RepInfo

2007-05-20 12:09:02 -------- d-----w C:\Program Files\Real Alternative

2007-05-19 21:34:05 -------- d-----w C:\Program Files\RegCleaner

2007-05-19 21:34:05 -------- d-----w C:\Program Files\Hide IP Platinum

2007-05-19 21:21:11 -------- d-----w C:\Program Files\Folder Guide

2007-05-18 17:22:18 -------- d-----w C:\Program Files\EA Games

2007-05-17 23:23:00 -------- d-----w C:\Program Files\Electronic Arts

2007-05-17 14:50:31 -------- d-----w C:\Program Files\Sakhr ML Dictionary 4.0

2007-05-16 21:56:03 1,243,680 ----a-w C:\WINDOWS\system32\AutoPartNt.exe

2007-05-16 21:13:54 -------- d-----w C:\Program Files\OO Software

2007-05-16 18:53:28 -------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard

2007-05-16 14:37:43 -------- d-----w C:\Program Files\Fichiers communs\Acronis

2007-05-16 05:55:42 -------- d-----w C:\Program Files\Skype

2007-05-16 04:08:16 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Smart PC Solutions

2007-05-15 01:16:46 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Skype

2007-05-12 13:37:40 76,248 ----a-w C:\WINDOWS\system32\perfc00C.dat

2007-05-12 13:37:40 470,894 ----a-w C:\WINDOWS\system32\perfh00C.dat

2007-05-11 15:58:07 737,280 ----a-w C:\WINDOWS\iun6002.exe

2007-05-10 18:07:55 -------- d-----w C:\Program Files\Alem1QrnTrth

2007-05-10 11:22:05 -------- d-----w C:\Program Files\Windows Live Safety Center

2007-05-09 19:37:18 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys

2007-05-07 22:04:56 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\iolo

2007-05-06 06:22:38 -------- d-----w C:\Program Files\SoftsPack

2007-05-05 18:41:08 -------- d-----w C:\Program Files\Shadowgrounds

2007-05-03 05:16:07 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat

2007-05-01 08:06:03 -------- d-----w C:\Program Files\MozBackup

2007-04-27 04:35:45 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Real

2007-04-26 22:34:55 359,808 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS

2007-04-25 11:16:03 -------- d-----w C:\Program Files\Media Player Classic

2007-04-25 06:04:19 -------- d-----w C:\Program Files\BinarySense

2007-04-24 02:28:27 -------- d-----w C:\Program Files\Spy Sweeper

2007-04-24 02:11:26 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Webroot

2007-04-24 00:15:50 -------- d-----w C:\Program Files\Fichiers communs\eSellerate

2007-04-24 00:15:48 -------- d-----w C:\Program Files\AnswersThatWork

2007-04-23 22:01:15 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\BinarySense

2007-04-23 19:59:21 -------- d-----w C:\Program Files\Eidos

2007-04-22 15:32:39 -------- d-----w C:\Program Files\Raven

2007-04-21 21:29:13 -------- d-----w C:\Program Files\Your Uninstaller 2006

2007-04-21 21:24:11 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\URSoft

2007-04-21 02:32:48 -------- d-----w C:\Program Files\uTorrent

2007-04-20 21:40:22 -------- d-----w C:\Program Files\SystemMechanic7

2007-04-18 20:27:20 73 ----a-w C:\WINDOWS\system32\ssprs.dll

2007-04-18 20:27:20 205 ----a-w C:\WINDOWS\system32\lsprst7.dll

2007-04-18 19:51:52 1,025 ----a-w C:\WINDOWS\system32\sysprs7.dll

2007-04-18 19:51:52 1,025 ----a-w C:\WINDOWS\system32\clauth2.dll

2007-04-18 19:51:52 1,025 ----a-w C:\WINDOWS\system32\clauth1.dll

2007-04-18 19:36:48 -------- d-----w C:\Program Files\InfinaDyne

2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll

2007-04-18 09:55:42 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Uniblue

2007-04-18 09:48:55 -------- d-----w C:\Program Files\Uniblue

2007-04-18 09:11:11 -------- d-----w C:\Program Files\Blue Lakes Technology

2007-04-17 21:59:21 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Ahead

2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll

2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll

2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll

2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll

2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll

2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll

2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe

2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll

2007-04-16 20:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll

2007-04-16 20:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll

2007-04-16 11:27:29 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\NewsBin

2007-04-16 05:26:02 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\SYSTRAN

2007-04-16 05:20:27 878,080 ----a-w C:\WINDOWS\system32\iconv.dll

2007-04-16 05:20:26 721,920 ----a-w C:\WINDOWS\system32\libxml2.dll

2007-04-16 05:20:26 51,200 ----a-w C:\WINDOWS\system32\libexslt.dll

2007-04-16 05:20:26 150,016 ----a-w C:\WINDOWS\system32\libxslt.dll

2007-04-16 05:12:53 -------- d-----w C:\Program Files\Lavasoft

2007-04-15 04:16:12 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Media Player Classic

2007-04-15 04:13:41 -------- d-----w C:\Program Files\K-Lite Codec Packk

2007-04-13 16:28:38 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Elaborate Bytes

2007-04-12 18:20:59 -------- d-----w C:\Program Files\TuneUp Utilities 2007

2007-04-12 01:30:58 -------- d-----w C:\Program Files\Fichiers communs\Agnitum Shared

2007-04-12 00:00:37 -------- d-----w C:\Program Files\Acronis

2007-04-11 19:21:37 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\dvdcss

2007-04-11 05:13:58 -------- d-----w C:\Program Files\Macrovision

2007-04-11 05:13:57 -------- d-----w C:\Program Files\Fichiers communs\Merge Modules

2007-04-11 01:59:04 -------- d-----w C:\Program Files\NewsLeecher

2007-04-11 01:42:32 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\NewsLeecher

2007-04-08 12:59:03 -------- d-----w C:\Program Files\MyFreeTV

2007-04-06 14:19:45 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Command & Conquer 3 Les guerres du Tiberium

2007-04-06 14:00:20 977 ----a-w C:\WINDOWS\eReg.dat

2007-04-06 13:45:23 -------- d--h--r C:\DOCUME~1\Dolc3\APPLIC~1\SecuROM

2007-04-06 13:45:21 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll

2007-04-04 13:19:20 -------- d-----w C:\Program Files\VBReFormer

2007-04-04 12:58:26 24,344 ----a-w C:\WINDOWS\system32\drivers\klim5.sys

2007-04-03 14:52:54 1,658,880 ----a-w C:\WINDOWS\system32\ExGrid.dll

2007-04-03 14:51:56 614,400 ----a-w C:\WINDOWS\system32\ExButton.dll

2007-04-03 14:51:24 307,200 ----a-w C:\WINDOWS\system32\ExPMenu.dll

2007-04-03 14:51:00 585,728 ----a-w C:\WINDOWS\system32\ExMenu.dll

2007-04-03 03:50:47 -------- d-----w C:\Program Files\NSIS

2007-04-03 03:47:41 -------- d-----w C:\Program Files\XnView

2007-04-03 02:42:04 -------- d-----w C:\Program Files\Universal Extractor

2007-04-03 00:49:44 -------- d-----w C:\Program Files\Microsoft Works

2007-04-03 00:49:25 -------- d-----w C:\Program Files\MSBuild

2007-04-03 00:47:43 -------- d-----w C:\Program Files\Microsoft.NET

2007-04-02 23:56:49 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Thinstall

2007-04-01 20:12:15 -------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared

2007-04-01 12:17:43 -------- d-----w C:\Program Files\ReadWrite Arabic

2007-03-31 07:27:28 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\WinPatrol

2007-03-31 07:27:08 -------- d-----w C:\Program Files\BillP Studios

2007-03-30 12:15:52 34,143 ----a-w C:\WINDOWS\system32\drivers\MiniIcpt.sys

2007-03-30 10:57:54 56 --sh--r C:\WINDOWS\system32\9AAF4FB2E0.sys

2007-03-30 10:57:54 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

2007-03-30 10:54:12 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Corel

2007-03-30 10:53:48 -------- d-----w C:\Program Files\Corel

2007-03-29 09:01:33 -------- d-----w C:\Program Files\AliveBox

2007-03-29 07:36:51 -------- d-----w C:\Program Files\HardwareDetection

2007-03-29 06:33:13 -------- d-----w C:\Program Files\TechSmith

2007-03-27 11:53:03 -------- d-----w C:\Program Files\IEFavorisExport10

2007-03-27 09:05:32 27 ----a-w C:\WINDOWS\system32\ML.DLL

2007-03-27 07:55:57 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe

2007-03-27 07:55:48 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll

2007-03-27 07:55:23 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll

2007-03-27 07:55:23 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll

2007-03-27 07:53:00 435,816 ----a-w C:\WINDOWS\system32\Incinerator.dll

2007-03-27 07:49:07 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll

2007-03-27 07:49:07 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll

2007-03-27 07:49:05 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll

2007-03-27 07:49:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll

2007-03-27 07:49:02 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll

2007-03-27 07:49:02 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll

2007-03-27 07:49:02 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll

2007-03-27 07:49:02 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll

2007-03-27 07:48:59 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll

2007-03-27 07:48:58 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll

2007-03-27 07:48:58 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll

2007-03-27 07:48:58 639,066 ----a-w C:\WINDOWS\system32\DivX.dll

2007-03-24 10:45:48 57,344 ----a-r C:\WINDOWS\system32\libsyslic1.dll

2007-03-19 21:08:56 50,784 ----a-w C:\WINDOWS\system32\csvidcap.dll

2007-03-19 06:30:24 102,400 ----a-w C:\WINDOWS\system32\tsccvid.dll

2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll

2007-03-13 23:57:54 144,896 ----a-r C:\WINDOWS\system32\libsyslic1.original.dll

2007-03-12 12:10:56 206,368 ----a-w C:\WINDOWS\system32\snapapi.dll

2007-03-09 17:24:04 129,536 ----a-w C:\WINDOWS\system32\IJL15.dll

2007-03-09 17:23:45 94,208 ----a-w C:\WINDOWS\system32\ScrUnZip.dll

2007-03-09 07:57:40 27,376 ----a-w C:\WINDOWS\system32\SBBD.exe

2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll

2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll

2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll

2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys

2007-03-03 22:23:19 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll

2007-02-27 01:16:48 1,802 ----a-w C:\WINDOWS\system32\ealregsnapshot1.reg

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{00011268-E188-40DF-A514-835FCD78B1BF}=C:\Program Files\IE7Pro\IE7Pro.dll [2007-05-15 16:43]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nwiz"="nwiz.exe" [2006-08-17 07:35 C:\WINDOWS\system32\nwiz.exe]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-17 07:35]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-17 07:35]

"gfxtray"="ctccw32.dll" [2007-05-21 10:00 C:\WINDOWS\system32\ctccw32.dll]

"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-05-19 22:36]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NosecurityTab"=1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NosecurityTab"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 16:13]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [2006-10-27 00:48]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages msv1_0 relog_ap

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SBCSSvc]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]

backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]

backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]

backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Skype.lnk]

backup=C:\WINDOWS\pss\Skype.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]

backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]

backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^ERUNT AutoBackup.lnk]

backup=C:\WINDOWS\pss\ERUNT AutoBackup.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^HDDlife.lnk]

backup=C:\WINDOWS\pss\HDDlife.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^OneNote 2007 - Capture d'écran et lancement.lnk]

backup=C:\WINDOWS\pss\OneNote 2007 - Capture d'écran et lancement.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]

"C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]

C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]

"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]

"C:\Program Files\Comodo\Firewall\CPF.exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conjugaison]

D:\Torrent\NewsLeecher\alt.binaries.cd.image.french\[email protected]\conjugaison 4.70\conjLauncher.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]

"C:\Program Files\D-Tools\daemon.exe" -lang 1033

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gizmo Project]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]

"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hard Disk Sentinel]

C:\Program Files\Hard Disk Sentinel\HDSentinel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]

"C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LeechGet]

"C:\Program Files\LeechGet 2006\LeechGet.exe" -intray

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Office SturtUp]

osa9.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooccctrl.exe]

C:\Program Files\OO Software\CleverCache\ooccctrl.exe /tasktray

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpAgent]

"C:\Program Files\ScanSoft\OmniPage15\OpAgent.exe" /agent

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Opware15]

"C:\Program Files\ScanSoft\OmniPage15\Opware15.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]

C:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe" -atboottime

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Red Swoosh]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBCSTray]

C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]

"C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Popup Blocker]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Total Uninstall]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tracks Eraser Pro]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]

C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnHackMe Monitor]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue Registry Booster]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]

C:\Program Files\Webroot\Washer\wwDisp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"OutpostFirewall"=2 (0x2)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"ISUSPM"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler

"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

UxTuneUp

 

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]

AutoRun\command- F:\autorn.exe MldAutRn.EXE

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{95ae0bbd-033b-11dc-b960-00e018b4cbba}]

AutoRun\command- F:\autorn.exe MldAutRn.EXE

 

 

Contents of the 'Scheduled Tasks' folder

2007-05-25 18:08:41 C:\WINDOWS\tasks\Maintenance en 1 clic.job

2007-05-27 05:34:12 C:\WINDOWS\tasks\User_Feed_Synchronization-{EB10F0AE-F6CA-47AA-B9F9-55EC8E6E816D}.job

 

********************************************************************

 

catchme 0.3.681 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-27 11:51:55

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

 

********************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\(VFILT)]

 

 

Completion time: 2007-05-27 11:53:13

C:\ComboFix-quarantined-files.txt ... 2007-05-27 11:52

C:\ComboFix2.txt ... 2007-05-25 22:13

 

--- E O F ---

 

Edit

 

Même chose, ces 3 fichiers sont encore là. Ils réapparaissent tout le temps.

 

Je viens de scanner ce repertoire: voilà le log de CounterSPY

 

Scan History Details

Start Date: 27/05/2007 13:43:17

End Date: 27/05/2007 14:06:34

Total Time: 23 Min 17 Sec

Detected security risks

 

Trojan-Dropper.Win32.Delf.aau Trojan Downloader more information...

Status: Ignored

 

Files detected

C:\WINDOWS\update.exe

AVG Anti-Spyware ne le detecte pas, même chose pour Kaspersky

 

Il manque un second log:

 

2007-05-04 05:35	  91282	--a------	C:\Qoobox\Quarantine\C\WINDOWS\system32\Update.exe.vir
2007-05-25 12:19	  551149	--a------	C:\Qoobox\Quarantine\C\WINDOWS\update.exe.vir
2007-05-25 22:02	  1194	--a------	C:\Qoobox\Quarantine\Registry_backups\LEGACY_NM.reg.cf
2007-05-25 22:02	  7028	--a------	C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.cf


Structure du dossier
Le num‚ro de s‚rie du volume est 4092-D854
C:\QOOBOX
\---Quarantine
+---C
|   \---WINDOWS
|	   |   update.exe.vir
|	   |   
|	   \---system32
|			   Update.exe.vir
|			   
\---Registry_backups
		LEGACY_NM.reg.cf
		services_nm.reg.cf

 

 

Bonjour Charles,

 

Désolé mais je n'avais pas vu ta réponse. Je vais le refaire en mode normal.Merci

 

 

Voilà le Log en mode NORMAL

 

"Dolc3" - 2007-05-27 15:06:03 Service Pack 2

ComboFix 07-05.27.V - Running from: "C:\Documents and Settings\Dolc3\Bureau\"

 

 

((((((((((((((((((((((((((((((( Files Created from 2007-04-27 to 2007-05-27 ))))))))))))))))))))))))))))))))))

 

 

2007-05-27 12:59 148,368 --a------ C:\WINDOWS\rrrar.exe

2007-05-26 12:28 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\IE7Pro

2007-05-25 22:13 49,152 --a------ C:\WINDOWS\nircmd.exe

2007-05-25 14:33 5,888 --------- C:\WINDOWS\system32\drivers\imagedrv.sys

2007-05-25 14:33 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll

2007-05-25 14:33 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll

2007-05-25 14:33 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll

2007-05-25 14:33 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll

2007-05-25 14:33 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe

2007-05-25 14:33 127,488 --------- C:\WINDOWS\system32\drivers\imagesrv.sys

2007-05-25 14:33 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll

2007-05-25 14:33 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll

2007-05-24 14:43 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys

2007-05-24 13:44 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy

2007-05-24 00:00 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2007-05-24 00:00 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2007-05-24 00:00 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys

2007-05-23 23:46 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak

2007-05-23 20:45 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\Comodo

2007-05-23 16:14 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Comodo

2007-05-23 16:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Comodo

2007-05-23 13:18 <REP> d-------- C:\Program Files\Comodo

2007-05-23 11:05 <REP> d-------- C:\Program Files\The_Jolly_Roger

2007-05-23 06:58 82,258 --a------ C:\WINDOWS\system32\drivers\klin.dat

2007-05-23 06:58 82,258 --a------ C:\WINDOWS\system32\drivers\klick.dat

2007-05-23 06:57 8,246,816 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat

2007-05-23 06:57 100,384 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat

2007-05-23 06:46 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files

2007-05-22 18:43 <REP> d-------- C:\Program Files\Dictionnaire Fran‡ais

2007-05-22 18:42 0 -rahs---- C:\MSDOS.SYS

2007-05-22 18:42 0 -rahs---- C:\IO.SYS

2007-05-21 22:59 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Abexo

2007-05-21 21:54 0 --a------ C:\WINDOWS\system32\SBRC.dat

2007-05-21 21:54 0 --a------ C:\WINDOWS\system32\SBFC.dat

2007-05-21 20:02 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\Thunderbird

2007-05-21 17:24 <REP> d-------- C:\DOCUME~1\ILYES\Bureau

2007-05-21 10:01 257 --a------ C:\WINDOWS\msdres.bin

2007-05-21 10:00 25,600 --a------ C:\WINDOWS\system32\ctccw32.dll

2007-05-21 09:49 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip

2007-05-21 00:52 <REP> d-------- C:\Programmi

2007-05-20 23:55 <REP> d-------- C:\Program Files\Dictionnaire

2007-05-20 16:16 <REP> d-------- C:\Program Files\Hard Disk Sentinel

2007-05-20 14:52 <REP> d-------- C:\Program Files\WinPcap

2007-05-20 14:35 <REP> d-------- C:\Program Files\regshot1_7_2

2007-05-20 14:16 <REP> d-------- C:\DOCUME~1\ALLUSE~1\ModÙ¹les

2007-05-20 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared

2007-05-20 13:09 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FLEXnet

2007-05-20 08:39 <REP> d-------- C:\Program Files\NewsSearcher

2007-05-20 07:24 <REP> d-------- C:\Program Files\Generalia Multimedia

2007-05-20 06:45 <REP> d-------- C:\Program Files\IDA Freeware 4.3

2007-05-20 04:07 <REP> d-------- C:\Program Files\ISTool

2007-05-20 04:07 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\ISTool

2007-05-20 03:55 <REP> d-------- C:\Program Files\Far

2007-05-19 22:37 206,352 --a------ C:\WINDOWS\system32\klogon.dll

2007-05-19 22:36 22,354 --a------ C:\WINDOWS\system32\drivers\klop.dat

2007-05-18 23:27 <REP> d-------- C:\Program Files\TechnoLogismiki

2007-05-18 00:54 <REP> d-------- C:\Program Files\CrazyPixels

2007-05-17 06:19 <REP> d-------- C:\Program Files\inSpeak

2007-05-16 23:37 200 --a------ C:\WINDOWS\QUIC2007.dat

2007-05-16 23:37 <REP> d-------- C:\Program Files\QuickTranslator 2007

2007-05-16 21:47 <REP> d-------- C:\RkUnhooker

2007-05-16 07:22 <REP> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\IE7Pro

2007-05-16 07:21 <REP> d-------- C:\Program Files\Diskeeper Corporation

2007-05-16 07:21 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Diskeeper Corporation

2007-05-16 06:59 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\IE7Pro

2007-05-16 06:56 <REP> d-------- C:\Program Files\IE7Pro

2007-05-16 06:07 <REP> d-------- C:\Program Files\Smart PC Solutions

2007-05-16 03:59 <REP> d-------- C:\Dic01

2007-05-15 04:50 <REP> d-------- C:\Program Files\EmuLe

2007-05-15 04:42 <REP> d-------- C:\WINDOWS\EmuLe

2007-05-15 03:15 <REP> d-------- C:\WINDOWS\Skype

2007-05-14 05:53 <REP> d-------- C:\Program Files\LeechGet 2006

2007-05-13 21:24 10,298 --a------ C:\WINDOWS\CODER.DAT

2007-05-13 21:23 <REP> d-------- C:\EARAB

2007-05-13 21:10 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\DivX

2007-05-13 21:09 <REP> d-------- C:\DOCUME~1\ILYES\APPLIC~1\IDM

2007-05-12 14:22 <REP> d-------- C:\Program Files\Microsoft Bootvis

2007-05-12 06:37 <REP> d-------- C:\Program Files\Teleport Pro

2007-05-12 06:09 <REP> d-------- C:\Program Files\ToniArts

2007-05-12 06:00 <REP> d-------- C:\WINDOWS\Screensaver

2007-05-12 06:00 <REP> d-------- C:\Program Files\Samurize

2007-05-12 01:16 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\IndigoRose

2007-05-12 01:04 <REP> d-------- C:\WINDOWS\Setup Factory 7.0 Trial

2007-05-12 01:04 <REP> d-------- C:\Program Files\Setup Factory 7.0 Trial

2007-05-11 20:52 <REP> d-------- C:\Program Files\1200livres

2007-05-11 18:23 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\DMCache

2007-05-11 17:58 <REP> d-------- C:\Program Files\Úºéê袠، Úºé¬ÚºêéØŒ

2007-05-11 15:18 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Caphyon

2007-05-11 15:15 <REP> d-------- C:\Program Files\Caphyon

2007-05-11 14:28 69,632 --a------ C:\WINDOWS\system32\xmltok.dll

2007-05-11 14:28 36,864 --a------ C:\WINDOWS\system32\xmlparse.dll

2007-05-11 14:28 26,096 --a------ C:\WINDOWS\system32\xmlinst.exe

2007-05-11 14:28 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll

2007-05-11 02:09 1,050,120 --a------ C:\WINDOWS\system32\oodag.exe

2007-05-11 02:08 2,512,392 --a------ C:\WINDOWS\system32\oodtray.exe

2007-05-11 02:08 194,056 --a------ C:\WINDOWS\system32\oodbs.exe

2007-05-11 02:06 542,216 --a------ C:\WINDOWS\system32\oodssrs.dll

2007-05-11 02:06 202,248 --a------ C:\WINDOWS\system32\oodtrrs.dll

2007-05-11 02:06 15,880 --a------ C:\WINDOWS\system32\oodagrs.dll

2007-05-11 02:06 15,880 --a------ C:\WINDOWS\system32\oodagmg.dll

2007-05-11 02:06 10,248 --a------ C:\WINDOWS\system32\oodbsrs.dll

2007-05-11 01:42 1,294,336 --a------ C:\WINDOWS\system32\ooscrsav.scr

2007-05-10 23:19 38,160 --a------ C:\WINDOWS\system32\drivers\oobctm.sys

2007-05-10 23:18 15,368 --a------ C:\WINDOWS\system32\ootmapi.dll

2007-05-10 15:02 639,224 --a------ C:\WINDOWS\system32\drivers\sptd.sys

2007-05-09 23:59 <REP> d-------- C:\Program Files\Dorar

2007-05-09 13:45 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Nouveau dossier

2007-05-09 13:43 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\TrojanHunter

2007-05-09 12:31 53,248 --a------ C:\WINDOWS\system32\UNRAR.DLL

2007-05-09 12:31 216,064 --a------ C:\WINDOWS\system32\CP5DLL32.DLL

2007-05-09 12:31 160,256 --a------ C:\WINDOWS\system32\ShrLk21.dll

2007-05-09 12:31 <REP> d-------- C:\Program Files\Anti-Trojan-55

2007-05-09 12:05 302,592 --a------ C:\WINDOWS\unin040c.exe

2007-05-09 01:10 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2

2007-05-08 18:05 <REP> d-------- C:\Documents and Settings\Dolc3\My GCompris

2007-05-08 18:05 <REP> d-------- C:\Documents and Settings\Dolc3\.config

2007-05-08 18:05 <REP> d-------- C:\DOCUME~1\Dolc3\My GCompris

2007-05-08 18:05 <REP> d-------- C:\DOCUME~1\Dolc3\.config

2007-05-08 00:35 <REP> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\iolo

2007-05-08 00:04 <REP> d-------- C:\Program Files\iolo

2007-05-07 19:06 118,784 --a------ C:\WINDOWS\system32\CLKERN.DLL

2007-05-07 19:06 <REP> d-------- C:\Program Files\Cracklock

2007-05-07 14:33 <REP> d-------- C:\Program Files\WebAnim‚

2007-05-07 13:47 <REP> d-------- C:\Program Files\A4Desk

2007-05-06 14:32 20,480 --a------ C:\WINDOWS\system32\[email protected]@@k.DLL

2007-05-06 12:10 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys

2007-05-06 12:10 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys

2007-05-06 10:08 <REP> d-------- C:\Program Files\Spyware Doctor

2007-05-06 08:55 <REP> d-------- C:\Exemple

2007-05-05 20:27 <REP> d-------- C:\HijackThis

2007-05-05 10:08 298,496 --a------ C:\WINDOWS\uninst.exe

2007-05-03 23:15 <REP> d-------- C:\Program Files\GameSpy Arcade

2007-05-03 23:05 22,040 --a------ C:\DOCUME~1\ADMINI~1\APPLIC~1\addon.dat

2007-05-03 07:25 22,040 --a------ C:\DOCUME~1\Dolc3\APPLIC~1\addon.dat

2007-05-01 12:14 <REP> d-------- C:\WINDOWS\system32\oodag

2007-05-01 10:10 <REP> d-------- C:\DOCUME~1\Dolc3\APPLIC~1\Resource Tuner

2007-04-30 07:39 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\pcgdemo

2007-04-29 15:17 <REP> d-------- C:\Program Files\PROnetworks

2007-04-29 11:49 <REP> d-------- C:\Program Files\PBA

2007-04-28 16:51 110,360 --a------ C:\WINDOWS\system32\drivers\kl1.sys

 

 

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

 

2007-05-27 09:40:30 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\uTorrent

2007-05-26 19:47:03 -------- d-----w C:\Program Files\Ubisoft

2007-05-25 12:33:16 -------- d-----w C:\Program Files\Ahead

2007-05-25 12:33:14 -------- d-----w C:\Program Files\Fichiers communs\Ahead

2007-05-25 11:49:02 -------- d-----w C:\Program Files\Emule0.47c

2007-05-24 12:38:23 -------- d-----w C:\Program Files\Sunbelt Software

2007-05-23 21:48:19 -------- d-----w C:\Program Files\المكتبة الشاملة

2007-05-23 17:58:49 -------- d-----w C:\Program Files\Fichiers communs\InstallShield

2007-05-23 04:57:07 -------- d-----w C:\Program Files\Kaspersky Lab

2007-05-22 17:57:23 -------- d-----w C:\Program Files\Dictionnaire Français

2007-05-22 08:23:50 -------- d-----w C:\Program Files\Messenger Plus! Live

2007-05-21 13:37:54 -------- d-----w C:\Program Files\WinHex

2007-05-20 21:51:06 720,896 ----a-w C:\WINDOWS\iun6002ev.exe

2007-05-20 14:32:53 -------- d-----w C:\Program Files\Fichiers communs\ODBC

2007-05-20 14:31:43 -------- d-----w C:\Program Files\Microsoft Visual Studio 8

2007-05-20 12:28:25 -------- d-----w C:\Program Files\FreeGo

2007-05-20 12:10:04 -------- d--h--w C:\Program Files\InstallShield Installation Information

2007-05-20 12:10:04 -------- d-----w C:\Program Files\QuickTime

2007-05-20 12:10:04 -------- d-----w C:\Program Files\pspad

2007-05-20 12:10:04 -------- d-----w C:\Program Files\Mozilla Thunderbird

2007-05-20 12:10:02 -------- d-----w C:\Program Files\DivX

2007-05-20 12:10:02 -------- d-----w C:\Program Files\D-Tools

2007-05-20 12:09:04 -------- d-----w C:\Program Files\ISS

2007-05-20 12:09:04 -------- d-----w C:\Program Files\Fichiers communs\Symantec Shared

2007-05-20 12:09:02 -------- d-----w C:\Program Files\WebAnimé

2007-05-20 12:09:02 -------- d-----w C:\Program Files\RepInfo

2007-05-20 12:09:02 -------- d-----w C:\Program Files\Real Alternative

2007-05-19 21:34:05 -------- d-----w C:\Program Files\RegCleaner

2007-05-19 21:34:05 -------- d-----w C:\Program Files\Hide IP Platinum

2007-05-19 21:21:11 -------- d-----w C:\Program Files\Folder Guide

2007-05-18 17:22:18 -------- d-----w C:\Program Files\EA Games

2007-05-17 23:23:00 -------- d-----w C:\Program Files\Electronic Arts

2007-05-17 14:50:31 -------- d-----w C:\Program Files\Sakhr ML Dictionary 4.0

2007-05-16 21:56:03 1,243,680 ----a-w C:\WINDOWS\system32\AutoPartNt.exe

2007-05-16 21:13:54 -------- d-----w C:\Program Files\OO Software

2007-05-16 18:53:28 -------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard

2007-05-16 14:37:43 -------- d-----w C:\Program Files\Fichiers communs\Acronis

2007-05-16 05:55:42 -------- d-----w C:\Program Files\Skype

2007-05-16 04:08:16 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Smart PC Solutions

2007-05-15 01:16:46 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Skype

2007-05-12 13:37:40 76,248 ----a-w C:\WINDOWS\system32\perfc00C.dat

2007-05-12 13:37:40 470,894 ----a-w C:\WINDOWS\system32\perfh00C.dat

2007-05-11 15:58:07 737,280 ----a-w C:\WINDOWS\iun6002.exe

2007-05-10 18:07:55 -------- d-----w C:\Program Files\Alem1QrnTrth

2007-05-10 11:22:05 -------- d-----w C:\Program Files\Windows Live Safety Center

2007-05-09 19:37:18 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys

2007-05-07 22:04:56 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\iolo

2007-05-06 06:22:38 -------- d-----w C:\Program Files\SoftsPack

2007-05-05 18:41:08 -------- d-----w C:\Program Files\Shadowgrounds

2007-05-03 05:16:07 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat

2007-05-01 08:06:03 -------- d-----w C:\Program Files\MozBackup

2007-04-27 04:35:45 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Real

2007-04-26 22:34:55 359,808 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS

2007-04-25 11:16:03 -------- d-----w C:\Program Files\Media Player Classic

2007-04-25 06:04:19 -------- d-----w C:\Program Files\BinarySense

2007-04-24 02:28:27 -------- d-----w C:\Program Files\Spy Sweeper

2007-04-24 02:11:26 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Webroot

2007-04-24 00:15:50 -------- d-----w C:\Program Files\Fichiers communs\eSellerate

2007-04-24 00:15:48 -------- d-----w C:\Program Files\AnswersThatWork

2007-04-23 22:01:15 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\BinarySense

2007-04-23 19:59:21 -------- d-----w C:\Program Files\Eidos

2007-04-22 15:32:39 -------- d-----w C:\Program Files\Raven

2007-04-21 21:29:13 -------- d-----w C:\Program Files\Your Uninstaller 2006

2007-04-21 21:24:11 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\URSoft

2007-04-21 02:32:48 -------- d-----w C:\Program Files\uTorrent

2007-04-20 21:40:22 -------- d-----w C:\Program Files\SystemMechanic7

2007-04-18 20:27:20 73 ----a-w C:\WINDOWS\system32\ssprs.dll

2007-04-18 20:27:20 205 ----a-w C:\WINDOWS\system32\lsprst7.dll

2007-04-18 19:51:52 1,025 ----a-w C:\WINDOWS\system32\sysprs7.dll

2007-04-18 19:51:52 1,025 ----a-w C:\WINDOWS\system32\clauth2.dll

2007-04-18 19:51:52 1,025 ----a-w C:\WINDOWS\system32\clauth1.dll

2007-04-18 19:36:48 -------- d-----w C:\Program Files\InfinaDyne

2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll

2007-04-18 09:55:42 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Uniblue

2007-04-18 09:48:55 -------- d-----w C:\Program Files\Uniblue

2007-04-18 09:11:11 -------- d-----w C:\Program Files\Blue Lakes Technology

2007-04-17 21:59:21 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Ahead

2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll

2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll

2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll

2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll

2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll

2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll

2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe

2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll

2007-04-16 20:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll

2007-04-16 20:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll

2007-04-16 11:27:29 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\NewsBin

2007-04-16 05:26:02 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\SYSTRAN

2007-04-16 05:20:27 878,080 ----a-w C:\WINDOWS\system32\iconv.dll

2007-04-16 05:20:26 721,920 ----a-w C:\WINDOWS\system32\libxml2.dll

2007-04-16 05:20:26 51,200 ----a-w C:\WINDOWS\system32\libexslt.dll

2007-04-16 05:20:26 150,016 ----a-w C:\WINDOWS\system32\libxslt.dll

2007-04-16 05:12:53 -------- d-----w C:\Program Files\Lavasoft

2007-04-15 04:16:12 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Media Player Classic

2007-04-15 04:13:41 -------- d-----w C:\Program Files\K-Lite Codec Packk

2007-04-13 16:28:38 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Elaborate Bytes

2007-04-12 18:20:59 -------- d-----w C:\Program Files\TuneUp Utilities 2007

2007-04-12 01:30:58 -------- d-----w C:\Program Files\Fichiers communs\Agnitum Shared

2007-04-12 00:00:37 -------- d-----w C:\Program Files\Acronis

2007-04-11 19:21:37 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\dvdcss

2007-04-11 05:13:58 -------- d-----w C:\Program Files\Macrovision

2007-04-11 05:13:57 -------- d-----w C:\Program Files\Fichiers communs\Merge Modules

2007-04-11 01:59:04 -------- d-----w C:\Program Files\NewsLeecher

2007-04-11 01:42:32 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\NewsLeecher

2007-04-08 12:59:03 -------- d-----w C:\Program Files\MyFreeTV

2007-04-06 14:19:45 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Command & Conquer 3 Les guerres du Tiberium

2007-04-06 14:00:20 977 ----a-w C:\WINDOWS\eReg.dat

2007-04-06 13:45:23 -------- d--h--r C:\DOCUME~1\Dolc3\APPLIC~1\SecuROM

2007-04-06 13:45:21 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll

2007-04-04 13:19:20 -------- d-----w C:\Program Files\VBReFormer

2007-04-04 12:58:26 24,344 ----a-w C:\WINDOWS\system32\drivers\klim5.sys

2007-04-03 14:52:54 1,658,880 ----a-w C:\WINDOWS\system32\ExGrid.dll

2007-04-03 14:51:56 614,400 ----a-w C:\WINDOWS\system32\ExButton.dll

2007-04-03 14:51:24 307,200 ----a-w C:\WINDOWS\system32\ExPMenu.dll

2007-04-03 14:51:00 585,728 ----a-w C:\WINDOWS\system32\ExMenu.dll

2007-04-03 03:50:47 -------- d-----w C:\Program Files\NSIS

2007-04-03 03:47:41 -------- d-----w C:\Program Files\XnView

2007-04-03 02:42:04 -------- d-----w C:\Program Files\Universal Extractor

2007-04-03 00:49:44 -------- d-----w C:\Program Files\Microsoft Works

2007-04-03 00:49:25 -------- d-----w C:\Program Files\MSBuild

2007-04-03 00:47:43 -------- d-----w C:\Program Files\Microsoft.NET

2007-04-02 23:56:49 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Thinstall

2007-04-01 20:12:15 -------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared

2007-04-01 12:17:43 -------- d-----w C:\Program Files\ReadWrite Arabic

2007-03-31 07:27:28 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\WinPatrol

2007-03-31 07:27:08 -------- d-----w C:\Program Files\BillP Studios

2007-03-30 12:15:52 34,143 ----a-w C:\WINDOWS\system32\drivers\MiniIcpt.sys

2007-03-30 10:57:54 56 --sh--r C:\WINDOWS\system32\9AAF4FB2E0.sys

2007-03-30 10:57:54 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys

2007-03-30 10:54:12 -------- d-----w C:\DOCUME~1\Dolc3\APPLIC~1\Corel

2007-03-30 10:53:48 -------- d-----w C:\Program Files\Corel

2007-03-29 09:01:33 -------- d-----w C:\Program Files\AliveBox

2007-03-29 07:36:51 -------- d-----w C:\Program Files\HardwareDetection

2007-03-29 06:33:13 -------- d-----w C:\Program Files\TechSmith

2007-03-27 11:53:03 -------- d-----w C:\Program Files\IEFavorisExport10

2007-03-27 09:05:32 27 ----a-w C:\WINDOWS\system32\ML.DLL

2007-03-27 07:55:57 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe

2007-03-27 07:55:48 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll

2007-03-27 07:55:23 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll

2007-03-27 07:55:23 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll

2007-03-27 07:53:00 435,816 ----a-w C:\WINDOWS\system32\Incinerator.dll

2007-03-27 07:49:07 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll

2007-03-27 07:49:07 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll

2007-03-27 07:49:05 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll

2007-03-27 07:49:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll

2007-03-27 07:49:02 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll

2007-03-27 07:49:02 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll

2007-03-27 07:49:02 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll

2007-03-27 07:49:02 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll

2007-03-27 07:48:59 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll

2007-03-27 07:48:58 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll

2007-03-27 07:48:58 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll

2007-03-27 07:48:58 639,066 ----a-w C:\WINDOWS\system32\DivX.dll

2007-03-24 10:45:48 57,344 ----a-r C:\WINDOWS\system32\libsyslic1.dll

2007-03-19 21:08:56 50,784 ----a-w C:\WINDOWS\system32\csvidcap.dll

2007-03-19 06:30:24 102,400 ----a-w C:\WINDOWS\system32\tsccvid.dll

2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll

2007-03-13 23:57:54 144,896 ----a-r C:\WINDOWS\system32\libsyslic1.original.dll

2007-03-12 12:10:56 206,368 ----a-w C:\WINDOWS\system32\snapapi.dll

2007-03-09 17:24:04 129,536 ----a-w C:\WINDOWS\system32\IJL15.dll

2007-03-09 17:23:45 94,208 ----a-w C:\WINDOWS\system32\ScrUnZip.dll

2007-03-09 07:57:40 27,376 ----a-w C:\WINDOWS\system32\SBBD.exe

2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll

2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll

2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll

2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys

2007-03-03 22:23:19 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll

2007-02-27 01:16:48 1,802 ----a-w C:\WINDOWS\system32\ealregsnapshot1.reg

 

 

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

 

 

*Note* empty entries & legit default entries are not shown

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

{00011268-E188-40DF-A514-835FCD78B1BF}=C:\Program Files\IE7Pro\IE7Pro.dll [2007-05-15 16:43]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nwiz"="nwiz.exe" [2006-08-17 07:35 C:\WINDOWS\system32\nwiz.exe]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-17 07:35]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-17 07:35]

"gfxtray"="ctccw32.dll" [2007-05-21 10:00 C:\WINDOWS\system32\ctccw32.dll]

"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-05-19 22:36]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09]

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"NosecurityTab"=1 (0x1)

 

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"NosecurityTab"=1 (0x1)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 16:13]

"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [2006-10-27 00:48]

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages msv1_0 relog_ap

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\SBCSSvc]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Synchronizer.lnk]

backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^InterVideo WinCinema Manager.lnk]

backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]

backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Skype.lnk]

backup=C:\WINDOWS\pss\Skype.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]

backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]

backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^ERUNT AutoBackup.lnk]

backup=C:\WINDOWS\pss\ERUNT AutoBackup.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^HDDlife.lnk]

backup=C:\WINDOWS\pss\HDDlife.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dolc3^Menu Démarrer^Programmes^Démarrage^OneNote 2007 - Capture d'écran et lancement.lnk]

backup=C:\WINDOWS\pss\OneNote 2007 - Capture d'écran et lancement.lnkStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]

"C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]

C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]

"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]

"C:\Program Files\Comodo\Firewall\CPF.exe" /background

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Conjugaison]

D:\Torrent\NewsLeecher\alt.binaries.cd.image.french\[email protected]\conjugaison 4.70\conjLauncher.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]

"C:\Program Files\D-Tools\daemon.exe" -lang 1033

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gizmo Project]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]

"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hard Disk Sentinel]

C:\Program Files\Hard Disk Sentinel\HDSentinel.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]

"C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LeechGet]

"C:\Program Files\LeechGet 2006\LeechGet.exe" -intray

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Office SturtUp]

osa9.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ooccctrl.exe]

C:\Program Files\OO Software\CleverCache\ooccctrl.exe /tasktray

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpAgent]

"C:\Program Files\ScanSoft\OmniPage15\OpAgent.exe" /agent

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Opware15]

"C:\Program Files\ScanSoft\OmniPage15\Opware15.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]

C:\Program Files\Fichiers communs\Acronis\Partition Suite\oss_reinstall.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe" -atboottime

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Red Swoosh]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBCSTray]

C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SDTray]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]

"C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Mechanic Popup Blocker]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Total Uninstall]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tracks Eraser Pro]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]

C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnHackMe Monitor]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue Registry Booster]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipBuster]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Window Washer]

C:\Program Files\Webroot\Washer\wwDisp.exe

 

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]

"OutpostFirewall"=2 (0x2)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"ISUSPM"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler

"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"

 

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

UxTuneUp

 

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]

AutoRun\command- F:\autorn.exe MldAutRn.EXE

 

*Newly Created Service* -SBAPIFS

 

 

~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

 

backup-20070526-134104-921

O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)

 

backup-20070505-203853-834

O23 - Service: Outpost Firewall Service (OutpostFirewall) - Unknown owner - C:\Documents and Settings\Dolc3\Bureau\Outpost_Firewall_1.0.1817\MAINDIR\outpost.exe (file missing)

 

backup-20070505-203619-530

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

 

Windows Registry Editor Version 5.00

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]

"DllName"="C:\\Program Files\\SUPERAntiSpyware\\SASWINLO.dll"

"Logon"="SABWINLOLogon"

"Logoff"="SABWINLOLogoff"

"Startup"="SABWINLOStartup"

"Shutdown"="SABWINLOShutdown"

"Asynchronous"=dword:00000000

"Impersonate"=dword:00000000

 

 

 

backup-20070505-203525-315

O23 - Service: Outpost Firewall Service (OutpostFirewall) - Unknown owner - C:\Documents and Settings\Dolc3\Bureau\Outpost_Firewall_1.0.1817\MAINDIR\outpost.exe (file missing)

Contents of the 'Scheduled Tasks' folder

2007-05-25 18:08:41 C:\WINDOWS\tasks\Maintenance en 1 clic.job

2007-05-27 05:34:12 C:\WINDOWS\tasks\User_Feed_Synchronization-{EB10F0AE-F6CA-47AA-B9F9-55EC8E6E816D}.job

 

********************************************************************

 

catchme 0.3.681 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net

Rootkit scan 2007-05-27 15:10:04

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden autostart entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden files: 0

 

 

********************************************************************

 

[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\(VFILT)]

 

 

Completion time: 2007-05-27 15:12:01

C:\ComboFix-quarantined-files.txt ... 2007-05-27 15:11

 

--- E O F ---

Et le second ComboFix Quarantine

 

2007-05-04 05:35	  91282	--a------	C:\Qoobox\Quarantine\C\WINDOWS\system32\Update.exe.vir
2007-05-25 12:19	  551149	--a------	C:\Qoobox\Quarantine\C\WINDOWS\update.exe.vir
2007-05-25 22:02	  1194	--a------	C:\Qoobox\Quarantine\Registry_backups\LEGACY_NM.reg.cf
2007-05-25 22:02	  7028	--a------	C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.cf


Structure du dossier
Le num‚ro de s‚rie du volume est 4092-D854
C:\QOOBOX
\---Quarantine
+---C
|   \---WINDOWS
|	   |   update.exe.vir
|	   |   
|	   \---system32
|			   Update.exe.vir
|			   
\---Registry_backups
		LEGACY_NM.reg.cf
		services_nm.reg.cf

Modifié par Av3n4s
Lien vers le commentaire
Partager sur d’autres sites

Re,

  • Télécharge OTMoveIt de OldTimer.
  • Sauvegarde le sur ton Bureau.
  • Double-Clique sur OTMoveIt.exe pour le lancer.
  • Copie le chemin des fichiers suivants en selectionnant TOUT et en appuyant sur CTRL+C (ou, après avoir sélectionner, clique-droit et choisis Copier) :

C:\WINDOWS\rrrar.exe

C:\WINDOWS\system32\drivers\sbhr.sys

C:\WINDOWS\system32\SBRC.dat

C:\WINDOWS\system32\SBFC.dat

C:\WINDOWS\msdres.bin

C:\WINDOWS\QUIC2007.dat

C:\Program Files\Úºéêè¢ ØŒ Úºé¬ÚºêéØŒ

C:\DOCUME~1\ADMINI~1\APPLIC~1\addon.dat

C:\DOCUME~1\Dolc3\APPLIC~1\addon.dat

C:\Program Files\Alem1QrnTrth

  • Retourne dans OTMoveit, fais un clique-droit dans la fenêtre "Paste List of Files/Folders to be moved" et choisis Coller.
  • Clique sur le bouton rouge Moveit!.
  • Ferme OTMoveIt.
    Note : Si un fichier ou un dossier ne peut être déplacer immédiatement il te sera demander de redémarrer ta machine pour finir le processus. Si c'est le cas, choisis Yes.

Poste moi le rapport de OTMoveIT disponible ici : C:\_OTMoveIt\MovedFiles, en pièce jointe.

 

Fais un scan en ligne avec http://webscanner.kaspersky.fr/kavwebscan.html

 

dans la nouvelle fenetre qui s'affiche clique sur J'accepte

 

On va te demander de télécharger un ou deux contôle active x, accepte . Laisse le faire les mises à jour puis quand il aura finit clique sur Suivant

 

Dans le menu Choisissez la cible de l'analyse , sélectionne Poste de travail .

Le scan va commencer.Poste le rapport qui sera généré stp.

 

Si il y a un problème, assure toi que les contrôles active x soient bien configurés dans les options internet comme

 

décrit sur ce lien=> http://www.inoculer.com/activex.php3

 

NOTE: le scan est a faire avec Internet Explorer

Lien vers le commentaire
Partager sur d’autres sites

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

 Partager

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...