Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

Bonjour,

 

j'utilise opera comme navigateur qui fonctionne super bien jusqu'à ce matin. En effet, depuis ce matin, impossible de me connecter sur internet via opera ou tout autre navigateur, IE ou même Firefox. Ce qui est bizarre, c'est que tout le reste focntionne bien, pas de problème avec emule ou Azureus, ni avec Skype, ni même avec le petit prog pour écouter la musique en live. Seuls les navigateurs n'ouvrent rien. Le pare-feu de windows me semble bien configurer (XP, SP2). PAs de virus, le scan de kaspersky n'a rien donné en mode sans échec!!!

Pourtant je pense que c'est lié à un virus, alors pour les pro des rapport hijsckthis, voici le mien.

Que faire?

 

Et voici le rapport hijackthis :

Logfile of HijackThis v1.99.1

Scan saved at 10:54:03 a.m., on 07/06/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

C:\Archivos de programa\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.3.1:3128

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_05\bin\jusched.exe

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe

O4 - HKLM\..\Run: [AVP] "C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe "

O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe

O4 - HKLM\..\Run: [iMJPMIG8.2] msime82.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsServer] msfun80.exe

O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmwordtrans.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\DOCUME~1\12\MISDOC~1\CDRIC~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Pages liées - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Pages similaires - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Recherche &Google - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmcache.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra button: Statistiques d'Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.antivirus-france.com

O15 - Trusted Zone: http://www.secuser.com

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab

O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.girafoto.fr/uploaders/ImageUploader3.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{96DEF815-EFFB-416A-82EA-8FB572DF068F}: NameServer = 192.168.3.1

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARCHIV~1\ARCHIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: MSCSPTISRV - Unknown owner - C:\Archivos de programa\Archivos comunes\Sony Shared\AVLib\MSCSPTISRV.exe (file missing)

O23 - Service: PACSPTISVR - Unknown owner - C:\Archivos de programa\Archivos comunes\Sony Shared\AVLib\PACSPTISVR.exe (file missing)

O23 - Service: Sony SPTI Service (SPTISRV) - Unknown owner - C:\Archivos de programa\Archivos comunes\Sony Shared\AVLib\SPTISRV.exe (file missing)

 

Merci pour votre aide!!!

A bientôt, jespère!!!

Cédo

Modifié par Cedcol

Posté(e)

Bonjour Cedcol !

 

Fais ceci stp :

 

Télécharge AVG Anti-Spyware

http://free3.grisoft.cz/softw/70free/setup...up-7.5.0.50.exe

  • Lance AVG Anti-Spyware et clique sur le bouton Update (barre d'outils - au haut). Sous Manual Update clique Start update.
  • Tu verras ceci juste au bas, lorsque la mise à jour sera complétée : "Update successful"
  • Ferme AVG Anti-Spyware. Ne pas le lancer tout de suite.

Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.

  • Du mode Sans Échec, lance AVG Anti-Spyware et clique sur le bouton Scanner (de la barre d'outils) et ensuite clique sur Complete System Scan. Le scan prendra un certain temps, donc sois patient.
  • AVG Anti-Spyware affichera une liste des fichiers détectés, sur la gauche. En fin de scan, l'outil appliquera les "Actions" à appliquer automatiquement. Clique sur le bouton Apply all actions. AVG Anti-Spyware affichera "All actions have been applied" du côté droit.
  • Clique sur "Save Report", puis "Save Report As". Ceci génère un rapport en fichier texte. Assure-toi de le sauvegarder dans un endroit sûr (sur ton Bureau, par exemple).
  • Redémarre ton ordi en mode Normal.

.

 

Je te fais passer un autre outil :

 

Télécharge Blacklight (de F-Secure) et sauvegarde le sur ton Bureau.

 

Double-clique blbeta.exe et accepte la licence; laisse [X]scan through Windows Explorer activé; clique Scan puis Next

 

Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

 

Copie et colle le contenu de ce rapport dans ta prochaine réponse. NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

Prière de poster les rapports suivant dans ta prochaine réponse :

 

1) AVG Anti-Spyware

2) BlackLight

3) Nouveau rapport HijackThis!

 

Bon courage, et @+

Posté(e)
Bonjour Cedcol !

 

Fais ceci stp :

 

Télécharge AVG Anti-Spyware

http://free3.grisoft.cz/softw/70free/setup...up-7.5.0.50.exe

  • Lance AVG Anti-Spyware et clique sur le bouton Update (barre d'outils - au haut). Sous Manual Update clique Start update.
  • Tu verras ceci juste au bas, lorsque la mise à jour sera complétée : "Update successful"
  • Ferme AVG Anti-Spyware. Ne pas le lancer tout de suite.

Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.

  • Du mode Sans Échec, lance AVG Anti-Spyware et clique sur le bouton Scanner (de la barre d'outils) et ensuite clique sur Complete System Scan. Le scan prendra un certain temps, donc sois patient.
  • AVG Anti-Spyware affichera une liste des fichiers détectés, sur la gauche. En fin de scan, l'outil appliquera les "Actions" à appliquer automatiquement. Clique sur le bouton Apply all actions. AVG Anti-Spyware affichera "All actions have been applied" du côté droit.
  • Clique sur "Save Report", puis "Save Report As". Ceci génère un rapport en fichier texte. Assure-toi de le sauvegarder dans un endroit sûr (sur ton Bureau, par exemple).
  • Redémarre ton ordi en mode Normal.

.

 

Je te fais passer un autre outil :

 

Télécharge Blacklight (de F-Secure) et sauvegarde le sur ton Bureau.

 

Double-clique blbeta.exe et accepte la licence; laisse [X]scan through Windows Explorer activé; clique Scan puis Next

 

Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

 

Copie et colle le contenu de ce rapport dans ta prochaine réponse. NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

Prière de poster les rapports suivant dans ta prochaine réponse :

 

1) AVG Anti-Spyware

2) BlackLight

3) Nouveau rapport HijackThis!

 

Bon courage, et @+

 

Salut

Alors voilà le resultat des opérations

1/ la recherche avec AVG Anti-Spyware a été réalisée sans la mise à jour car je n'ai même pas eu accés à la mise à jour.

Voici le résultat :

+ Résultat de l'analyse:

 

 

 

C:\AUTORUN.INF -> Trojan.Agent.ao : Nettoyé.

E:\AUTORUN.INF -> Trojan.Agent.ao : Nettoyé.

 

 

Fin du rapport

 

Et b]BlackLight[/b

06/13/07 09:07:12 [info]: BlackLight Engine 1.0.61 initialized

06/13/07 09:07:12 [info]: OS: 5.1 build 2600 (Service Pack 2)

06/13/07 09:07:12 [Note]: 7019 4

06/13/07 09:07:12 [Note]: 7005 0

06/13/07 09:07:57 [Note]: 7006 0

06/13/07 09:07:57 [Note]: 7011 172

06/13/07 09:07:57 [Note]: 7026 0

06/13/07 09:07:58 [Note]: 7026 0

06/13/07 09:08:03 [Note]: FSRAW library version 1.7.1021

06/13/07 09:12:56 [Note]: 7007 0

 

je n'ai pas le rapport Hijakthis , je te le post très bientôt

 

Chao, Cédric

Posté(e)
Salut

Alors voilà le resultat des opérations

1/ la recherche avec AVG Anti-Spyware a été réalisée sans la mise à jour car je n'ai même pas eu accés à la mise à jour.

Voici le résultat :

+ Résultat de l'analyse:

C:\AUTORUN.INF -> Trojan.Agent.ao : Nettoyé.

E:\AUTORUN.INF -> Trojan.Agent.ao : Nettoyé.

Fin du rapport

 

Et b]BlackLight[/b

06/13/07 09:07:12 [info]: BlackLight Engine 1.0.61 initialized

06/13/07 09:07:12 [info]: OS: 5.1 build 2600 (Service Pack 2)

06/13/07 09:07:12 [Note]: 7019 4

06/13/07 09:07:12 [Note]: 7005 0

06/13/07 09:07:57 [Note]: 7006 0

06/13/07 09:07:57 [Note]: 7011 172

06/13/07 09:07:57 [Note]: 7026 0

06/13/07 09:07:58 [Note]: 7026 0

06/13/07 09:08:03 [Note]: FSRAW library version 1.7.1021

06/13/07 09:12:56 [Note]: 7007 0

 

je n'ai pas le rapport Hijakthis , je te le post très bientôt

 

Chao, Cédric

 

 

et voici le rapport Hijackthis :

Logfile of HijackThis v1.99.1

Scan saved at 09:51:09 a.m., on 13/06/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\LEXBCES.EXE

C:\WINDOWS\system32\LEXPPS.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\pctspk.exe

C:\Archivos de programa\Java\jre1.5.0_05\bin\jusched.exe

C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe

C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe

C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

C:\Archivos de programa\Winamp\winampa.exe

C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Archivos de programa\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll

O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_05\bin\jusched.exe

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Archivos de programa\Google\Gmail Notifier\gnotify.exe

O4 - HKLM\..\Run: [AVP] "C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"

O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe

O4 - HKLM\..\Run: [iMJPMIG8.2] msime82.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsServer] msfun80.exe

O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmwordtrans.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\DOCUME~1\12\MISDOC~1\CDRIC~1\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Pages liées - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmbacklinks.html

O8 - Extra context menu item: Pages similaires - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsimilar.html

O8 - Extra context menu item: Recherche &Google - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmsearch.html

O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\archivos de programa\google\GoogleToolbar1.dll/cmcache.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe

O15 - Trusted Zone: http://www.antivirus-france.com

O15 - Trusted Zone: http://www.secuser.com

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab

O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.girafoto.fr/uploaders/ImageUploader3.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{96DEF815-EFFB-416A-82EA-8FB572DF068F}: NameServer = 192.168.3.1

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARCHIV~1\ARCHIV~1\Skype\SKYPE4~1.DLL

O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Archivos de programa\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

O23 - Service: MSCSPTISRV - Unknown owner - C:\Archivos de programa\Archivos comunes\Sony Shared\AVLib\MSCSPTISRV.exe (file missing)

O23 - Service: PACSPTISVR - Unknown owner - C:\Archivos de programa\Archivos comunes\Sony Shared\AVLib\PACSPTISVR.exe (file missing)

O23 - Service: Sony SPTI Service (SPTISRV) - Unknown owner - C:\Archivos de programa\Archivos comunes\Sony Shared\AVLib\SPTISRV.exe (file missing)

 

j'attends la suite maintenant

Merci

Cédric

Posté(e)

RE

 

Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/s...Disinfector.exe

 

 

 

Double-clique sur l’icône.

 

Les icônes vont disparaître. C’est normal.

 

Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau.

 

Redémarre ensuite le PC.

 

A plus.

Posté(e)
RE

 

Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/s...Disinfector.exe

 

 

 

Double-clique sur l’icône.

 

Les icônes vont disparaître. C’est normal.

 

Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau.

 

Redémarre ensuite le PC.

 

A plus.

 

j'ai executé mais rien!!!

alors, que faire? c'est vraiment bien compliqué et chi...

Merci pour ton aide et ton temps

Cédric

Posté(e)

Re

 

Bien continu comme ceci :

 

Télécharge SpySweeper (de Webroot) de ce lien (version d'essai de 14 jours) :

http://www.webroot.com/fr/land/karangatria...&ac=webroot

  • Clique sur "Télécharger la version test".
  • Installe le programme. Une fois installé, il se lancera.
  • L'option de le mettre à jour s'affichera; clic Yes.
  • Lorsque les mises à jour seront installées, clic Options sur la gauche.
  • Clic sur l'onglet Sweep Options.
  • Sous What to Sweep, coche les options suivantes:

    • Sweep Memory
    • Sweep Registry
    • Sweep Cookies
    • Sweep All User Accounts
    • Enable Direct Disk Sweeping
    • Sweep Contents of Compressed Files
    • Sweep for Rootkits
    • DÉCOCHE Do not Sweep System Restore Folder.

    [*]Clic Sweep Now sur la gauche.

    [*]Clic sur Start.

    [*]Quand le scan est terminé, clic sur Next.

    [*]Assure-toi que tous les items sont cochés, puis clic sur Next.

    [*]Tous les items cochés seront éliminés.

    [*]Si Spy Sweeper veut redémarrer pour terminer le nettoyage : ACCEPTE.

    [*]Clic Session Log au haut - à droite, et copie tout ce qu'il y a dans la fenêtre.

    [*]Clic sur l'onglet Summary, puis clic sur Finish.

    [*]Colle le contenu du "Session Log" dans ta prochaine réponse.

A plus.

Posté(e)
Re

 

Bien continu comme ceci :

 

Télécharge SpySweeper (de Webroot) de ce lien (version d'essai de 14 jours) :

http://www.webroot.com/fr/land/karangatria...&ac=webroot

  • Clique sur "Télécharger la version test".
  • Installe le programme. Une fois installé, il se lancera.
  • L'option de le mettre à jour s'affichera; clic Yes.
  • Lorsque les mises à jour seront installées, clic Options sur la gauche.
  • Clic sur l'onglet Sweep Options.
  • Sous What to Sweep, coche les options suivantes:

    • Sweep Memory
    • Sweep Registry
    • Sweep Cookies
    • Sweep All User Accounts
    • Enable Direct Disk Sweeping
    • Sweep Contents of Compressed Files
    • Sweep for Rootkits
    • DÉCOCHE Do not Sweep System Restore Folder.

    [*]Clic Sweep Now sur la gauche.

    [*]Clic sur Start.

    [*]Quand le scan est terminé, clic sur Next.

    [*]Assure-toi que tous les items sont cochés, puis clic sur Next.

    [*]Tous les items cochés seront éliminés.

    [*]Si Spy Sweeper veut redémarrer pour terminer le nettoyage : ACCEPTE.

    [*]Clic Session Log au haut - à droite, et copie tout ce qu'il y a dans la fenêtre.

    [*]Clic sur l'onglet Summary, puis clic sur Finish.

    [*]Colle le contenu du "Session Log" dans ta prochaine réponse.

A plus.

 

 

alors voici la suite :

07:46 a.m.: Removal process completed. Elapsed time 00:03:18

07:46 a.m.: Preparing to restart your computer. Please wait...

07:45 a.m.: Quarantining All Traces: topsearch

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\m.b.locatelli@free.fr\dfsr\staging\cs{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}1\129-{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v129-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}1\10-{d67ec1ad-d891-354b-2faa-50333e3041f7}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v10-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\16\121-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v16-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v121-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\13\13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\20\125-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v20-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v125-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\31\108-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v31-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v108-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\25\102-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v25-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v102-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\11\116-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v11-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v116-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\23\100-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v23-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v100-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\117-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v117-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\34\111-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v34-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v111-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\36\113-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v36-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v113-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\29\29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\24\101-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v24-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v101-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\19\124-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v19-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v124-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\127-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v127-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\15\120-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v15-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v120-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\128-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v128-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\30\107-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v30-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v107-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\14\14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\28\105-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v28-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v105-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\38\115-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v38-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v115-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\32\109-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v32-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v109-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\21\126-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v21-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v126-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\122-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v122-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\37\114-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v37-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v114-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\22\39-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v22-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v39-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\27\104-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v27-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v104-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\33\110-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v33-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v110-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\35\112-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v35-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v112-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\26\103-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v26-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v103-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\18\123-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v18-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v123-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: potentially rootkit-masked files is in use. It will be removed on reboot.

07:43 a.m.: Quarantining All Traces: potentially rootkit-masked files

07:43 a.m.: Removal process initiated

Operation: File Access

Target:

Source: C:\ARCHIVOS DE PROGRAMA\KASPERSKY LAB\KASPERSKY ANTI-VIRUS 6.0\AVP.EXE

06:25 a.m.: Tamper Detection

03:21 p.m.: Traces Found: 34

03:21 p.m.: Full Sweep has completed. Elapsed time 00:24:12

03:21 p.m.: File Sweep Complete, Elapsed Time: 00:19:49

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\m.b.locatelli@free.fr\dfsr\staging\cs{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}1\129-{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v129-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}1\10-{d67ec1ad-d891-354b-2faa-50333e3041f7}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v10-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\16\121-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v16-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v121-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\13\13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\20\125-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v20-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v125-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\31\108-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v31-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v108-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\25\102-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v25-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v102-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\11\116-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v11-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v116-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\23\100-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v23-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v100-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\117-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v117-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\34\111-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v34-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v111-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\36\113-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v36-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v113-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\29\29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\24\101-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v24-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v101-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\19\124-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v19-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v124-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\127-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v127-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\15\120-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v15-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v120-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\128-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v128-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\30\107-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v30-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v107-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\14\14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\28\105-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v28-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v105-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\38\115-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v38-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v115-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\32\109-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v32-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v109-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\21\126-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v21-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v126-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\122-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v122-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\37\114-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v37-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v114-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\22\39-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v22-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v39-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\27\104-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v27-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v104-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\33\110-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v33-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v110-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\35\112-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v35-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v112-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\26\103-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v26-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v103-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\18\123-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v18-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v123-downloaded.frx (ID = 0)

03:11 p.m.: Found System Monitor: potentially rootkit-masked files

03:10 p.m.: Warning: Failed to access drive D:

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\datos de programa\skype\elcedo1\profile256.dbb". La operación se ha completado correctamente

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\configuración local\temp\~df911e.tmp". La operación se ha completado correctamente

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\configuración local\temp\~df8d09.tmp". La operación se ha completado correctamente

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\datos de programa\skype\elcedo1\chat256.dbb". La operación se ha completado correctamente

03:01 p.m.: Starting File Sweep

03:01 p.m.: Warning: Failed to access drive A:

03:01 p.m.: Cookie Sweep Complete, Elapsed Time: 00:00:00

03:01 p.m.: Starting Cookie Sweep

03:01 p.m.: Registry Sweep Complete, Elapsed Time:00:00:41

03:00 p.m.: HKCR\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (ID = 143930)

03:00 p.m.: HKLM\software\classes\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (ID = 143928)

03:00 p.m.: Found Adware: topsearch

03:00 p.m.: Starting Registry Sweep

03:00 p.m.: Memory Sweep Complete, Elapsed Time: 00:03:30

02:56 p.m.: Starting Memory Sweep

02:56 p.m.: Sweep initiated using definitions version 734

02:56 p.m.: Spy Sweeper 5.0.7.1608 started

02:56 p.m.: | Start of Session, Miércoles, 13 de Junio de 2007 |

********

02:56 p.m.: | End of Session, Miércoles, 13 de Junio de 2007 |

Keylogger Shield: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites Shield: Off

Hosts File Shield: On

Spy Communication Shield: On

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: On

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

02:54 p.m.: Shield States

02:54 p.m.: Spyware Definitions: 734

02:54 p.m.: Spy Sweeper 5.0.7.1608 started

02:54 p.m.: Spy Sweeper 5.0.7.1608 started

02:54 p.m.: | Start of Session, Miércoles, 13 de Junio de 2007 |

********

 

et avec ça?

Je commence à croire qu'il n'y a pas de virus mais un autre pb et que formater sera la meilleure solution.

A plus tard

Cédric

 

Re

 

Bien continu comme ceci :

 

Télécharge SpySweeper (de Webroot) de ce lien (version d'essai de 14 jours) :

http://www.webroot.com/fr/land/karangatria...&ac=webroot

  • Clique sur "Télécharger la version test".
  • Installe le programme. Une fois installé, il se lancera.
  • L'option de le mettre à jour s'affichera; clic Yes.
  • Lorsque les mises à jour seront installées, clic Options sur la gauche.
  • Clic sur l'onglet Sweep Options.
  • Sous What to Sweep, coche les options suivantes:

    • Sweep Memory
    • Sweep Registry
    • Sweep Cookies
    • Sweep All User Accounts
    • Enable Direct Disk Sweeping
    • Sweep Contents of Compressed Files
    • Sweep for Rootkits
    • DÉCOCHE Do not Sweep System Restore Folder.

    [*]Clic Sweep Now sur la gauche.

    [*]Clic sur Start.

    [*]Quand le scan est terminé, clic sur Next.

    [*]Assure-toi que tous les items sont cochés, puis clic sur Next.

    [*]Tous les items cochés seront éliminés.

    [*]Si Spy Sweeper veut redémarrer pour terminer le nettoyage : ACCEPTE.

    [*]Clic Session Log au haut - à droite, et copie tout ce qu'il y a dans la fenêtre.

    [*]Clic sur l'onglet Summary, puis clic sur Finish.

    [*]Colle le contenu du "Session Log" dans ta prochaine réponse.

A plus.

 

 

alors voici la suite :

07:46 a.m.: Removal process completed. Elapsed time 00:03:18

07:46 a.m.: Preparing to restart your computer. Please wait...

07:45 a.m.: Quarantining All Traces: topsearch

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\m.b.locatelli@free.fr\dfsr\staging\cs{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}1\129-{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v129-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}1\10-{d67ec1ad-d891-354b-2faa-50333e3041f7}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v10-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\16\121-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v16-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v121-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\13\13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\20\125-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v20-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v125-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\31\108-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v31-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v108-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\25\102-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v25-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v102-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\11\116-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v11-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v116-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\23\100-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v23-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v100-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\117-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v117-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\34\111-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v34-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v111-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\36\113-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v36-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v113-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\29\29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\24\101-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v24-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v101-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\19\124-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v19-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v124-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\127-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v127-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\15\120-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v15-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v120-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\128-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v128-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\30\107-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v30-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v107-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\14\14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\28\105-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v28-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v105-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\38\115-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v38-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v115-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\32\109-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v32-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v109-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\21\126-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v21-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v126-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\122-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v122-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\37\114-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v37-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v114-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\22\39-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v22-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v39-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\27\104-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v27-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v104-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\33\110-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v33-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v110-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\35\112-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v35-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v112-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\26\103-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v26-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v103-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\18\123-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v18-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v123-downloaded.frx is in use. It will be removed on reboot.

07:45 a.m.: potentially rootkit-masked files is in use. It will be removed on reboot.

07:43 a.m.: Quarantining All Traces: potentially rootkit-masked files

07:43 a.m.: Removal process initiated

Operation: File Access

Target:

Source: C:\ARCHIVOS DE PROGRAMA\KASPERSKY LAB\KASPERSKY ANTI-VIRUS 6.0\AVP.EXE

06:25 a.m.: Tamper Detection

03:21 p.m.: Traces Found: 34

03:21 p.m.: Full Sweep has completed. Elapsed time 00:24:12

03:21 p.m.: File Sweep Complete, Elapsed Time: 00:19:49

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\m.b.locatelli@free.fr\dfsr\staging\cs{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}1\129-{6ab3b38e-5547-6a1e-1f7a-f4a6d6a8d33c}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v129-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}1\10-{d67ec1ad-d891-354b-2faa-50333e3041f7}-v1-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v10-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\16\121-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v16-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v121-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\13\13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v13-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\20\125-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v20-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v125-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\31\108-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v31-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v108-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\25\102-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v25-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v102-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\11\116-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v11-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v116-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\23\100-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v23-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v100-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\117-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v117-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\34\111-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v34-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v111-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\36\113-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v36-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v113-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\29\29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v29-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\24\101-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v24-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v101-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\19\124-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v19-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v124-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\127-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v127-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\15\120-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v15-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v120-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\12\128-{4b823a4a-962a-4b8c-9ef7-9228e3a26c63}-v12-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v128-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\30\107-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v30-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v107-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\14\14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v14-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\28\105-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v28-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v105-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\38\115-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v38-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v115-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\32\109-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v32-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v109-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\21\126-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v21-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v126-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\17\122-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v17-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v122-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\37\114-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v37-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v114-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\22\39-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v22-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v39-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\27\104-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v27-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v104-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\33\110-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v33-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v110-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\35\112-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v35-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v112-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\26\103-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v26-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v103-downloaded.frx (ID = 0)

03:11 p.m.: c:\documents and settings\12\configuración local\datos de programa\microsoft\messenger\ced_berger@hotmail.com\sharingmetadata\cristian_medina@hotmail.com\dfsr\staging\cs{d67ec1ad-d891-354b-2faa-50333e3041f7}\18\123-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v18-{add8a414-7383-46c1-8c2f-9d608baae1a8}-v123-downloaded.frx (ID = 0)

03:11 p.m.: Found System Monitor: potentially rootkit-masked files

03:10 p.m.: Warning: Failed to access drive D:

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\datos de programa\skype\elcedo1\profile256.dbb". La operación se ha completado correctamente

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\configuración local\temp\~df911e.tmp". La operación se ha completado correctamente

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\configuración local\temp\~df8d09.tmp". La operación se ha completado correctamente

03:09 p.m.: Warning: Failed to open file "c:\documents and settings\12\datos de programa\skype\elcedo1\chat256.dbb". La operación se ha completado correctamente

03:01 p.m.: Starting File Sweep

03:01 p.m.: Warning: Failed to access drive A:

03:01 p.m.: Cookie Sweep Complete, Elapsed Time: 00:00:00

03:01 p.m.: Starting Cookie Sweep

03:01 p.m.: Registry Sweep Complete, Elapsed Time:00:00:41

03:00 p.m.: HKCR\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (ID = 143930)

03:00 p.m.: HKLM\software\classes\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (ID = 143928)

03:00 p.m.: Found Adware: topsearch

03:00 p.m.: Starting Registry Sweep

03:00 p.m.: Memory Sweep Complete, Elapsed Time: 00:03:30

02:56 p.m.: Starting Memory Sweep

02:56 p.m.: Sweep initiated using definitions version 734

02:56 p.m.: Spy Sweeper 5.0.7.1608 started

02:56 p.m.: | Start of Session, Miércoles, 13 de Junio de 2007 |

********

02:56 p.m.: | End of Session, Miércoles, 13 de Junio de 2007 |

Keylogger Shield: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites Shield: Off

Hosts File Shield: On

Spy Communication Shield: On

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: On

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

02:54 p.m.: Shield States

02:54 p.m.: Spyware Definitions: 734

02:54 p.m.: Spy Sweeper 5.0.7.1608 started

02:54 p.m.: Spy Sweeper 5.0.7.1608 started

02:54 p.m.: | Start of Session, Miércoles, 13 de Junio de 2007 |

********

 

et avec ça?

Je commence à croire qu'il n'y a pas de virus mais un autre pb et que formater sera la meilleure solution.

A plus tard

Cédric

Posté(e)

Salut !

 

Formater ? nan je pense qu'on en est pas là pour l'instant :P

 

Fait ceci stp :

 

Télécharge Gmer ici :

http://gmer.net/gmer110.zip

 

Ensuite du decompresse l'archive et tu clique sur l'icone Gmer

 

Clique sur l'onglet Rootkit

Vérifie que tout soit coché à droite :

  1. System
  2. Devices
  3. Proceses
  4. Libraries
  5. Modules
  6. Services
  7. Registry
  8. Files

Ensuite clique sur scan et laisse le faire son travail.

 

A la fin du scan clique sur copy

Dans ton prochain message fais clique droit/copier

 

Merci de bien lire et suivre attentivement ce qui est écrit car tu dois appuyer sur une touche lors du scan.. si tu ne le fais pas le rapport ne sera pas entier et tu devras recommencer donc :

 

- Télécharge DiagHelp.zip sur ton bureau - Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php

- Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout

- Un nouveau dossier chercher va être créé DiagHelp

- Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)

- Une fenêtre va s'ouvrir, choisis l'option 1

- L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.

 

ATTENTION : pendant l'analyse, après le rapport catchme, il te sera demandé d'appuyer sur une touche afin de poursuivre le scan, suis bien les instructions à l'écran !

 

- A la fin de l'analyse, il peut-être (pas obligatoire) demandé de redemanderl'ordinateur... Une fois l'ordinateur redémarré le rapport va apparaître sur le bloc-note.. Ce dernier se trouve sur C:\resultat.txt

- Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :

-- Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout

-- A nouveau menu Edition / copier

-- Dans un nouveau message ici, faire un clic droit / coller

 

Et enfin :

 

fais un scan en ligne ici :

Panda si tu n'y arrives pas : tutorial

 

A plus.

Posté(e)
Salut !

 

Formater ? nan je pense qu'on en est pas là pour l'instant :P

 

Fait ceci stp :

 

Télécharge Gmer ici :

http://gmer.net/gmer110.zip

 

Ensuite du decompresse l'archive et tu clique sur l'icone Gmer

 

Clique sur l'onglet Rootkit

Vérifie que tout soit coché à droite :

  1. System
  2. Devices
  3. Proceses
  4. Libraries
  5. Modules
  6. Services
  7. Registry
  8. Files

Ensuite clique sur scan et laisse le faire son travail.

 

A la fin du scan clique sur copy

Dans ton prochain message fais clique droit/copier

 

Merci de bien lire et suivre attentivement ce qui est écrit car tu dois appuyer sur une touche lors du scan.. si tu ne le fais pas le rapport ne sera pas entier et tu devras recommencer donc :

 

- Télécharge DiagHelp.zip sur ton bureau - Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php

- Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout

- Un nouveau dossier chercher va être créé DiagHelp

- Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)

- Une fenêtre va s'ouvrir, choisis l'option 1

- L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.

 

ATTENTION : pendant l'analyse, après le rapport catchme, il te sera demandé d'appuyer sur une touche afin de poursuivre le scan, suis bien les instructions à l'écran !

 

- A la fin de l'analyse, il peut-être (pas obligatoire) demandé de redemanderl'ordinateur... Une fois l'ordinateur redémarré le rapport va apparaître sur le bloc-note.. Ce dernier se trouve sur C:\resultat.txt

- Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :

-- Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout

-- A nouveau menu Edition / copier

-- Dans un nouveau message ici, faire un clic droit / coller

 

Et enfin :

 

fais un scan en ligne ici :

Panda si tu n'y arrives pas : tutorial

 

A plus.

 

Salut

Comment faire pour effacer tous les messages que j'ai postés par erreur?

La suite :

iagHelp version v1.1.1 - http://www.malekal.com

excute le 14/06/2007 à 11:40:24,70

 

 

Liste des derniers fichies modifies/crees dans windir\system32

C:\WINDOWS\System32/drivers\fidbox2.dat -->14/06/2007 11:37:32 a.m.

C:\WINDOWS\System32/drivers\gmer.sys -->14/06/2007 11:28:57 a.m.

C:\WINDOWS\System32/drivers\fidbox2.idx -->14/06/2007 07:47:58 a.m.

C:\WINDOWS\System32/drivers\fidbox.idx -->14/06/2007 07:47:57 a.m.

C:\WINDOWS\System32/drivers\fidbox.dat -->14/06/2007 07:47:57 a.m.

C:\WINDOWS\System32/drivers\klin.dat -->17/05/2007 07:37:30 a.m.

C:\WINDOWS\System32/drivers\klick.dat -->17/05/2007 07:37:29 a.m.

 

C:\WINDOWS\System32\wpa.dbl -->12/06/2007 07:52:59 a.m.

C:\WINDOWS\System32\PerfStringBackup.INI -->06/06/2007 08:06:59 a.m.

C:\WINDOWS\System32\perfh00A.dat -->06/06/2007 08:06:59 a.m.

C:\WINDOWS\System32\perfh009.dat -->06/06/2007 08:06:59 a.m.

C:\WINDOWS\System32\perfc00A.dat -->06/06/2007 08:06:59 a.m.

C:\WINDOWS\System32\perfc009.dat -->06/06/2007 08:06:59 a.m.

C:\WINDOWS\System32\vxblock.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxwave.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxsfs.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxmas.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxinsa64.exe -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxhpinst.exe -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxdrv.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxcpya64.exe -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\pxafs.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\px.dll -->07/03/2007 06:51:00 p.m.

C:\WINDOWS\System32\FNTCACHE.DAT -->22/02/2007 05:46:46 p.m.

C:\WINDOWS\System32\VQW -->22/02/2007 05:44:08 p.m.

C:\WINDOWS\System32\CONFIG.NT -->22/02/2007 04:23:50 p.m.

C:\WINDOWS\System32\klogon.dll -->29/01/2007 11:04:00 p.m.

C:\WINDOWS\System32\sirenacm.dll -->19/01/2007 12:53:04 p.m.

C:\WINDOWS\System32\aswBoot.exe -->15/01/2007 12:32:07 p.m.

C:\WINDOWS\System32\SIntfNT.dll -->27/09/2006 02:42:09 p.m.

C:\WINDOWS\System32\SIntf32.dll -->27/09/2006 02:42:09 p.m.

C:\WINDOWS\System32\SIntf16.dll -->27/09/2006 02:42:09 p.m.

 

C:\WINDOWS\ntbtlog.txt -->14/06/2007 11:28:58 a.m.

C:\WINDOWS\gmer.ini -->14/06/2007 11:28:58 a.m.

C:\WINDOWS\gmer.dll -->14/06/2007 11:28:57 a.m.

C:\WINDOWS\WindowsUpdate.log -->14/06/2007 08:57:58 a.m.

C:\WINDOWS.log -->14/06/2007 07:49:36 a.m.

C:\WINDOWS\wiadebug.log -->14/06/2007 07:49:07 a.m.

C:\WINDOWS\wiaservc.log -->14/06/2007 07:49:06 a.m.

C:\WINDOWS\bootstat.dat -->14/06/2007 07:48:46 a.m.

C:\WINDOWS\SchedLgU.Txt -->14/06/2007 07:47:46 a.m.

C:\WINDOWS\LEXSTAT.INI -->13/06/2007 03:14:11 p.m.

C:\WINDOWS\win.ini -->13/06/2007 02:53:33 p.m.

C:\WINDOWS\setupapi.log -->12/06/2007 10:57:23 a.m.

C:\WINDOWS\winamp.ini -->03/05/2007 02:00:15 p.m.

C:\WINDOWS\SVCHOST.INI -->02/05/2007 01:51:58 p.m.

C:\WINDOWS\wininit.ini -->26/03/2007 07:57:24 a.m.

 

 

El volumen de la unidad C no tiene etiqueta.

El número de serie del volumen es: A8BE-6BEE

 

Directorio de C:\WINDOWS\system32

 

19/08/2004 03:42 p.m. 6.144 csrss.exe

1 archivos 6.144 bytes

0 dirs 3.998.834.688 bytes libres

 

Contenu de Downloaded Program Files

El volumen de la unidad C no tiene etiqueta.

El número de serie del volumen es: A8BE-6BEE

 

Directorio de C:\WINDOWS\Downloaded Program Files

 

07/06/2007 09:58 a.m. <DIR> .

07/06/2007 09:58 a.m. <DIR> ..

07/12/2004 05:07 p.m. 32 bdcore.dll

25/05/2006 01:21 a.m. 118.784 bdupd.dll

21/02/2004 08:42 p.m. 65 desktop.ini

14/10/1997 06:52 p.m. 697 DirectAnimation Java Classes.osd

26/08/2005 06:39 p.m. 379 ImageUploader3.inf

26/08/2005 06:39 p.m. 1.893.912 ImageUploader3.ocx

25/05/2006 01:21 a.m. 53.248 ipsupd.dll

08/08/2006 11:45 a.m. 576 kavwebscan.inf

16/03/2005 12:34 p.m. 7.407 lang.ini

07/12/2004 05:07 p.m. 32 libfn.dll

14/03/2005 02:38 p.m. 126 live.ini

20/01/2000 03:25 p.m. 1.162 Microsoft XML Parser for Java.osd

01/06/2006 02:57 a.m. 1.331 oscan8.inf

01/06/2006 02:54 a.m. 471.040 oscan8.ocx

31/05/2006 04:15 a.m. 10 oscan81.ocx_x

14/03/2005 02:58 p.m. 7.073 scanoptions.tsi

08/12/2003 01:58 p.m. 3.759 swflash.inf

17 archivos 2.559.633 bytes

 

Total de archivos en la lista:

17 archivos 2.559.633 bytes

2 dirs 3.998.830.592 bytes libres

 

Recherche de rootkit! (Merci S!Ri)

 

Recherche d'infections connues

 

Export des clefs sensibles..

 

Liste des fichiers en exception sur le pare-feu XP SP2

 

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Archivos de programa\\Messenger\\msmsgs.exe"="C:\\Archivos de programa\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

"C:\\Archivos de programa\\eMule\\emule.exe"="C:\\Archivos de programa\\eMule\\emule.exe:*:Enabled:eMule"

"C:\\Archivos de programa\\Internet Explorer\\iexplore.exe"="C:\\Archivos de programa\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"

"C:\\Archivos de programa\\Opera\\Opera.exe"="C:\\Archivos de programa\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser"

"C:\\Archivos de programa\\Azureus\\Azureus.exe"="C:\\Archivos de programa\\Azureus\\Azureus.exe:*:Enabled:Azureus"

"C:\\WINDOWS\\system32\\svchost.exe"="C:\\WINDOWS\\system32\\svchost.exe:*:Enabled:Microsoft Update"

"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

"C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

"C:\\Archivos de programa\\Skype\\Phone\\Skype.exe"="C:\\Archivos de programa\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "

 

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"

"C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

 

Export de la clef SharedTaskScheduler

 

[sharedTaskScheduler]

"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Precargador Browseui"

"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Demonio de caché de las categorías de componente"

 

Rechercher adresses sensibles dans le fichier HOSTS...

 

 

 

 

KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

 

Process list by traversal of KiWaitListHead

 

4 - System

196 - WINWORD.EXE

320 - cmd.exe

480 - csrss.exe

504 - winlogon.exe

548 - services.exe

560 - lsass.exe

720 - svchost.exe

772 - svchost.exe

836 - svchost.exe

884 - svchost.exe

980 - svchost.exe

1104 - spoolsv.exe

1112 - LEXPPS.EXE

1388 - explorer.exe

1480 - pctspk.exe

1496 - MsgPlus.exe

1504 - gnotify.exe

1512 - avp.exe

1520 - winampa.exe

1528 - SpySweeperUI.ex

1556 - ctfmon.exe

1756 - guard.exe

1768 - avp.exe

1808 - MDM.EXE

1896 - SpySweeper.exe

2172 - firefox.exe

2188 - ssu.exe

2720 - Skype.exe

3044 - skypePM.exe

 

Total number of processes = 30

NOTE: Under WinXP, this will not show all processes.

 

KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

 

Driver/Module list by traversal of PsLoadedModuleList

 

804D7000 - \WINDOWS\system32\ntoskrnl.exe

806ED000 - \WINDOWS\system32\hal.dll

FA3AC000 - \WINDOWS\system32\KDCOM.DLL

FA2BC000 - \WINDOWS\system32\BOOTVID.dll

F9E5C000 - ACPI.sys

FA3AE000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS

F9E4B000 - pci.sys

F9EAC000 - isapnp.sys

F9EBC000 - SSHRMD.SYS

FA12C000 - SSFS0509.SYS

F9E29000 - SSIDRV.SYS

F9DFC000 - \WINDOWS\SYSTEM32\Drivers\NDIS.SYS

FA134000 - \WINDOWS\SYSTEM32\Drivers\TDI.SYS

FA3B0000 - viaide.sys

FA13C000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS

F9ECC000 - MountMgr.sys

F9DDD000 - ftdisk.sys

FA3B2000 - dmload.sys

F9DB7000 - dmio.sys

FA144000 - PartMgr.sys

F9EDC000 - VolSnap.sys

F9D9F000 - atapi.sys

F9EEC000 - disk.sys

F9EFC000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS

F9D80000 - fltmgr.sys

F9F0C000 - PxHelp20.sys

F9D69000 - KSecDD.sys

F9CDC000 - Ntfs.sys

F9F1C000 - vvoice.sys

F9C79000 - vpctcom.sys

F9BF9000 - vmodem.sys

F9F2C000 - viaagp.sys

FA14C000 - viaagp1.sys

F9BDE000 - Mup.sys

F9BC2000 - kl1.sys

FA08C000 - \SystemRoot\System32\DRIVERS\intelppm.sys

F9B53000 - \SystemRoot\System32\DRIVERS\s3gnbm.sys

F9B3F000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS

FA3E0000 - \SystemRoot\System32\Drivers\vulfnth.sys

FA1E4000 - \SystemRoot\System32\DRIVERS\usbuhci.sys

F9B1C000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS

FA1EC000 - \SystemRoot\System32\DRIVERS\usbehci.sys

FA09C000 - \SystemRoot\System32\DRIVERS\cdrom.sys

FA0AC000 - \SystemRoot\System32\DRIVERS\redbook.sys

F9AF9000 - \SystemRoot\System32\DRIVERS\ks.sys

FA0BC000 - \SystemRoot\system32\drivers\viaudio.sys

F9AD5000 - \SystemRoot\system32\drivers\portcls.sys

FA0CC000 - \SystemRoot\system32\drivers\drmk.sys

F9AB4000 - \SystemRoot\System32\DRIVERS\ptserial.sys

FA1F4000 - \SystemRoot\System32\Drivers\Modem.SYS

FA0DC000 - \SystemRoot\System32\DRIVERS\fetnd5b.sys

FA1FC000 - \SystemRoot\System32\DRIVERS\fdc.sys

F9AA3000 - \SystemRoot\System32\DRIVERS\serial.sys

FA394000 - \SystemRoot\System32\DRIVERS\serenum.sys

F9A8F000 - \SystemRoot\System32\DRIVERS\parport.sys

FA0EC000 - \SystemRoot\System32\DRIVERS\i8042prt.sys

FA204000 - \SystemRoot\System32\DRIVERS\mouclass.sys

FA10C000 - \SystemRoot\System32\Drivers\sskbfd.sys

FA20C000 - \SystemRoot\System32\DRIVERS\kbdclass.sys

FA5AC000 - \SystemRoot\system32\drivers\msmpu401.sys

FA398000 - \SystemRoot\System32\DRIVERS\gameenum.sys

FA5B0000 - \SystemRoot\System32\DRIVERS\audstub.sys

FA11C000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys

FA39C000 - \SystemRoot\System32\DRIVERS\ndistapi.sys

F9A50000 - \SystemRoot\System32\DRIVERS\ndiswan.sys

F9F5C000 - \SystemRoot\System32\DRIVERS\raspppoe.sys

F9F6C000 - \SystemRoot\System32\DRIVERS\raspptp.sys

FA214000 - \SystemRoot\System32\DRIVERS\ptilink.sys

FA21C000 - \SystemRoot\System32\DRIVERS\raspti.sys

F997F000 - \SystemRoot\System32\DRIVERS\rdpdr.sys

F9F7C000 - \SystemRoot\System32\DRIVERS\termdd.sys

FA3EC000 - \SystemRoot\System32\DRIVERS\swenum.sys

F994B000 - \SystemRoot\System32\DRIVERS\update.sys

F9B9E000 - \SystemRoot\System32\DRIVERS\mssmbios.sys

F9F9C000 - \SystemRoot\System32\Drivers\NDProxy.SYS

FA344000 - \SystemRoot\System32\Drivers\vulfntr.sys

F9FAC000 - \SystemRoot\System32\DRIVERS\usbhub.sys

FA3EE000 - \SystemRoot\System32\DRIVERS\USBD.SYS

FA364000 - \SystemRoot\system32\drivers\MODEMCSA.sys

FA254000 - \SystemRoot\System32\DRIVERS\flpydisk.sys

FA416000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS

FA4A3000 - \SystemRoot\System32\Drivers\Null.SYS

FA418000 - \SystemRoot\System32\Drivers\Beep.SYS

FA4A4000 - \SystemRoot\System32\DRIVERS\AvgAsCln.sys

FA264000 - \SystemRoot\System32\drivers\vga.sys

FA41A000 - \SystemRoot\System32\Drivers\mnmdd.SYS

FA41C000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys

FA26C000 - \SystemRoot\System32\Drivers\Msfs.SYS

FA274000 - \SystemRoot\System32\Drivers\Npfs.SYS

FA36C000 - \SystemRoot\System32\DRIVERS\rasacd.sys

F7800000 - \SystemRoot\System32\DRIVERS\ipsec.sys

F9FFC000 - \SystemRoot\System32\DRIVERS\msgpc.sys

F77A8000 - \SystemRoot\System32\DRIVERS\tcpip.sys

F7780000 - \SystemRoot\System32\DRIVERS\netbt.sys

F775E000 - \SystemRoot\System32\drivers\afd.sys

FA00C000 - \SystemRoot\System32\DRIVERS\netbios.sys

F7732000 - \SystemRoot\System32\DRIVERS\rdbss.sys

F76C3000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys

F7688000 - \??\C:\WINDOWS\system32\drivers\klif.sys

FA03C000 - \SystemRoot\System32\Drivers\Fips.SYS

F7667000 - \SystemRoot\System32\DRIVERS\ipnat.sys

FA05C000 - \SystemRoot\System32\DRIVERS\wanarp.sys

FA4BA000 - \??\C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.sys

FA284000 - \SystemRoot\system32\DRIVERS\usbprint.sys

F9A00000 - \SystemRoot\System32\Drivers\Cdfs.SYS

F7587000 - \SystemRoot\System32\Drivers\dump_atapi.sys

FA442000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS

BF800000 - \SystemRoot\System32\win32k.sys

FA16C000 - \SystemRoot\System32\watchdog.sys

FA358000 - \SystemRoot\System32\drivers\Dxapi.sys

BF9C1000 - \SystemRoot\System32\drivers\dxg.sys

FA477000 - \SystemRoot\System32\drivers\dxgthk.sys

BF9D3000 - \SystemRoot\System32\s3gnb.dll

F2BA1000 - \SystemRoot\system32\drivers\wdmaud.sys

F2D26000 - \SystemRoot\system32\drivers\sysaudio.sys

F2877000 - \SystemRoot\System32\DRIVERS\mrxdav.sys

FA45C000 - \SystemRoot\System32\Drivers\ParVdm.SYS

FA52E000 - \SystemRoot\system32\SetupNT.sys

F266C000 - \SystemRoot\System32\DRIVERS\srv.sys

F2621000 - \SystemRoot\System32\Drivers\Fastfat.SYS

F2428000 - \SystemRoot\System32\Drivers\HTTP.sys

F210F000 - \SystemRoot\System32\Drivers\SPCA561.SYS

F2964000 - \SystemRoot\System32\Drivers\STREAM.SYS

F201B000 - \SystemRoot\system32\drivers\kmixer.sys

F2045000 - \SystemRoot\System32\DRIVERS\gmer.sys

FA4AD000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys

 

Total number of drivers = 126

 

Liste des programmes installes

 

1000 mots pour apprendre à lire V 2.0

Adobe Reader 7.0.9 - Español

Apple Software Update

Archiveur WinRAR

Audacity 1.2.4

AutoUpdate

AVG Anti-Spyware 7.5

Azureus

Barra Yahoo! con bloqueador de ventanas emergentes

Bibliothèques GTK+ 2.6.9 rev a (supprimer uniquement)

CCleaner (remove only)

CDex extraction audio

DivX

DivX Player

EuroThink Lune

EVEREST Home Edition v2.20

FastStone Image Viewer 2.8 (French)

Franklin va à l'école

Google Gmail Notifier

Google Toolbar for Internet Explorer

HijackThis 1.99.1

Hijackthis Version Française

HSP56 MR Drivers

ICatch (VI) PC Camera

J2SE Runtime Environment 5.0 Update 5

Kaspersky Anti-Virus 6.0

Kaspersky Anti-Virus 6.0

Kaspersky Online Scanner

Lecto

Lexmark Z600 Series

Messenger Plus! 3

Microsoft .NET Framework 2.0

Microsoft .NET Framework 2.0

Microsoft Office Professional Edition 2003

Microsoft Office Standard Edition 2003

Mozilla Firefox (2.0.0.4)

OpenMG Limited Patch 4.1-05-14-24-01

Opera 9.21

Pack Longhorn Inspirat 1.0

ProSavageDDR and Utilities

QuickTime for Windows (32-bit)

Radio Fr Solo 2.1

Revisión de Windows XP - KB887472

S3Display

S3Gamma2

S3Info2

S3Overlay

Skype 3.1

Skype Plugin Manager

Spy Sweeper

Tibili

VIA Audio Driver Setup Program

VideoLAN VLC media player 0.8.5

WebFldrs XP

Winamp (remove only)

Windows Live Messenger

Windows Live Sign-in Assistant

Windows XP Service Pack 2

Yahoo! Toolbar

 

 

 

El volumen de la unidad C no tiene etiqueta.

El número de serie del volumen es: A8BE-6BEE

 

Directorio de C:\Archivos de programa

 

13/06/2007 02:53 p.m. <DIR> .

13/06/2007 02:53 p.m. <DIR> ..

25/01/2006 01:39 p.m. <DIR> Adobe

25/09/2006 02:33 p.m. <DIR> Apple Software Update

03/05/2007 04:05 p.m. <DIR> Archivos comunes

30/01/2006 10:44 a.m. 385.648 aswclnr.exe

07/06/2007 12:01 p.m. 2.050 aswclnr.log

10/10/2006 11:50 a.m. <DIR> Audacity

05/10/2006 11:49 a.m. 2.327.233 audacity-win-1.2.4b.exe

01/07/2005 01:24 p.m. 12.298.536 avg70free_323a539.exe

26/10/2006 01:16 p.m. <DIR> Azureus

24/05/2007 10:22 a.m. <DIR> CCleaner

06/12/2006 07:53 a.m. <DIR> CDex_170b2

28/03/2007 09:51 a.m. <DIR> Common Files

21/02/2004 08:39 p.m. <DIR> ComPlus Applications

29/03/2007 09:59 a.m. <DIR> DivX

12/06/2007 02:39 p.m. <DIR> eMule

31/01/2006 11:38 a.m. 2.606.057 eMule0.47a.zip

03/05/2007 04:59 p.m. <DIR> FastStone Image Viewer

30/08/2006 12:00 p.m. <DIR> Google

13/06/2007 07:56 a.m. <DIR> Grisoft

13/06/2007 09:51 a.m. <DIR> Hijackthis Version Française

24/10/2005 01:01 p.m. <DIR> Home

13/12/2005 02:00 p.m. 294.595 imageenhance.zip

06/06/2007 07:58 a.m. <DIR> Internet Explorer

24/10/2005 12:37 p.m. <DIR> Java

01/03/2007 02:49 p.m. <DIR> Kaspersky Lab

10/10/2006 11:49 a.m. 525.012 lame3.97.zip

22/03/2007 01:12 p.m. <DIR> Lavalys

29/03/2007 09:59 a.m. <DIR> Messenger

24/04/2006 08:40 a.m. <DIR> MessengerPlus! 3

21/02/2004 08:43 p.m. <DIR> microsoft frontpage

06/02/2007 11:33 a.m. <DIR> Microsoft Office

09/03/2004 11:16 a.m. <DIR> Microsoft Visual Studio

27/11/2006 02:06 p.m. <DIR> Microsoft Works

29/03/2007 09:59 a.m. <DIR> Movie Maker

07/06/2007 09:55 a.m. <DIR> Mozilla Firefox

07/06/2007 09:46 a.m. 5.823.256 mozilla-firefox_mozilla_firefox_2.0.0.4_francais_11003.exe

21/02/2004 08:39 p.m. <DIR> MSN

21/02/2004 08:39 p.m. <DIR> MSN Gaming Zone

06/02/2007 10:29 a.m. <DIR> MSN Messenger

14/02/2003 04:26 a.m. <DIR> NetMeeting

22/05/2007 08:20 a.m. <DIR> Opera

23/08/2005 01:19 p.m. <DIR> Outlook Express

28/03/2007 09:58 a.m. <DIR> QuickTime

25/09/2006 02:20 p.m. 19.666.504 QuickTimeInstaller.exe

14/03/2007 01:48 p.m. <DIR> Radio Fr Solo

23/08/2005 10:06 a.m. 1.775.108 radio-fr-amp_1.8_solo_francais_11078.exe

21/02/2004 08:51 p.m. <DIR> S3Inc

21/02/2004 08:41 p.m. <DIR> Servicios en línea

28/03/2007 11:19 a.m. <DIR> Skype

26/03/2007 07:26 a.m. <DIR> Spyware Terminator

23/08/2005 12:36 p.m. <DIR> TClockEx

07/06/2007 11:47 a.m. <DIR> Trillian

21/02/2004 08:51 p.m. <DIR> VIA Technologies, Inc

10/10/2005 10:52 a.m. <DIR> VideoLAN

13/06/2007 02:53 p.m. <DIR> Webroot

02/10/2006 02:50 p.m. <DIR> Webteh

07/06/2007 08:40 a.m. <DIR> Winamp

20/09/2005 02:54 p.m. 6.224.432 winamp51_full_emusic-7plus.exe

18/09/2006 02:34 p.m. <DIR> Windows Live Safety Center

29/03/2007 09:59 a.m. <DIR> Windows Media Player

14/02/2003 04:25 a.m. <DIR> Windows NT

13/10/2005 12:15 p.m. <DIR> WinRAR

13/10/2005 12:14 p.m. 1.106.812 wrar350fr.exe

21/02/2004 08:43 p.m. <DIR> xerox

26/01/2007 02:25 p.m. <DIR> Yahoo!

12 archivos 53.035.243 bytes

55 dirs 3.999.059.968 bytes libres

El volumen de la unidad C no tiene etiqueta.

El número de serie del volumen es: A8BE-6BEE

 

Directorio de C:\Archivos de programa\common files

 

28/03/2007 09:51 a.m. <DIR> .

28/03/2007 09:51 a.m. <DIR> ..

28/03/2007 09:51 a.m. <DIR> GTK

0 archivos 0 bytes

3 dirs 3.999.059.968 bytes libres

El volumen de la unidad C no tiene etiqueta.

El número de serie del volumen es: A8BE-6BEE

 

Directorio de C:\

 

12/05/2007 06:22 p.m. 68.096 diff.exe

12/05/2007 06:22 p.m. 103.424 grep.exe

21/09/2006 07:49 a.m. 359.112 LimeWireWin.exe

04/01/1980 08:28 a.m. 356.352 putty.exe

4 archivos 886.984 bytes

0 dirs 3.999.059.968 bytes libres

El volumen de la unidad C no tiene etiqueta.

El número de serie del volumen es: A8BE-6BEE

 

Directorio de C:\

 

c:\Documents and Settings\12\.limewire\.NetworkShare\LimeWireWin4.12.6-nopack2.exe

c:\Documents and Settings\12\.limewire\.NetworkShare\LimeWireWinInstaller.exe

c:\Documents and Settings\12\Datos de programa\Adobe\Acrobat\7.0\Updater\AdbeRdr709_es_ES.exe

c:\Documents and Settings\12\Datos de programa\Microsoft\Installer\{39619863-8A11-4B60-A166-E6747C986EBE}\ARPPRODUCTICON.exe

c:\Documents and Settings\12\Datos de programa\U3\temp\cleanup.exe

c:\Documents and Settings\12\Escritorio\ImageEnhance.exe

c:\Documents and Settings\12\Escritorio\unlocker_unlocker_1.8.5_francais_20237.exe

c:\Documents and Settings\12\Escritorio\desinfection\avgas-setup-7.5.0.50.exe

c:\Documents and Settings\12\Escritorio\desinfection\Flash_Disinfector.exe

c:\Documents and Settings\12\Escritorio\desinfection\fsbl.exe

c:\Documents and Settings\12\Escritorio\desinfection\gmer.exe

c:\Documents and Settings\12\Escritorio\desinfection\HijackThisFR.exe

c:\Documents and Settings\12\Escritorio\desinfection\ssfisetup1611_1924042633.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\catchme.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\diff.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\dumphive.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\FilesInfoCmd.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\find2.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\Fport.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\grep.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\KProcCheck.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\LFiles.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\LISTDLLS.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\pslist.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\streams.exe

c:\Documents and Settings\12\Escritorio\desinfection\DiagHelp\swreg.exe

 

****** Fin du rapport DiagHelp

 

et :

GMER 1.0.10.10122 - http://www.gmer.net

Rootkit 2007-06-14 11:36:58

Windows 5.1.2600 Service Pack 2

 

 

---- System - GMER 1.0.10 ----

 

SSDT 812CE170 ZwAllocateVirtualMemory

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwClose

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcess

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateProcessEx

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSection

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSymbolicLinkObject

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateThread

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDeleteValueKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwDuplicateObject

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwFlushKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwInitializeRegistry

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey2

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwNotifyChangeKey

SSDT kl1.sys ZwOpenFile

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenKey

SSDT \??\C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwOpenSection

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryMultipleValueKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryValueKey

SSDT 812CE1E8 ZwQueueApcThread

SSDT 812CDFA8 ZwReadVirtualMemory

SSDT 812CE878 ZwRenameKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwReplaceKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwRestoreKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwResumeThread

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSaveKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetContextThread

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationFile

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationProcess

SSDT 812CE350 ZwSetInformationThread

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetSecurityObject

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetValueKey

SSDT 812CE4B8 ZwSuspendProcess

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSuspendThread

SSDT \??\C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

SSDT 812CE3C8 ZwTerminateThread

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwUnloadKey

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwWriteVirtualMemory

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[284]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[285]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[286]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[287]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[288]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[289]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[290]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[291]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[292]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[293]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[294]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[295]

SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[296]

 

---- Devices - GMER 1.0.10 ----

 

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE 8117DD18

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE 8117D2A8

Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ 8117CDD8

Device \Driver\Tcpip \Device\Ip IRP_MJ_WRITE 811650F8

Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION 81164A18

Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION 811602C0

Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA 8115F908

Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA 8116E0E8

Device \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS 8116DF40

Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION 81183608

Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION 8117E4B8

Device \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL 8117D848

Device \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL 8117D5E0

Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL 8116AF40

Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL 81163958

Device \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN 8115FB98

Device \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL 8115EBC0

Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP 81212378

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT 81185B98

Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY FFABC100

Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY FF9EABD8

Device \Driver\Tcpip \Device\Ip IRP_MJ_POWER 81215CE8

Device \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL 81188100

Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE 811856C8

Device \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA 81185460

Device \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA 81185930

Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP 8116E820

Device \Driver\Tcpip \Device\Ip IRP_MJ_PNP_POWER 8116E5B8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE 8117DD18

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE 8117D2A8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ 8117CDD8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE 811650F8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION 81164A18

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION 811602C0

Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA 8115F908

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA 8116E0E8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS 8116DF40

Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION 81183608

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION 8117E4B8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL 8117D848

Device \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL 8117D5E0

Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL 8116AF40

Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL 81163958

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN 8115FB98

Device \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL 8115EBC0

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP 81212378

Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT 81185B98

Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY FFABC100

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY FF9EABD8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_POWER 81215CE8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL 81188100

Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE 811856C8

Device \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA 81185460

Device \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA 81185930

Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP 8116E820

Device \Driver\Tcpip \Device\Tcp IRP_MJ_PNP_POWER 8116E5B8

Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE 8117DD18

Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE 8117D2A8

Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSEIRP_MJ_READ 8117CDD8

Device \Driver\Tcpip \Device\Udp IRP_MJ_WRITE 811650F8

Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION 81164A18

Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION 811602C0

Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA 8115F908

Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA 8116E0E8

Device \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS 8116DF40

Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION 81183608

Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION 8117E4B8

Device \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL 8117D848

Device \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL 8117D5E0

Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL 8116AF40

Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL 81163958

Device \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN 8115FB98

Device \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL 8115EBC0

Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP 81212378

Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT 81185B98

Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY FFABC100

Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY FF9EABD8

Device \Driver\Tcpip \Device\Udp IRP_MJ_POWER 81215CE8

Device \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL 81188100

Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE 811856C8

Device \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA 81185460

Device \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA 81185930

Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP 8116E820

Device \Driver\Tcpip \Device\Udp IRP_MJ_PNP_POWER 8116E5B8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE 8117DD18

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_NAMED_PIPE 8117D2A8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSEIRP_MJ_READ 8117CDD8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_WRITE 811650F8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_INFORMATION 81164A18

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_INFORMATION 811602C0

Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_EA 8115F908

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_EA 8116E0E8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_FLUSH_BUFFERS 8116DF40

Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_VOLUME_INFORMATION 81183608

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_VOLUME_INFORMATION 8117E4B8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_DIRECTORY_CONTROL 8117D848

Device \Driver\Tcpip \Device\RawIp IRP_MJ_FILE_SYSTEM_CONTROL 8117D5E0

Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL 8116AF40

Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL 81163958

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN 8115FB98

Device \Driver\Tcpip \Device\RawIp IRP_MJ_LOCK_CONTROL 8115EBC0

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP 81212378

Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT 81185B98

Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_SECURITY FFABC100

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_SECURITY FF9EABD8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_POWER 81215CE8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SYSTEM_CONTROL 81188100

Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CHANGE 811856C8

Device \Driver\Tcpip \Device\RawIp IRP_MJ_QUERY_QUOTA 81185460

Device \Driver\Tcpip \Device\RawIp IRP_MJ_SET_QUOTA 81185930

Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP 8116E820

Device \Driver\Tcpip \Device\RawIp IRP_MJ_PNP_POWER 8116E5B8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE 8117DD18

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_NAMED_PIPE 8117D2A8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSEIRP_MJ_READ 8117CDD8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_WRITE 811650F8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_INFORMATION 81164A18

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_INFORMATION 811602C0

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_EA 8115F908

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_EA 8116E0E8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FLUSH_BUFFERS 8116DF40

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_VOLUME_INFORMATION 81183608

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_VOLUME_INFORMATION 8117E4B8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DIRECTORY_CONTROL 8117D848

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_FILE_SYSTEM_CONTROL 8117D5E0

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL 8116AF40

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL 81163958

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN 8115FB98

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_LOCK_CONTROL 8115EBC0

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP 81212378

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT 81185B98

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_SECURITY FFABC100

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_SECURITY FF9EABD8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_POWER 81215CE8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SYSTEM_CONTROL 81188100

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CHANGE 811856C8

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_QUERY_QUOTA 81185460

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SET_QUOTA 81185930

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP 8116E820

Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_PNP_POWER 8116E5B8

 

---- Registry - GMER 1.0.10 ----

 

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@bbjenjhakljihabpgbfjpkdmhplhijhdihob 0x6A 0x61 0x6E 0x65 ...

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@abddkphlhpelfmbalgehfjiepealdgbepf 0x6A 0x61 0x6E 0x65 ...

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@iajenjhakljihabpgb 0x61 0x61 0x00 0x01

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@haddkphlhpelfmba 0x61 0x61 0x00 0x01

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@iancmfepgjojdnebha 0x61 0x61 0x00 0x01

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@bbjenjhakljihabpgbfjpkdmhplhljihebni 0x6A 0x61 0x6E 0x65 ...

Reg \Registry\USER\S-1-5-21-796845957-1364589140-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{17B13EA1-502D-872A-F278-DB26CB751421}@abddkphlhpelfmbalgehfjiepeflilbald 0x6A 0x61 0x6E 0x65 ...

 

---- Files - GMER 1.0.10 ----

 

File C:\System Volume Information\MountPointManagerRemoteDatabase

File C:\System Volume Information\tracking.log

File E:\System Volume Information\MountPointManagerRemoteDatabase

File E:\System Volume Information\tracking.log

 

---- EOF - GMER 1.0.10 ----

 

comment tu peux comprendre quelque chose là dedans.

Pour ce qui est des hidens = 0

Pour la recherche des virus avec panda, je n'ai pas pu car toujours pas accés avec internet explorer, mais avec skype oui.

Et maintenant?

C'est ton boulot?

Merci encore car ça fait 1 semaine que j'attends le mec de la manutention et rien!!!

chao,

Cédric

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...