[Résolu] PC infecté

Section d'analyse de rapports et de désinfection : malwares en tous genre et autres indésirables. Demandes de nettoyage uniquement. Prise en charge restreinte : équipe spécialisée.

Modérateur: Modérateurs

Règles du forum :arrow: Les désinfections sont prises en charge par un groupe spécifique, tout le monde ne peut pas intervenir pour désinfecter les machines (règles).
:arrow: Les procédures sont sur-mesure, ne faites pas la même chose chez vous (explications).
:arrow: Un topic par machine, chacun crée le sien. ;)

[Résolu] PC infecté

Messagepar HyperPat » 25 Mai 2010 20:39

Bonsoir,

J'ai récupéré le PC d'une amie. Ce dernier est bourré d'éléments infectieux. Je soupçonne le fiston d'être dans le coup. Il y en a un qui va ramasser un savon. :x

Quoiqu'il en soit, est-ce que quelqu'un aurait la gentillesse de jeter un oeil sur le log ci-après ?

D'avance, merci pour le coup de main.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:36:15, on 25.05.2010
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\System32\smss32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Logitech\Logitech Vid\vid.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Securityessentials2010\SE2010.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\System32\MsiExec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\winlogon32.exe
O2 - BHO: (no name) - {02F843F2-D898-4B70-A289-AF5E13BD84C0} - C:\WINDOWS\system32\diskcopy32.dll (file missing)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: hotrevenue browser enhancer - {6831E747-95CB-BEC1-A6E8-AC4C3C5B1636} - C:\WINDOWS\system32\wevizyfcsd.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ezLife] rundll32 "bawuuuec.dll",,Run
O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\System32\smss32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
O4 - HKCU\..\Run: [smss32.exe] C:\WINDOWS\System32\smss32.exe
O4 - HKCU\..\Run: [Security essentials 2010] C:\Program Files\Securityessentials2010\SE2010.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.miniclip.com/games/freestyle-snowboard/de/"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10c.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\helpers32.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\helpers32.dll
O15 - Trusted Zone: http://*.digital-supply.com
O15 - Trusted Zone: http://*.download-soft-package.com
O15 - Trusted Zone: http://*.download-software-package.com
O15 - Trusted Zone: http://*.get-key-se10.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.digital-supply.com (HKLM)
O15 - Trusted Zone: http://*.get-key-se10.com (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 9842410433
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9842400681
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe

--
End of file - 9654 bytes
Dernière édition par HyperPat le 31 Mai 2010 21:35, édité 1 fois.
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 25 Mai 2010 21:31

Bonsoir,

Rassure moi,tu viens de le reformater et t'as pas eu le temps de faire les mises à jours!

Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Ou alors c'est une VM?
Commence déjà par cela:

Télécharge MBAM

  • Installe le
  • Lance l'outil
  • Coche "Executer un examen complet"
  • Si tu es en présence d'une infection à la fin de l'examen clique sur "ok"
  • Clique sur Supprimer la sélection
  • Pour poster le rapport clique sur l'onglet Rapports/Log et
  • Sélectionne celui t'intéresse et clique sur Ouvrir
  • Fait copier coller et poste le rapport stp

A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 27 Mai 2010 14:16

Rassure moi,tu viens de le reformater et t'as pas eu le temps de faire les mises à jours!

Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


Effectivement, ça fait mal au yeux ! Mais, j'ai récupéré le PC dans cet état. Je procéderai aux mises à jour ultérieurement.

Malwarebytes' Anti-Malware 1.46
http://www.malwarebytes.org

Version de la base de données: 4143

Windows 5.1.2600 Service Pack 1
Internet Explorer 6.0.2800.1106

26.05.2010 13:31:35
mbam-log-2010-05-26 (13-31-35).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 198766
Temps écoulé: 1 heure(s), 0 minute(s), 57 seconde(s)

Processus mémoire infecté(s): 2
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 15
Valeur(s) du Registre infectée(s): 4
Elément(s) de données du Registre infecté(s): 15
Dossier(s) infecté(s): 5
Fichier(s) infecté(s): 336

Processus mémoire infecté(s):
C:\Program Files\Securityessentials2010\SE2010.exe (Rogue.SecurityEssentials2010) -> Unloaded process successfully.
C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\helpers32.dll (Trojan.FakeAlert) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{a9722a0d-365f-47d2-b70b-37d046316d99} (Adware.EZlife) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\puevcotqjx (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2281d6c1-10bf-42b9-a49b-c9c921323a81} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2281d6c1-10bf-42b9-a49b-c9c921323a81} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2281d6c1-10bf-42b9-a49b-c9c921323a81} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a984a152-2054-46ab-bb1a-90d12002b9b1} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a984a152-2054-46ab-bb1a-90d12002b9b1} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{a984a152-2054-46ab-bb1a-90d12002b9b1} (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SE2010 (Rogue.Securityessentials2010) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adhlpr.adhlpr (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\adhlpr.adhlpr.1.0 (Adware.Adrotator) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6831e747-95cb-bec1-a6e8-ac4c3c5b1636} (Adware.AdRotator) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6831e747-95cb-bec1-a6e8-ac4c3c5b1636} (Adware.AdRotator) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\security essentials 2010 (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ezlife (Adware.EZlife) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon32.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon32.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-soft-package.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-software-package.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\digital-supply.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\digital-supply.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\System32\winlogon32.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Program Files\Securityessentials2010 (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Application Data\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D} (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Worm.Prolaco.M) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\WINDOWS\system32\helpers32.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Program Files\Securityessentials2010\SE2010.exe (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\5.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\621.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\622.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\653.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\792.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\794.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\795.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\11.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\24C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\263.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\27D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2BB.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2FC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\318.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\32D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\264.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\265.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\266.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\267.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\268.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\269.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\26A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\26B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\26D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\26E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\26F.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\27.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\270.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\273.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\274.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\275.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\276.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\277.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\278.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\279.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\27B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\27C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\COM Security Update Level 1 (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\COM Security Update Level 5 (Adware.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\27F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\280.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\282.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\283.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\284.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\287.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\288.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\289.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28C.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28E.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\28F.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\29.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\290.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\291.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\292.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\293.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\294.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\295.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\296.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\297.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\298.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\299.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\29A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\29B.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\29C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\29D.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2A9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2AA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2AF.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B1.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B3.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B5.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B7.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B8.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2B9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2BA.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2BC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2BD.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2BE.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2BF.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C1.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C3.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C5.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C7.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2C9.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2CA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2CB.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2CC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2CD.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2CE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2CF.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D1.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D3.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D5.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D6.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2D9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2DA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2DB.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2DC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2DD.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2DE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2DF.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E1.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E5.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2E9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2EA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2EB.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2EC.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2EE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2EF.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F0.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F1.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F5.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F6.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2F9.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2FA.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2FB.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\24E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\24F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\250.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\252.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\254.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\255.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\256.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\257.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\258.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\259.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\25F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\26.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\260.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\261.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\262.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2FD.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2FE.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2FF.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\3.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\300.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\301.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\304.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\305.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\306.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\307.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\308.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\309.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\30F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\310.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\311.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\312.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\313.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\314.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\315.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\316.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\317.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\319.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31A.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\31F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\32.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\320.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\321.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\322.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\323.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\324.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\325.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\326.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\329.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\32C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\32E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\32F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\330.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\332.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\333.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\334.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\337.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\338.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\33C.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\342.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\35.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\3B7.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\3B8.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\3D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\4.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\416.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\417.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\12.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\13.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\14.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\15.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\16.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\17.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\18.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\19.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1A.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1C.tmp (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1D.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1E.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\1F.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\2.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\20.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\21.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\22.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\23.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\24.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temp\24B.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temporary Internet Files\Content.IE5\5RBRUSKW\SetupSE2010[1].exe (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temporary Internet Files\Content.IE5\7GMXQJBS\exe[1].exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temporary Internet Files\Content.IE5\8K1OA3NK\exe[1].exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Local Settings\Temporary Internet Files\Content.IE5\8K1OA3NK\firewall[1].dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\adproFfx.dll (Adware.SmartAds) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\ffxShot.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{08003088-E499-4DE2-AB60-3C90013AB488}\RP1\A0000290.exe (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{08003088-E499-4DE2-AB60-3C90013AB488}\RP1\A0000270.exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3svc32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\18467.exe (Rootkit.TDSS.Gen) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\icardres32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CmdLineExt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\d3drm3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\d3dx9_3032.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\deploytk32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\docprop3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3api3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3api323232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3gpclnt32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3gpclnt3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dskquoui3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dsound3d3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ES15.exe (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\puevcotqjx.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dsuiext3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cryptdll32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cryptnet32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ciadmin32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ciodm32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hpboid32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hpowiax732.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\HPZidr1232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jhztikbf.dll (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comcat32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comres32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\comsnap3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eapqec3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eapsvc32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3svc3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dot3ui32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dpnaddr323232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\digest3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dimsntfy32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dmserver3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dmusic3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dmusic323232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dnsapi3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\davclnt3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dbmsvinn32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drmv2clt3232.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\nwncz.sys (Rootkit.Agent) -> Delete on reboot.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Worm.Prolaco.M) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Bureau\Security essentials 2010.lnk (Rogue.Agent) -> Quarantined and deleted successfully.
C:\Program Files\mozilla firefox\components\nsAdproFFx.xpt (Adware.AdRotator) -> Quarantined and deleted successfully.
C:\Program Files\Mozilla Firefox\components\nsFFxSHot.xpt (Adware.Adrotator) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\warnings.html (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Application Data\Microsoft\Internet Explorer\Quick Launch\Security essentials 2010.lnk (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\Documents and Settings\Andrée\Menu Démarrer\Security essentials 2010.lnk (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\Winlogon32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\41.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 27 Mai 2010 18:25

Ah ben 2 fois rien :plaf:
Avec du TDSS avec, pourquoi pas...
Aller on approfondi:

Télécharge ZHPDiag crée par Nicolas Coolman

  • Enregistre le sur ton bureau
  • Double clique sur l'icône
  • Suis les instructions à l'ecran
  • Clique sur Image pour lancer l'analyse
  • Clique sur Image pour copier le rapport
  • Puis colle le dans ta prochaine réponses
  • Le rapport se situe aussi sous C:\Program Files\ZebHelpProcess\ZHPDiag.txt

A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 27 Mai 2010 18:37

Voici (en 2 parties)

1ère partie

Rapport de ZHPDiag v1.25.1426 par Nicolas Coolman, Update du 06/05/2010
Run by Andrée at 27.05.2010 19:31:46
Web site : http://www.premiumorange.com/zeb-help-p ... pdiag.html
Contact : nicolascoolman@yahoo.fr

---\\ Web Browser
MSIE: Internet Explorer v6.0.2800.1106

---\\ System Information
Platform : Microsoft Windows XP (5.1.2600) Service Pack 1
Processor: x86 Family 15 Model 2 Stepping 9, GenuineIntel
Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 511.5 MB (29% free)
System drive C: has 81 GB (70%) free of 115 GB

---\\ Logged in mode
Computer Name: PC-DE-DEDEE
User Name: Andrée
Unselected Option: O1,O45,O61,O65
Logged in as Administrator

---\\ DOS/Devices
A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
C:\ Hard drive, Flash drive, Thumb drive (Free 81 Go of 115 Go)
D:\ CD-ROM drive (Not Inserted)
E:\ CD-ROM drive (Not Inserted)
F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)


---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK


---\\ Processus lancés
[MD5.234051C0D242A6F4A79AE5212C1323D4] - (.LogMeIn, Inc. - LogMeIn Desktop Application.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [63048]
[MD5.29680A793F690EEF4AAA68479D2A6DF8] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [209153]
[MD5.062F3DB9AFA9C3CE0DA52F28595C0C6D] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152]
[MD5.FF473648E7B1B37C7F3249A6549FAC72] - (.Hewlett-Packard - HpqSRmon.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150016]
[MD5.3B8C106587A57159639713EEE074EF83] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2780432]
[MD5.5E4C9C25D603AE46DEDCBD9674F86E21] - (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe [149280]
[MD5.F91F52F4EA5D88DAB6245682A16F3A72] - (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [36272]
[MD5.DB1DB28467111A24664933AB8908CBCE] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [952768]
[MD5.FD89A30C8A9FF4929ABC5039E6A527A4] - (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe [47392]
[MD5.ED7A6D40B20DC34BE06F4AE196AE7D50] - (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe [421888]
[MD5.59C0BDCFE273334D3133C7F2B57A2A13] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [142120]
[MD5.2C856908EE61424238772508E9FBCBC8] - (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\ctfmon.exe [13312]
[MD5.E13EA4860E8F2AA845B53BFD2B6FEC5B] - (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe [1695232]
[MD5.E60BD23059B3E0C8D59B71CAB743445D] - (.Logitech Inc. - Logitech Vid.) -- C:\Program Files\Logitech\Logitech Vid\vid.exe [5451536]
[MD5.9015BC03F62940527EC92D45EE89E46F] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [108289]
[MD5.B8720A787C1223492E6F319465E996CE] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [185089]
[MD5.ACB095E7E1663F1B83A41C22C5D75F90] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [144672]
[MD5.333A4DB8410D8E24DB06D6AEBECDC7C2] - (.Microsoft Corporation - Generic Host Process for Win32 Services.) -- C:\WINDOWS\System32\svchost.exe [12800]
[MD5.A065F048E9E23E6C026A7BB548D126A7] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [345376]
[MD5.FC0691097471EE374907E1024EDCBD43] - (.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\WINDOWS\system32\services.exe [101888]
[MD5.09417134F248DFCEEA15C72BCC87F592] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
[MD5.500F1E4461075D602CE77109A9A3D634] - (.LogMeIn, Inc. - LogMeIn Maintenance Service.) -- C:\Program Files\LogMeIn\x86\RaMaint.exe [116032]
[MD5.9015122D04C195BDAB88FEBCBAE229DB] - (.LogMeIn, Inc. - LogMeIn.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe [63040]
[MD5.5C7B88695CE461D8BDA4FE0C0E57E71D] - (.Logitech Inc. - Logitech LVPrcSrv Module..) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe [154136]
[MD5.B7B1C150AFF59455DB4DF082815F88F5] - (.Microsoft Corporation - LSA Shell (Export Version).) -- C:\WINDOWS\System32\lsass.exe [11776]
[MD5.B1CE5287F096895D9BE26EB86F4D5FAF] - (.Microsoft Corporation - Spooler SubSystem App.) -- C:\WINDOWS\system32\spoolsv.exe [51200]


---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,


---\\ Pages de recherche d'Internet Explorer (R1)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local


---\\ Internet Explorer URLSearchHook (R3)
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Bibliothèque d'objets et de contrôles de do.) (No version) -- %SystemRoot%\System32\shdocvw.dll


---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: (no name) - {02F843F2-D898-4B70-A289-AF5E13BD84C0} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\diskcopy32.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} . (.Hewlett-Packard Co. - HP Smart Web Printing add-on for Internet E.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} . (.Hewlett-Packard Co. - HP Smart Web Printing add-on for Internet E.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll


---\\ Internet Explorer Toolbars (O3)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} . (.Microsoft Corporation - Contrôle ActiveX du Lecteur Windows Media.) -- C:\WINDOWS\System32\msdxm.ocx


---\\ Applications démarrées automatiquement par le registre (O4)
O4 - HKLM\..\Run: [LogMeIn GUI] . (.LogMeIn, Inc. - LogMeIn Desktop Application.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] . (.Hewlett-Packard - HpqSRmon.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] . (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [Logitech Vid] . (.Logitech Inc. - Logitech Vid.) -- C:\Program Files\Logitech\Logitech Vid\vid.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk . (.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe


---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra 'Tools' menuitem: @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} . (.not file.) - ,4
O9 - Extra button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} . (.Hewlett-Packard Co. - HP Smart Web Printing add-on for Internet Explorer.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe


---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\System32\mswsock.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\System32\winrnr.dll
O10 - WLSP:\000000000004\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\System32\mswsock.dll


---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 9842410433
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9842400681
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab


---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: LMIinit . (.LogMeIn, Inc. - LogMeIn Remote Control Helper.) -- C:\WINDOWS\System32\LMIinit.dll


---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Contrôleur de site Web.) -- C:\WINDOWS\System32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\System32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll


---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\System32\browseui.dll


---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) . (.LogMeIn, Inc. - LogMeIn Maintenance Service.) - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn (LogMeIn) . (.LogMeIn, Inc. - LogMeIn.) - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Process Monitor (LVPrcSrv) . (.Logitech Inc. - Logitech LVPrcSrv Module..) - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe


---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Personnalisation du navigateur - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS . (.Pas de propriétaire - Pas de description.) -- RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\wmp.inf
O40 - ASIC: Macromedia Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.0 r32.) -- C:\WINDOWS\system32\Macromed\Flash\Flash10c.ocx


---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: avgntdd (avgntdd) . (.Avira GmbH - Avira AntiVir File Filter Driver.) - C:\Windows\sysTEM32\DRIVERS\avgntdd.sys
O41 - Driver: avipbb (avipbb) . (.Avira GmbH - Avira Driver for RootKit Detection.) - C:\Windows\system32\DRIVERS\avipbb.sys
O41 - Driver: NetBIOS sur TCP/IP (NetBT) . (.Pas de propriétaire - Pas de description.) - C:\Windows\system32\DRIVERS\netbt.sys
O41 - Driver: ssmdrv (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\system32\DRIVERS\ssmdrv.sys


---\\ Logiciels installés (O42)
O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM]
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems, Inc..) [HKLM]
O42 - Logiciel: Adobe Reader 9.3.2 - Français - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM]
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM]
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM]
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM]
O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM]
O42 - Logiciel: Bonjour - (.Apple Inc..) [HKLM]
O42 - Logiciel: Free Video to iPhone Converter version 2.2 - (.DVDVideoSoft Limited..) [HKLM]
O42 - Logiciel: GameCenter - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: HP Customer Participation Program 10.0 - (.HP.) [HKLM]
O42 - Logiciel: HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 - (.HP.) [HKLM]
O42 - Logiciel: HP Imaging Device Functions 10.0 - (.HP.) [HKLM]
O42 - Logiciel: HP Photosmart Essential 3.5 - (.HP.) [HKLM]
O42 - Logiciel: HP Smart Web Printing 4.60 - (.HP.) [HKLM]
O42 - Logiciel: HP Solution Center 13.0 - (.HP.) [HKLM]
O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM]
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Java(TM) 6 Update 16 - (.Sun Microsystems, Inc..) [HKLM]
O42 - Logiciel: LFP Manager 2004 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: LogMeIn - (.LogMeIn, Inc..) [HKLM]
O42 - Logiciel: Logitech Vid - (.Logitech Inc..) [HKLM]
O42 - Logiciel: Logitech Webcam Software - (.Logitech Inc..) [HKLM]
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MobileMe Control Panel - (.Apple Inc..) [HKLM]
O42 - Logiciel: OpenOffice.org 3.1 - (.OpenOffice.org.) [HKLM]
O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM]
O42 - Logiciel: Safari - (.Apple Inc..) [HKLM]
O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM]
O42 - Logiciel: Shop for HP Supplies - (.HP.) [HKLM]
O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Uninstall 1.0.0.1 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: VC 9.0 Runtime - (.Check Point Software Technologies Ltd.) [HKLM]
O42 - Logiciel: VLC media player 1.0.1 - (.VideoLAN Team.) [HKLM]
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: iTunes - (.Apple Inc..) [HKLM]

---\\ HKCU & HKLM Software Keys
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Applications locales générées par AppWizard]
[HKCU\Software\Aurigma]
[HKCU\Software\Avira]
[HKCU\Software\Borland]
[HKCU\Software\Classes]
[HKCU\Software\Cyanide]
[HKCU\Software\DVDVideoSoft]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\IM Providers]
[HKCU\Software\ImageViewer]
[HKCU\Software\JEDI-VCL]
[HKCU\Software\JavaSoft]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\LogMeIn]
[HKCU\Software\LogiShrd]
[HKCU\Software\Logitech]
[HKCU\Software\Macromedia]
[HKCU\Software\Magnet]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\Oigixdeors]
[HKCU\Software\OpenOffice.org]
[HKCU\Software\Policies]
[HKCU\Software\SecuROM]
[HKCU\Software\Skype]
[HKCU\Software\Team17SoftwareLTD]
[HKCU\Software\Trolltech]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\mgSoftware]
[HKCU\Software\perforce]
[HKCU\Software\shockwave.com]
[HKCU\Software\yahooinstall]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AppDataLow]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Avira]
[HKLM\Software\BrowserChoice]
[HKLM\Software\C07ft5Y]
[HKLM\Software\CA561B]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Cyanide]
[HKLM\Software\DVDVideoSoft]
[HKLM\Software\Digital Now]
[HKLM\Software\EA SPORTS]
[HKLM\Software\GEAR Software]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HP]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\ICE]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\LogMeIn, Inc.]
[HKLM\Software\LogMeIn]
[HKLM\Software\LogiShrd]
[HKLM\Software\Logitech]
[HKLM\Software\Macromedia]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\ODBC]
[HKLM\Software\OpenOffice.org]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secure]
[HKLM\Software\Sun Microsystems]
[HKLM\Software\TENCENT]
[HKLM\Software\TrendMicro]
[HKLM\Software\Trymedia Systems]
[HKLM\Software\VideoLAN]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\X-AVCSD]
[HKLM\Software\Zone Labs]
[HKLM\Software\perforce]
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar HyperPat » 27 Mai 2010 18:38

2ème partie

---\\ Contenu des dossiers Fichiers Communs (O43)
O43 - CFD:Common File Directory ----D- C:\Program Files\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files\Apple Software Update
O43 - CFD:Common File Directory ----D- C:\Program Files\Avira
O43 - CFD:Common File Directory ----D- C:\Program Files\Bonjour
O43 - CFD:Common File Directory ----D- C:\Program Files\ComPlus Applications
O43 - CFD:Common File Directory ----D- C:\Program Files\DVDVideoSoft
O43 - CFD:Common File Directory ----D- C:\Program Files\EA SPORTS
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers communs
O43 - CFD:Common File Directory ----D- C:\Program Files\Hewlett-Packard
O43 - CFD:Common File Directory ----D- C:\Program Files\HP
O43 - CFD:Common File Directory ----D- C:\Program Files\InstallShield Installation Information
O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files\iPod
O43 - CFD:Common File Directory ----D- C:\Program Files\iTunes
O43 - CFD:Common File Directory ----D- C:\Program Files\Java
O43 - CFD:Common File Directory ----D- C:\Program Files\JRE
O43 - CFD:Common File Directory ----D- C:\Program Files\LimeWire
O43 - CFD:Common File Directory ----D- C:\Program Files\Logitech
O43 - CFD:Common File Directory ----D- C:\Program Files\LogMeIn
O43 - CFD:Common File Directory ----D- C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD:Common File Directory ----D- C:\Program Files\Messenger
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
O43 - CFD:Common File Directory ----D- C:\Program Files\microsoft frontpage
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Silverlight
O43 - CFD:Common File Directory ----D- C:\Program Files\Movie Maker
O43 - CFD:Common File Directory ----D- C:\Program Files\Mozilla Firefox
O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files\msn
O43 - CFD:Common File Directory ----D- C:\Program Files\MSN Gaming Zone
O43 - CFD:Common File Directory ----D- C:\Program Files\MSXML 4.0
O43 - CFD:Common File Directory ----D- C:\Program Files\NetMeeting
O43 - CFD:Common File Directory ----D- C:\Program Files\OpenOffice.org 3
O43 - CFD:Common File Directory ----D- C:\Program Files\Outlook Express
O43 - CFD:Common File Directory ----D- C:\Program Files\QuickTime
O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files\Safari
O43 - CFD:Common File Directory ----D- C:\Program Files\Services en ligne
O43 - CFD:Common File Directory ----D- C:\Program Files\Trend Micro
O43 - CFD:Common File Directory ----D- C:\Program Files\TryMedia
O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files\VideoLAN
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Live SkyDrive
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Connect 2
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT
O43 - CFD:Common File Directory --H-D- C:\Program Files\WindowsUpdate
O43 - CFD:Common File Directory ----D- C:\Program Files\xerox
O43 - CFD:Common File Directory ----D- C:\Program Files\ZHPDiag
O43 - CFD:Common File Directory ----D- C:\Program Files\Zone Labs
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Adobe AIR
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Apple
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\DVDVideoSoft
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Hewlett-Packard
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\HP
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\InstallShield
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\logishrd
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\MSSoap
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\ODBC
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Services
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\System
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Windows Live


---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.DEB3697D0C1BAD7556450491F403B26C] - 27.05.2010 - 18:30:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupapi.log [479287]
O44 - LFC:[MD5.00000000000000000000000000000000] - 27.05.2010 - 18:28:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WindowsUpdate.log [427570]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 27.05.2010 - 18:28:37 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\0.log [0]
O44 - LFC:[MD5.00000000000000000000000000000000] - 27.05.2010 - 18:27:07 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.00000000000000000000000000000000] - 27.05.2010 - 18:27:06 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiadebug.log [159]
O44 - LFC:[MD5.7E216643A577E4D8B99A4AD355496F32] - 27.05.2010 - 18:24:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wpa.dbl [13646]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 27.05.2010 - 18:23:26 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26.05.2010 - 12:27:22 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\5909.exe [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26.05.2010 - 12:07:21 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\6907.exe [0]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26.05.2010 - 11:47:21 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\31214.exe [0]
O44 - LFC:[MD5.2E8F6BE71469A67D5AA32D9A766A2F93] - 25.05.2010 - 22:00:21 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\mbam-error.txt [127]
O44 - LFC:[MD5.00000000000000000000000000000000] - 25.05.2010 - 20:52:51 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SchedLgU.Txt [32578]
O44 - LFC:[MD5.97B1090A93C26E9221EA3708BB1884BF] - 25.05.2010 - 20:31:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\PerfStringBackup.INI [1094606]
O44 - LFC:[MD5.F6A1B0EE56EB912DCE2F4BEE28A93D5B] - 25.05.2010 - 20:31:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfc009.dat [67312]
O44 - LFC:[MD5.865D67554DB9FBF71DD1A31A9C10C2BF] - 25.05.2010 - 20:31:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfc00C.dat [80508]
O44 - LFC:[MD5.603649A5747189269DE6765C574A8A07] - 25.05.2010 - 20:31:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfh009.dat [432356]
O44 - LFC:[MD5.C6DC8E628CC1D2D5EEDA87637E6630B1] - 25.05.2010 - 20:31:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfh00C.dat [500482]
O44 - LFC:[MD5.53424552693536F936029755D0D127ED] - 25.05.2010 - 20:26:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\COM+.log [1536]
O44 - LFC:[MD5.4CFB3010C9402C492E7640E7D4646279] - 25.05.2010 - 20:14:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\comsetup.log [385835]
O44 - LFC:[MD5.4E71D994E0470A63C0B86E28458CA61A] - 25.05.2010 - 20:06:58 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\DirectX.log [364671]
O44 - LFC:[MD5.FE1DE4FBFFEF93893C46324D239A1404] - 25.05.2010 - 20:05:41 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wmsetup.log [122637]
O44 - LFC:[MD5.B455CA6241AE344BB8E51CC95571D87B] - 25.05.2010 - 20:03:59 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setuplog.txt [562171]
O44 - LFC:[MD5.C90D2C8DECB6C18713E412EAC010A936] - 25.05.2010 - 20:03:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\FNTCACHE.DAT [116560]
O44 - LFC:[MD5.3912D04AA4F01BF0B33CE5703CF8E479] - 25.05.2010 - 20:02:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\iis6.log [165112]
O44 - LFC:[MD5.F97AF1C6C9387B6D21D3B50564B1A535] - 25.05.2010 - 20:02:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\imsins.log [4382]
O44 - LFC:[MD5.4EB3063ED7FA75900B7D11A24220A8B5] - 25.05.2010 - 20:02:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ntdtcsetup.log [233845]
O44 - LFC:[MD5.2E4E15CD0B61B638BDF7B123773FDCEE] - 25.05.2010 - 20:02:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupact.log [264873]
O44 - LFC:[MD5.F22D5DA2A2B307FBB79CEA055AF52F12] - 25.05.2010 - 20:02:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\tsoc.log [425414]
O44 - LFC:[MD5.8255FE8ABF1C35497F5A9FBDBBF99D27] - 25.05.2010 - 20:02:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\$winnt$.inf [288]
O44 - LFC:[MD5.DC17DD0189B0C36D863B4DD0A036C10F] - 25.05.2010 - 19:58:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WMSysPr9.prx [316640]
O44 - LFC:[MD5.33C3013F2376FA839EEC112FAE3DA9FB] - 25.05.2010 - 19:58:45 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\win.ini [596]
O44 - LFC:[MD5.A3CCB3485B71C8F7AD06E4B82755DF50] - 25.05.2010 - 19:58:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\amcompat.tlb [16832]
O44 - LFC:[MD5.89293A243DEB6DC3CCFCE54C0F00D87D] - 25.05.2010 - 19:58:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\nscompat.tlb [23392]
O44 - LFC:[MD5.F9F53D8752A1AD1991B897A44B10106D] - 25.05.2010 - 19:58:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wmpscheme.xml [25065]
O44 - LFC:[MD5.94940A5C4D5219EE0F4F9D5355C6C1E8] - 25.05.2010 - 19:58:40 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WMSysPrx.prx [299552]
O44 - LFC:[MD5.86D04223CADCF43665940AC5017E9673] - 25.05.2010 - 19:58:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\OEWABLog.txt [1933]
O44 - LFC:[MD5.E4CF20EB892520497CF7F8BBAFC032BC] - 25.05.2010 - 19:58:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ODBCINST.INI [4207]
O44 - LFC:[MD5.9639F63C23097CE8A71C9D4CF1C89A91] - 25.05.2010 - 19:58:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setuperr.log [658]
O44 - LFC:[MD5.2F131E0BCC23B2EFB939370DC7C670AC] - 25.05.2010 - 19:55:04 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\Windows Update.log [558]
O44 - LFC:[MD5.5D76C3FB736514E1D7C88791E7322784] - 25.05.2010 - 19:54:37 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\WindowsLogon.manifest [488]
O44 - LFC:[MD5.5D76C3FB736514E1D7C88791E7322784] - 25.05.2010 - 19:54:37 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\logonui.exe.manifest [488]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 25.05.2010 - 19:54:30 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\cdplayer.exe.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 25.05.2010 - 19:54:30 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ncpa.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 25.05.2010 - 19:54:30 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\nwc.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 25.05.2010 - 19:54:30 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\sapi.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 25.05.2010 - 19:54:30 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wuaucpl.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 25.05.2010 - 19:54:30 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WindowsShell.Manifest [749]
O44 - LFC:[MD5.031299D1AC7E6B9FC5085A44C6749B8B] - 25.05.2010 - 19:54:09 ---A- . (.Intel Corporation - ISR Debug 32-bit Engine.) -- C:\WINDOWS\System32\isrdbg32.dll [28672]
O44 - LFC:[MD5.81051BCC2CF1BEDF378224B0A93E2877] - 25.05.2010 - 19:54:09 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\desktop.ini [2]
O44 - LFC:[MD5.1AB278B5CC2179719C90310A8492A824] - 25.05.2010 - 19:53:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\FaxSetup.log [1069390]
O44 - LFC:[MD5.D504647DD06A4BF592BAD7D2033F84DB] - 25.05.2010 - 19:53:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\msgsocm.log [55272]
O44 - LFC:[MD5.6DF7E180B1606F480783BE60A333E9A8] - 25.05.2010 - 19:53:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ocgen.log [568865]
O44 - LFC:[MD5.8213D3B15E199593B487F4C9B3CA72D6] - 25.05.2010 - 19:53:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ocmsn.log [61455]
O44 - LFC:[MD5.CB047A8F00C864C50129A9473EAA07EC] - 25.05.2010 - 19:53:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\emptyregdb.dat [23032]
O44 - LFC:[MD5.EB1345F9C438677CCDD7D8E66CBC2DA3] - 25.05.2010 - 19:53:18 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\DtcInstall.log [701]
O44 - LFC:[MD5.14D0824A3FE88E66CB21FF9F86D4CACF] - 25.05.2010 - 19:53:15 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\sessmgr.setup.log [2614]
O44 - LFC:[MD5.1C72F695F87125E74DC86E090C00CD29] - 25.05.2010 - 19:52:41 ---A- . (.Hilgraeve, Inc. - Bibliothèque d'applications HyperTerminal.) -- C:\WINDOWS\System32\hypertrm.dll [497152]
O44 - LFC:[MD5.05DEC82012820F7A5DE7A6CD7AAAD61C] - 25.05.2010 - 19:51:46 -SH-- . (.Pas de propriétaire - Pas de description.) -- C:\boot.ini [216]
O44 - LFC:[MD5.3B78D345F0983F778345C1C817175109] - 25.05.2010 - 19:48:31 ---A- . (.SiS Corporation - SiS PCI Fast Ethernet Adapter Driver.) -- C:\WINDOWS\System32\drivers\sisnic.sys [31232]
O44 - LFC:[MD5.E7A4310574D27F429F307FCE128EBCC2] - 25.05.2010 - 19:45:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\regopt.log [5256]
O44 - LFC:[MD5.A0E02492452D4E237465D99D005D91FD] - 25.05.2010 - 19:45:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system.ini [231]
O44 - LFC:[MD5.FA511331A48B582A7D584FC2408E8C1A] - 25.05.2010 - 19:45:25 ---A- . (.Perle Systems Ltd. - Specialix MPS NT Upgrade CoInstaller.) -- C:\WINDOWS\System32\spxcoins.dll [24661]
O44 - LFC:[MD5.E9D9927EF032BECA97C42B0F03E191A0] - 25.05.2010 - 19:45:06 R--A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SETAF.tmp [13923]
O44 - LFC:[MD5.87D7EBA2D823656EEB29FE6938932298] - 25.05.2010 - 19:45:04 R--A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SETA3.tmp [1086182]
O44 - LFC:[MD5.71973E4F8CA4164825A95C1C02B190D1] - 25.05.2010 - 19:31:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ntbtlog.txt [68696]
O44 - LFC:[MD5.ECD866F2268CA41E90A04DA1CA196D3E] - 25.05.2010 - 19:20:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupapi.old [54731]
O44 - LFC:[MD5.2A6C516CB474B2D667AD059E909D9CE6] - 21.05.2010 - 18:36:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\c5d712a [20]
O44 - LFC:[MD5.1753EEA648260EBC3E4978A2980089EA] - 13.05.2010 - 06:21:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB978542.log [13245]
O44 - LFC:[MD5.0BAC29462C596B33CD2201D0CA77E6E2] - 13.05.2010 - 06:21:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\imsins.BAK [1374]
O44 - LFC:[MD5.42E765188DD7515E79369785E033D7B0] - 10.05.2010 - 10:26:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\1558017581 [817]
O44 - LFC:[MD5.4D9511C64FA2F86F6DA177481B795D4C] - 10.05.2010 - 08:10:56 -SHA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\210577021 [1061]
O44 - LFC:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 29.04.2010 - 14:39:38 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [38224]
O44 - LFC:[MD5.A1CD8EEC777F05DE505B76BB96709498] - 29.04.2010 - 14:39:24 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [19288]


---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll


---\\ Export de clé d'application autorisée (ECAA) (O47)
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" [Enabled] .(.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Cyanide\GameCenter\GameCenter.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Cyanide\GameCenter\GameCenter.exe
O47 - AAKE:Key Export SP - "C:\Program Files\LimeWire\LimeWire.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\LimeWire\LimeWire.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Skype\Plugin Manager\skypePM.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Logitech\Logitech Vid\Vid.exe" [Enabled] .(.Logitech Inc. - Logitech Vid.) (.not file.) -- C:\Program Files\Logitech\Logitech Vid\Vid.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) (.not file.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export SP - "C:\Program Files\PowerJass\sjOnline\powerjassonline.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\PowerJass\sjOnline\powerjassonline.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\PCM.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\PCM.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\Autorun\Exe\Autorun.exe" [Enabled] .(.Pas de propriétaire - .) (.not file.) -- C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\Autorun\exe\Autorun.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" [Enabled] .(.Hewlett-Packard Co. - HP CUE Status Root.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" [Enabled] .(.Hewlett-Packard Co. - HP All-in-One Launcher Utility.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" [Enabled] .(.Hewlett-Packard - HP CUE-Scanning Flow Component.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" [Enabled] .(.Hewlett-Packard Co. - NewCopy Application.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" [Enabled] .(.Hewlett-Packard - MFC HP Scan Application.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - hpqsudi.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential Software.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" [Enabled] .(.Hewlett-Packard Co. - HP Guided Solutions.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" [Enabled] .(.Hewlett-Packard - GPCore COM object.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\HP Software Update\hpwucli.exe" [Enabled] .(.Hewlett-Packard - HP Update Client.) (.not file.) -- C:\Program Files\HP\HP Software Update\hpwucli.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" [Enabled] .(.Hewlett-Packard Co. - .) (.not file.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintexe.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Bonjour\mDNSResponder.exe" [Enabled] .(.Apple Inc. - Bonjour Service.) (.not file.) -- C:\Program Files\Bonjour\mDNSResponder.exe
O47 - AAKE:Key Export SP - "C:\Program Files\iTunes\iTunes.exe" [Enabled] .(.Apple Inc. - iTunes.) (.not file.) -- C:\Program Files\iTunes\iTunes.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Team17\Worms 2\Frontend.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Team17\Worms 2\Frontend.exe
O47 - AAKE:Key Export SP - "C:\WINDOWS\explorer.exe" [Enabled] .(.Microsoft Corporation - Explorateur Windows.) (.not file.) -- C:\WINDOWS\explorer.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" [Enabled] .(.Hewlett-Packard Co. - HP CUE Status Root.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" [Enabled] .(.Hewlett-Packard Co. - HP All-in-One Launcher Utility.) -- C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" [Enabled] .(.Hewlett-Packard - HP CUE-Scanning Flow Component.) -- C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" [Enabled] .(.Hewlett-Packard Co. - NewCopy Application.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" [Enabled] .(.Hewlett-Packard - MFC HP Scan Application.) -- C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - hpqsudi.) -- C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential Software.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" [Enabled] .(.Hewlett-Packard Co. - HP Guided Solutions.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" [Enabled] .(.Hewlett-Packard - GPCore COM object.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\HP Software Update\hpwucli.exe" [Enabled] .(.Hewlett-Packard - HP Update Client.) -- C:\Program Files\HP\HP Software Update\hpwucli.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" [Enabled] .(.Hewlett-Packard Co. - .) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintexe.exe
O47 - AAKE:Key Export DP - "C:\WINDOWS\explorer.exe" [Enabled] .(.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\explorer.exe


---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d


---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"mciqtz32.dll"="mciqtz32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\mciqtz32.dll
O52 - TDSD: \drivers.desc\"msg711.acm"="Microsoft CCITT G.711 Audio CODEC" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"msgsm32.acm"="Microsoft GSM 6.10 Audio CODEC" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"tssoft32.acm"="DSP Group TrueSpeech(TM) Audio CODEC" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
O52 - TDSD: \drivers.desc\"iccvid.dll"="Cinepak Codec by Radius Inc." . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"ir32_32.dll"="Indeo codec by Intel" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \drivers.desc\"lvcodec2.dll"="lvcodec2.dll" . (.Logitech Inc. - Video Codec.) -- C:\WINDOWS\System32\lvcodec2.dll


---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - "SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - "SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKCU\...\Policies\System] - "DisableTaskMgr"=0


---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoDriveTypeAutoRun"=145
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoSetActiveDesktop"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "HonorAutoRunSetting"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoSetActiveDesktop"=0


---\\ Liste des Drivers Système (SDL) (O58)
O58 - SDL:[MD5.D3BA744433F14E5C77107D9D82297801] - 17.08.2001 - 20:20:16 ---A- . (.Silicon Integrated Systems Corp. - SiS 7018 Audio Device WDM Driver.) -- C:\WINDOWS\System32\drivers\ac97sis.sys
O58 - SDL:[MD5.8D49DB427F7C6EB6A044FEA26CFAD4FF] - 24.04.2003 - 13:00:00 ---A- . (.Advanced Micro Devices, Inc. - AMD Win2000 AGP Filter.) -- C:\WINDOWS\System32\drivers\amdagp.sys
O58 - SDL:[MD5.BAEB8EE9A232515372E35E67582E4121] - 29.08.2002 - 10:24:52 ---A- . (.ATI Technologies Inc. - Pilote de miniport ATI RAGE 128.) -- C:\WINDOWS\System32\drivers\ati2mtaa.sys
O58 - SDL:[MD5.D505D4FDAA3497B9E57907A6AF379B52] - 29.08.2002 - 10:24:52 ---A- . (.ATI Technologies Inc. - Pilote de miniport ATI RAGE 128.) -- C:\WINDOWS\System32\drivers\ati2mtag.sys
O58 - SDL:[MD5.56425DF5BA6AD6319C2372EB762FC9B3] - 28.08.2002 - 22:16:24 ---A- . (.ATI Technologies Inc. - ATI WDM BT829 MiniDriver (A).) -- C:\WINDOWS\System32\drivers\atinbtxx.sys
O58 - SDL:[MD5.3943209112D5329E39FBF272FEB4BE64] - 28.08.2002 - 22:16:24 ---A- . (.ATI Technologies Inc. - ATI Specialized MVD VBI Codec.) -- C:\WINDOWS\System32\drivers\atinmdxx.sys
O58 - SDL:[MD5.E74208A4DC1BFF9C02A1D2ABE7F4D2D3] - 28.08.2002 - 22:16:26 ---A- . (.ATI Technologies Inc. - ATI Specialized PCD VBI Codec.) -- C:\WINDOWS\System32\drivers\atinpdxx.sys
O58 - SDL:[MD5.AE7CF7785C87CDA85ACAEE341FA5C9E7] - 28.08.2002 - 22:16:26 ---A- . (.ATI Technologies Inc. - ATI Rage Theater Audio WDM Minidriver.) -- C:\WINDOWS\System32\drivers\atinraxx.sys
O58 - SDL:[MD5.BFDD269F073C48045C603EE40292D38E] - 28.08.2002 - 22:16:26 ---A- . (.ATI Technologies Inc. - ATI WDM Rage Theater MiniDriver.) -- C:\WINDOWS\System32\drivers\atinrvxx.sys
O58 - SDL:[MD5.DE8112B2CF0CA43C3F0B0F0319B1B853] - 28.08.2002 - 22:16:28 ---A- . (.ATI Technologies Inc. - ATI WDM TV Sound MiniDriver.) -- C:\WINDOWS\System32\drivers\atinsnxx.sys
O58 - SDL:[MD5.576784030BC44BAF29E7F9C9CBF329AC] - 28.08.2002 - 22:16:28 ---A- . (.ATI Technologies Inc. - ATI WDM Teletext Decoder.) -- C:\WINDOWS\System32\drivers\atinttxx.sys
O58 - SDL:[MD5.24AAB71C27924511EB287E6ED5E066A1] - 28.08.2002 - 22:16:28 ---A- . (.ATI Technologies Inc. - ATI WDM TVTuner MiniDriver.) -- C:\WINDOWS\System32\drivers\atintuxx.sys
O58 - SDL:[MD5.FA9A2EDF1FDE103DE3F731AD0638F96E] - 28.08.2002 - 22:16:30 ---A- . (.ATI Technologies Inc. - ATI WDM CrossBar MiniDriver.) -- C:\WINDOWS\System32\drivers\atinxbxx.sys
O58 - SDL:[MD5.9A03F21983F9FDB65506030F35843CFE] - 28.08.2002 - 22:16:30 ---A- . (.ATI Technologies Inc. - ATI WDM TVAUDIO_CrossBar MiniDriver.) -- C:\WINDOWS\System32\drivers\atinxsxx.sys
O58 - SDL:[MD5.5B44C214F9CD9F590BE9125347610380] - 13.02.2009 - 11:17:49 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver.) -- C:\WINDOWS\System32\drivers\avgntdd.sys
O58 - SDL:[MD5.2DAA8CC2670720DEDDCC74A20EDE2EE9] - 13.02.2009 - 11:28:39 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver Manager.) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
O58 - SDL:[MD5.AD9BD66A862116E79CB45BB6BE46055F] - 30.03.2009 - 09:32:47 ---A- . (.Avira GmbH - Avira Driver for RootKit Detection.) -- C:\WINDOWS\System32\drivers\avipbb.sys
O58 - SDL:[MD5.C9B25AE9B8ABD983C5AD3F8CBFAB0F9C] - 24.04.2003 - 13:00:00 ---A- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\System32\drivers\cinemst2.sys
O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 24.04.2003 - 13:00:00 ---A- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\System32\drivers\cpqdap01.sys
O58 - SDL:[MD5.8182FF89C65E4D38B2DE4BB0FB18564E] - 18.05.2009 - 14:17:00 ---A- . (.GEAR Software Inc. - CD DVD Filter.) -- C:\WINDOWS\System32\drivers\GEARAspiWDM.sys
O58 - SDL:[MD5.D03D10F7DED688FECF50F8FBF1EA9B8A] - 30.10.2007 - 10:25:53 R--A- . (.HP - IEEE-1284.4-1999 Driver (Windows 2000).) -- C:\WINDOWS\System32\drivers\HPZid412.sys
O58 - SDL:[MD5.89F41658929393487B6B7D13C8528CE3] - 30.10.2007 - 10:25:54 R--A- . (.HP - IEEE-1284.4-1999 Print Class Driver.) -- C:\WINDOWS\System32\drivers\HPZipr12.sys
O58 - SDL:[MD5.ABCB05CCDBF03000354B9553820E39F8] - 30.10.2007 - 10:25:55 R--A- . (.HP - 1284.4<->Usb Datalink Driver (Windows 2000).) -- C:\WINDOWS\System32\drivers\HPZius12.sys
O58 - SDL:[MD5.4477689E2D8AE6B78BA34C9AF4CC1ED1] - 24.07.2008 - 17:45:20 ---A- . (.LogMeIn, Inc. - LogMeIn Mirror Miniport Driver.) -- C:\WINDOWS\System32\drivers\lmimirr.sys
O58 - SDL:[MD5.3FAA563DDF853320F90259D455A01D79] - 24.07.2008 - 17:46:10 ---A- . (.LogMeIn, Inc. - LogMeIn Rfs Drivemap Driver.) -- C:\WINDOWS\System32\drivers\LMIRfsDriver.sys
O58 - SDL:[MD5.D2D2FA02B722336960EEAE0AE7107891] - 30.04.2009 - 21:56:32 ---A- . (.Logitech Inc. - Logitech Video Driver.) -- C:\WINDOWS\System32\drivers\LV561AV.SYS
O58 - SDL:[MD5.C57C48FB9AE3EFB9848AF594E3123A63] - 30.04.2009 - 15:00:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
O58 - SDL:[MD5.A1CD8EEC777F05DE505B76BB96709498] - 29.04.2010 - 14:39:24 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys
O58 - SDL:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 29.04.2010 - 14:39:38 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
O58 - SDL:[MD5.B890419554E12B0B5A3F5A175773A03F] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\drivers\netbt.sys
O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 24.04.2003 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\nikedrv.sys
O58 - SDL:[MD5.EF97000C0D078C68BE4A4A3474A01B41] - 28.08.2002 - 22:16:30 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Windows 2000 Miniport Driver, Version 29.58.) -- C:\WINDOWS\System32\drivers\nv4_mini.sys
O58 - SDL:[MD5.00000000000000000000000000000000] - 27.05.2010 - 02:50:45 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\drivers\nwncz.sys
O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 24.04.2003 - 13:00:00 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\System32\drivers\ptilink.sys
O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 24.04.2003 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\System32\drivers\rio8drv.sys
O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 24.04.2003 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\System32\drivers\riodrv.sys
O58 - SDL:[MD5.A6886CAF9D03DADE7144171E471ECA6F] - 15.04.2009 - 07:32:36 R--A- . (.Ralink Technology, Corp. - Ralink 802.11 USB Wireless Adapter Driver.) -- C:\WINDOWS\System32\drivers\rt2870.sys
O58 - SDL:[MD5.D26E26EA516450AF9D072635C60387F4] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\drivers\secdrv.sys
O58 - SDL:[MD5.5A61F7F9DFB3D3BF5C5C72C36A375428] - 24.04.2003 - 13:00:00 ---A- . (.Silicon Integrated Systems Corporation - SiS NT AGP Filter.) -- C:\WINDOWS\System32\drivers\sisagp.sys
O58 - SDL:[MD5.3B78D345F0983F778345C1C817175109] - 17.08.2001 - 19:12:46 ---A- . (.SiS Corporation - SiS PCI Fast Ethernet Adapter Driver.) -- C:\WINDOWS\System32\drivers\sisnic.sys
O58 - SDL:[MD5.3AD0362CF68DE3AC500E981700242CCA] - 11.05.2009 - 09:11:52 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 24.04.2003 - 13:00:00 ---A- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\System32\drivers\tsbvcap.sys
O58 - SDL:[MD5.E8C1B9EBAC65288E1B51E8A987D98AF6] - 16.10.2009 - 01:33:06 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\WINDOWS\System32\drivers\usbaapl.sys
O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 24.04.2003 - 13:00:00 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\System32\drivers\vdmindvd.sys
O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ansi.sys
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\country.sys
O58 - SDL:[MD5.C6D29F29DE7427B1B0775E53E577B623] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\himem.sys
O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\key01.sys
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\keyboard.sys
O58 - SDL:[MD5.7D30A74B5FB9FE3B245A6CE5FBCD71D5] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntdos.sys
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntdos404.sys
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntdos411.sys
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntdos412.sys
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntdos804.sys
O58 - SDL:[MD5.56B6CA884835E478257A4AFE7CE30355] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntio.sys
O58 - SDL:[MD5.08C92D6CCD07C89FAA80167E2F457672] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntio404.sys
O58 - SDL:[MD5.A69805A0C141E37BD7102CE17719181A] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntio411.sys
O58 - SDL:[MD5.774CE1C6703A6CA07E69FCB0995BB7A5] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntio412.sys
O58 - SDL:[MD5.DC6A0C463A32B5A092FB5612084C1DD6] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ntio804.sys


---\\ Liste des outils de nettoyage (LATC) (O63)
O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.)
O63 - Logiciel: ZHPDiag 1.25 - (.Nicolas Coolman.)


---\\ Liste des services Legacy (LALS) (O64)
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\sched.exe - Avira AntiVir Planificateur (AntiVirSchedulerService) .(.Avira GmbH - Antivirus Scheduler.) - LEGACY_ANTIVIRSCHEDULERSERVICE
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\avguard.exe - Avira AntiVir Guard (AntiVirService) .(.Avira GmbH - Antivirus On-Access Service.) - LEGACY_ANTIVIRSERVICE
O64 - Services: CurCS - (.not file.) - appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946} (appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}) .(.Pas de propriétaire - Pas de description.) - LEGACY_APPDRV01.FS.{A7E56839-0B44-4261-8167-6DCA58E79946}
O64 - Services: CurCS - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe - Apple Mobile Device (Apple Mobile Device) .(.Apple Inc. - Apple Mobile Device Service.) - LEGACY_APPLE_MOBILE_DEVICE
O64 - Services: CurCS - C:\Windows\sysTEM32\DRIVERS\avgntdd.sys - avgntdd (avgntdd) .(.Avira GmbH - Avira AntiVir File Filter Driver.) - LEGACY_AVGNTDD
O64 - Services: CurCS - C:\Windows\sysTEM32\DRIVERS\avgntmgr.sys - avgntmgr (avgntmgr) .(.Avira GmbH - Avira AntiVir File Filter Driver Manager.) - LEGACY_AVGNTMGR
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Avira GmbH - Avira Driver for RootKit Detection.) - LEGACY_AVIPBB
O64 - Services: CurCS - C:\Program Files\Bonjour\mDNSResponder.exe - Service Bonjour (Bonjour Service) .(.Apple Inc. - Bonjour Service.) - LEGACY_BONJOUR_SERVICE
O64 - Services: CurCS - (.not file.) - Lanceur de processus serveur DCOM (DcomLaunch) .(.Pas de propriétaire - Pas de description.) - LEGACY_DCOMLAUNCH
O64 - Services: CurCS - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe - InstallDriver Table Manager (IDriverT) .(.Macrovision Corporation - IDriverT Module.) - LEGACY_IDRIVERT
O64 - Services: CurCS - C:\Program Files\iPod\bin\iPodService.exe - Service de l’iPod (iPod Service) .(.Apple Inc. - iPodService Module (32-bit).) - LEGACY_IPOD_SERVICE
O64 - Services: CurCS - C:\Program Files\Java\jre6\bin\jqs.exe - Java Quick Starter (JavaQuickStarterService) .(.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - LEGACY_JAVAQUICKSTARTERSERVICE
O64 - Services: CurCS - C:\Program Files\LogMeIn\x86\RaInfo.sys - LogMeIn Kernel Information Provider (LMIInfo) .(.LogMeIn, Inc. - RemotelyAnywhere Kernel Information Provide.) - LEGACY_LMIINFO
O64 - Services: CurCS - C:\Program Files\LogMeIn\x86\RaMaint.exe - LogMeIn Maintenance Service (LMIMaint) .(.LogMeIn, Inc. - LogMeIn Maintenance Service.) - LEGACY_LMIMAINT
O64 - Services: CurCS - (.not file.) - LMIRfsClientNP (LMIRfsClientNP) .(.Pas de propriétaire - Pas de description.) - LEGACY_LMIRFSCLIENTNP
O64 - Services: CurCS - C:\WINDOWS\system32\drivers\LMIRfsDriver.sys - LogMeIn Remote File System Driver (LMIRfsDriver) .(.LogMeIn, Inc. - LogMeIn Rfs Drivemap Driver.) - LEGACY_LMIRFSDRIVER
O64 - Services: CurCS - C:\Program Files\LogMeIn\x86\LogMeIn.exe - LogMeIn (LogMeIn) .(.LogMeIn, Inc. - LogMeIn.) - LEGACY_LOGMEIN
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\LVPr2Mon.sys - Logitech LVPr2Mon Driver (LVPr2Mon) .(.Pas de propriétaire - Pas de description.) - LEGACY_LVPR2MON
O64 - Services: CurCS - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe - Process Monitor (LVPrcSrv) .(.Logitech Inc. - Logitech LVPrcSrv Module..) - LEGACY_LVPRCSRV
O64 - Services: CurCS - (.not file.) - mountmgr (mountmgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MOUNTMGR
O64 - Services: CurCS - (.not file.) - Mup (Mup) .(.Pas de propriétaire - Pas de description.) - LEGACY_MUP
O64 - Services: CurCS - (.not file.) - Pilote système NDIS (NDIS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDIS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\netbt.sys - NetBIOS sur TCP/IP (NetBT) .(.Pas de propriétaire - Pas de description.) - LEGACY_NETBT
O64 - Services: CurCS - C:\WINDOWS\System32\Drivers\NWNCZ.sys - nwncz (nwncz) .(.Pas de propriétaire - Pas de description.) - LEGACY_NWNCZ
O64 - Services: CurCS - (.not file.) - PartMgr (PartMgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_PARTMGR
O64 - Services: CurCS - (.not file.) - RDPNP (RDPNP) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPNP
O64 - Services: CurCS - (.not file.) - Appel de procédure distante (RPC) (RpcSs) .(.Pas de propriétaire - Pas de description.) - LEGACY_RPCSS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\secdrv.sys - Secdrv (Secdrv) .(.Pas de propriétaire - Pas de description.) - LEGACY_SECDRV
O64 - Services: CurCS - (.not file.) - srescan (srescan) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRESCAN
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\ssmdrv.sys - ssmdrv (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV
O64 - Services: CurCS - (.not file.) - vsdatant (vsdatant) .(.Pas de propriétaire - Pas de description.) - LEGACY_VSDATANT
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\WudfPf.sys - Windows Driver Foundation - User-mode Driver Framework Platform Driver (WudfPf) .(.Pas de propriétaire - Pas de description.) - LEGACY_WUDFPF


---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (r) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (r) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe


---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <Safari.exe> <Safari>[HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files\Safari\Safari.exe


---\\ Recherche d'infection Master Boot Record (O80)
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
Run by Andrée at 27.05.2010 19:33:38
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK



End of the scan (742 lines in 01mn 51s)
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 28 Mai 2010 14:01

Bonjour,

Ok, on continu il y a un truc qui me gène...

Affiche les dossiers cachés:
  • Va sur démarrer / poste de travail / outil / option des dossiers / puis affichage
  • Et coche "Afficher les dossiers cachés"
  • Puis décoche "Masquer les extensions de fichiers" ainsi que "Masquer les fichier protégés du système"
  • Ensuite fais appliquer et ok

Vas sur http://www.virustotal.com/fr/

=> Clique sur " Parcourir " afin de rechercher le fichier à tester
=> Une fois sélectionné , clique sur " Ouvrir "
=> Clique sur " Envoyer "
=> L'envoi du fichier est en cours, patiente pendant quelques secondes
=> Clique sur " Formaté " afin d'avoir un rapport détaillé
=> Poste le moi ici

A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 28 Mai 2010 15:01

Bonjour Florinator,

Arrghh !! Je n'arrive plus à accéder au Net avec ce PC. (Problème DHCP et de réparation de la connexion). As-tu une autre solution pour t'envoyer le fichier ? Ou alors, il faut que je creuse pour réparer la connexion.

Que préfères-tu ?

1. Me donner une autre solution pour scanner ?
2. Que je "répare" Windows" via la console de récupération afin de voir si je peux à nouveau établir une connexion Internet ?

PS : Mais en fait, quel est le fichier que tu souhaites que je t'envoie ?
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 28 Mai 2010 15:22

:plaf: Oups:
C:\WINDOWS\System32\drivers\nwncz.sys

Tu peux effectivement tenter une réparation avec Console de récupération.

A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 28 Mai 2010 15:25

Ok, merci !

Je ne pourrai m'y remettre que dimanche soir. Dans l'intervalle, passe un excellent début de week-end.
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 28 Mai 2010 19:42

Aprés discussion, ne fais pas l'analyse VT
L'infection étant identifiée, fais ceci stp.
Pour qu'il fonctionne correctement il lui faut une connection internet pour qu'il télécharge une copie à jour, si tu n'a toujours pas de net on verra différement:


Télécharge Tdsskiller(fix de Kaspersky) sur ton Bureau

  • Décompresse le fichier en faisant un clique droit dessus
  • Double clique sur le nouveau fichier apparu.
  • Appuie sur une touche pour continuer à la fin de scan
  • Copie-colle le rapport qui apparait

NB:Le fichier est également présent ici : C:\tdsskiller\report.txt

A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 30 Mai 2010 17:41

Bonsoir Florinator,

Voici le rapport TDSSKiller.2.3.1.0_30.05.2010_18.29.28_log

18:29:28:500 2004 TDSS rootkit removing tool 2.3.1.0 May 25 2010 12:52:14
18:29:28:500 2004 ================================================================================
18:29:28:500 2004 SystemInfo:

18:29:28:500 2004 OS Version: 5.1.2600 ServicePack: 1.0
18:29:28:500 2004 Product type: Workstation
18:29:28:500 2004 ComputerName: PC-DE-DEDEE
18:29:28:500 2004 UserName: Andrée
18:29:28:500 2004 Windows directory: C:\WINDOWS
18:29:28:500 2004 Processor architecture: Intel x86
18:29:28:500 2004 Number of processors: 2
18:29:28:500 2004 Page size: 0x1000
18:29:28:500 2004 Boot type: Normal boot
18:29:28:500 2004 ================================================================================
18:29:28:734 2004 Initialize success
18:29:28:734 2004
18:29:28:734 2004 Scanning Services ...
18:29:28:984 2004 Raw services enum returned 337 services
18:29:29:000 2004 Suspicious serv nwncz (h: 0, b: 1)
18:29:29:000 2004
18:29:29:000 2004 Hidden service detected!
18:29:29:000 2004 Service name: nwncz
18:29:29:015 2004 Image path:
18:29:29:015 2004 Type "delete" (without quotes) to delete it: 18:30:02:875 2004
18:30:02:890 2004 By user detect nwncz
18:30:02:890 2004 RegNode HKLM\SYSTEM\ControlSet001\services\nwncz infected by TDSS rootkit ... 18:30:02:890 2004 will be deleted on reboot
18:30:02:890 2004 RegNode HKLM\SYSTEM\ControlSet002\services\nwncz infected by TDSS rootkit ... 18:30:02:890 2004 will be deleted on reboot
18:30:02:906 2004 !dttws2 218:30:02:906 2004 RegNode HKLM\SYSTEM\ControlSet003\services\nwncz infected by TDSS rootkit ... 18:30:02:906 2004 will be deleted on reboot
18:30:02:906 2004 !dttws2 218:30:02:906 2004 RegNode HKLM\SYSTEM\ControlSet004\services\nwncz infected by TDSS rootkit ... 18:30:02:906 2004 will be deleted on reboot
18:30:02:906 2004 File C:\WINDOWS\System32\drivers\nwncz.sys infected by TDSS rootkit ... 18:30:02:906 2004 will be deleted on reboot
18:30:02:921 2004
18:30:02:921 2004 Scanning Drivers ...
18:30:03:328 2004 ACPI (ffdef54a7a4519cf7117536d43deefab) C:\WINDOWS\System32\DRIVERS\ACPI.sys
18:30:03:390 2004 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\System32\drivers\ACPIEC.sys
18:30:03:453 2004 aec (ff773feda15e8bd97fd54fe87a0acdbe) C:\WINDOWS\System32\drivers\aec.sys
18:30:03:531 2004 AFD (51b1872b62d1c335bac53313913c8d5b) C:\WINDOWS\System32\drivers\afd.sys
18:30:03:718 2004 AsyncMac (03f403b07a884fc2aa54a0916c410931) C:\WINDOWS\System32\DRIVERS\asyncmac.sys
18:30:03:812 2004 atapi (95b858761a00e1d4f81f79a0da019aca) C:\WINDOWS\System32\DRIVERS\atapi.sys
18:30:03:890 2004 ati2mtag (d505d4fdaa3497b9e57907a6af379b52) C:\WINDOWS\System32\DRIVERS\ati2mtag.sys
18:30:03:968 2004 Atmarpc (8d735ca1cbdb0081b0e3b9ff0eb222d0) C:\WINDOWS\System32\DRIVERS\atmarpc.sys
18:30:04:015 2004 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\System32\DRIVERS\audstub.sys
18:30:04:062 2004 avgntdd (5b44c214f9cd9f590be9125347610380) C:\WINDOWS\System32\DRIVERS\avgntdd.sys
18:30:04:093 2004 avgntmgr (2daa8cc2670720deddcc74a20ede2ee9) C:\WINDOWS\System32\DRIVERS\avgntmgr.sys
18:30:04:109 2004 avipbb (ad9bd66a862116e79cb45bb6be46055f) C:\WINDOWS\System32\DRIVERS\avipbb.sys
18:30:04:140 2004 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\System32\drivers\Beep.sys
18:30:04:203 2004 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\System32\drivers\cbidf2k.sys
18:30:04:234 2004 CCDECODE (fdc06e2ada8c468ebb161624e03976cf) C:\WINDOWS\System32\DRIVERS\CCDECODE.sys
18:30:04:312 2004 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\System32\drivers\Cdaudio.sys
18:30:04:359 2004 Cdfs (049a38451f2611caf2fd528e023a0b5a) C:\WINDOWS\System32\drivers\Cdfs.sys
18:30:04:421 2004 Cdrom (6506e033ad04cfec9ee56dbefd1083dd) C:\WINDOWS\System32\DRIVERS\cdrom.sys
18:30:04:484 2004 Disk (d1b16340ceaceecbf52340a0cbdf43e1) C:\WINDOWS\System32\DRIVERS\disk.sys
18:30:04:640 2004 dmboot (625043857173294df9239909fc37ccd1) C:\WINDOWS\System32\drivers\dmboot.sys
18:30:04:812 2004 dmio (c85a01b45e107b2d80a1263b365e62b5) C:\WINDOWS\System32\drivers\dmio.sys
18:30:04:890 2004 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\System32\drivers\dmload.sys
18:30:04:921 2004 DMusic (ef05974d47d56fa8387f170f05bae5e7) C:\WINDOWS\System32\drivers\DMusic.sys
18:30:05:015 2004 drmkaud (fd859e517fa2abb53654afa7ec9e3a94) C:\WINDOWS\System32\drivers\drmkaud.sys
18:30:05:093 2004 Fastfat (e4a3a8f3e60b542a747b10e86faa5dad) C:\WINDOWS\System32\drivers\Fastfat.sys
18:30:05:125 2004 Fdc (19c5c7eac0190a42522290bf002f64ea) C:\WINDOWS\System32\DRIVERS\fdc.sys
18:30:05:187 2004 Fips (8b121ff880683607ab2aef0340721718) C:\WINDOWS\System32\drivers\Fips.sys
18:30:05:234 2004 Flpydisk (8f70d1f7606f7442e2f7383f3701d728) C:\WINDOWS\System32\DRIVERS\flpydisk.sys
18:30:05:312 2004 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\System32\drivers\fltmgr.sys
18:30:05:375 2004 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\System32\drivers\Fs_Rec.sys
18:30:05:406 2004 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\System32\DRIVERS\ftdisk.sys
18:30:05:468 2004 gameenum (6d18cad8a05d88e672b61db855a08289) C:\WINDOWS\System32\DRIVERS\gameenum.sys
18:30:05:515 2004 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\System32\DRIVERS\GEARAspiWDM.sys
18:30:05:593 2004 Gpc (13591e0a02e85de2a388f3ec4bd206df) C:\WINDOWS\System32\DRIVERS\msgpc.sys
18:30:05:656 2004 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\System32\DRIVERS\hidusb.sys
18:30:05:687 2004 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\System32\DRIVERS\HPZid412.sys
18:30:05:734 2004 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\System32\DRIVERS\HPZipr12.sys
18:30:05:750 2004 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\System32\DRIVERS\HPZius12.sys
18:30:05:812 2004 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\System32\Drivers\HTTP.sys
18:30:05:906 2004 i8042prt (62df7f3c91015d236353956995d02e80) C:\WINDOWS\System32\DRIVERS\i8042prt.sys
18:30:06:140 2004 Imapi (3cb4410747f2330d97b10b656d5bb2ac) C:\WINDOWS\System32\DRIVERS\imapi.sys
18:30:06:234 2004 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\System32\DRIVERS\intelppm.sys
18:30:06:250 2004 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\System32\drivers\ip6fw.sys
18:30:06:312 2004 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys
18:30:06:375 2004 IpInIp (f56dd863ba732a4e8ee58d486c31250f) C:\WINDOWS\System32\DRIVERS\ipinip.sys
18:30:06:406 2004 IpNat (fc672ad6e9676814a0c844912f2abcff) C:\WINDOWS\System32\DRIVERS\ipnat.sys
18:30:06:468 2004 IPSec (1c4802409cfd4a7051f458b744cfcaa5) C:\WINDOWS\System32\DRIVERS\ipsec.sys
18:30:06:500 2004 IRENUM (b43201394646b7e98c89056edda686b5) C:\WINDOWS\System32\DRIVERS\irenum.sys
18:30:06:593 2004 isapnp (54632f1a7de61dc3615d756f2a90fa72) C:\WINDOWS\System32\DRIVERS\isapnp.sys
18:30:06:671 2004 Kbdclass (9bb4976aacd2c9df788afcc53abb790c) C:\WINDOWS\System32\DRIVERS\kbdclass.sys
18:30:06:718 2004 kbdhid (8e5be87acab17764c034cb8e4b19742b) C:\WINDOWS\System32\DRIVERS\kbdhid.sys
18:30:06:796 2004 klmd23 (0b06b0a25e08df0d536402bce3bde61e) C:\WINDOWS\System32\drivers\klmd.sys
18:30:06:843 2004 kmixer (10e0feb086d8c1419b958c9034e4668a) C:\WINDOWS\System32\drivers\kmixer.sys
18:30:06:906 2004 KSecDD (abc70e8b89cce44731a346deb764bf95) C:\WINDOWS\System32\drivers\KSecDD.sys
18:30:07:031 2004 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
18:30:07:078 2004 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\System32\DRIVERS\lmimirr.sys
18:30:07:109 2004 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\System32\drivers\LMIRfsDriver.sys
18:30:07:140 2004 LVPr2Mon (c57c48fb9ae3efb9848af594e3123a63) C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys
18:30:07:203 2004 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\System32\drivers\mnmdd.sys
18:30:07:250 2004 Modem (2ceb658d70506dbb6a447e8fd3b8ff73) C:\WINDOWS\System32\drivers\Modem.sys
18:30:07:312 2004 Mouclass (b974771970ae24f6113e3e1434f10103) C:\WINDOWS\System32\DRIVERS\mouclass.sys
18:30:07:359 2004 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\System32\DRIVERS\mouhid.sys
18:30:07:421 2004 MountMgr (d4face53a1c48cf8419b4cf494d2ee2e) C:\WINDOWS\System32\drivers\MountMgr.sys
18:30:07:484 2004 MRxDAV (d30cba20cc355d3648b9fed5bb55a9d5) C:\WINDOWS\System32\DRIVERS\mrxdav.sys
18:30:07:656 2004 MRxSmb (7a3a2be44e12e2abde1af891e83ac130) C:\WINDOWS\System32\DRIVERS\mrxsmb.sys
18:30:07:843 2004 Msfs (a1831538e119363d0d90d757ac8a2012) C:\WINDOWS\System32\drivers\Msfs.sys
18:30:07:921 2004 MSKSSRV (85736f804191cb420a31aca2a7f0674f) C:\WINDOWS\System32\drivers\MSKSSRV.sys
18:30:07:968 2004 MSPCLOCK (e943adb93d83c5cbc0ca3f53f53b48cc) C:\WINDOWS\System32\drivers\MSPCLOCK.sys
18:30:08:015 2004 MSPQM (f6a726b8832db1f88326b8be98b11981) C:\WINDOWS\System32\drivers\MSPQM.sys
18:30:08:078 2004 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\System32\DRIVERS\mssmbios.sys
18:30:08:109 2004 MSTEE (d5059366b361f0e1124753447af08aa2) C:\WINDOWS\System32\drivers\MSTEE.sys
18:30:08:187 2004 Mup (08c56887f06473b09fc1b39e7dec0fb6) C:\WINDOWS\System32\drivers\Mup.sys
18:30:08:265 2004 NABTSFEC (ac31b352ce5e92704056d409834beb74) C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys
18:30:08:328 2004 NDIS (3b350e5a2a5e951453f3993275a4523a) C:\WINDOWS\System32\drivers\NDIS.sys
18:30:08:421 2004 NdisIP (abd7629cf2796250f315c1dd0b6cf7a0) C:\WINDOWS\System32\DRIVERS\NdisIP.sys
18:30:08:484 2004 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\System32\DRIVERS\ndistapi.sys
18:30:08:546 2004 Ndisuio (e6b6d5e4c9c199b7bb56d7862ea68fbc) C:\WINDOWS\System32\DRIVERS\ndisuio.sys
18:30:08:656 2004 NdisWan (15787deca8c5428beeaa8044f544fd85) C:\WINDOWS\System32\DRIVERS\ndiswan.sys
18:30:08:718 2004 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\System32\drivers\NDProxy.sys
18:30:08:765 2004 NetBIOS (e351339fa17c4a70940e15b5e3dae6e2) C:\WINDOWS\System32\DRIVERS\netbios.sys
18:30:08:843 2004 NetBT (d96f3bc5a6e7452b0e3275b560dc8528) C:\WINDOWS\System32\DRIVERS\netbt.sys
18:30:08:906 2004 Npfs (20aba9f035e3a98877480e34fcc4dcb3) C:\WINDOWS\System32\drivers\Npfs.sys
18:30:09:015 2004 Ntfs (e3ae9c79498210a5f39fe5a9ad62bc55) C:\WINDOWS\System32\drivers\Ntfs.sys
18:30:09:171 2004 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\System32\drivers\Null.sys
18:30:09:203 2004 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys
18:30:09:281 2004 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys
18:30:09:343 2004 nwncz (2aaca53b0486e329e516e30f5430e26a) C:\WINDOWS\System32\drivers\nwncz.sys
18:30:09:343 2004 Suspicious file (NoAccess): C:\WINDOWS\System32\drivers\nwncz.sys. md5: 2aaca53b0486e329e516e30f5430e26a
18:30:09:468 2004 Parport (1d6219ddb4327f0f317656f91228ea9e) C:\WINDOWS\System32\DRIVERS\parport.sys
18:30:09:515 2004 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\System32\drivers\PartMgr.sys
18:30:09:546 2004 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\System32\drivers\ParVdm.sys
18:30:09:640 2004 PCI (abbb48b084a52de8ff9c2f50b3dc2ec1) C:\WINDOWS\System32\DRIVERS\pci.sys
18:30:09:703 2004 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\System32\DRIVERS\pciide.sys
18:30:09:750 2004 Pcmcia (ae3a8f77efeed4c1a6e58fd8ce84f21f) C:\WINDOWS\System32\drivers\Pcmcia.sys
18:30:09:953 2004 PID_0928 (d2d2fa02b722336960eeae0ae7107891) C:\WINDOWS\System32\DRIVERS\LV561AV.SYS
18:30:10:031 2004 PptpMiniport (fed674d73eb56c35444f701e847bf85b) C:\WINDOWS\System32\DRIVERS\raspptp.sys
18:30:10:062 2004 Processor (7debdb2e9c5d84610a650c87fa1fa3f2) C:\WINDOWS\System32\DRIVERS\processr.sys
18:30:10:125 2004 PSched (944440247fe6988c88b376ed85a0cd1a) C:\WINDOWS\System32\DRIVERS\psched.sys
18:30:10:171 2004 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\System32\DRIVERS\ptilink.sys
18:30:10:250 2004 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\System32\DRIVERS\rasacd.sys
18:30:10:296 2004 Rasl2tp (4c242c79a9c0d98d52d6f8cb9248d528) C:\WINDOWS\System32\DRIVERS\rasl2tp.sys
18:30:10:343 2004 RasPppoe (888335b3be346119cf7b4eff3a3fca7c) C:\WINDOWS\System32\DRIVERS\raspppoe.sys
18:30:10:390 2004 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\System32\DRIVERS\raspti.sys
18:30:10:453 2004 Rdbss (df80c149c96fcfbb8a3dc3d5dd950aa8) C:\WINDOWS\System32\DRIVERS\rdbss.sys
18:30:10:515 2004 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
18:30:10:609 2004 RDPWD (0606700377b6fb8b04475e92507adade) C:\WINDOWS\System32\drivers\RDPWD.sys
18:30:10:671 2004 redbook (11aed740d537f83be05320b7c285a633) C:\WINDOWS\System32\DRIVERS\redbook.sys
18:30:10:734 2004 rt2870 (a6886caf9d03dade7144171e471eca6f) C:\WINDOWS\System32\DRIVERS\rt2870.sys
18:30:10:843 2004 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\System32\DRIVERS\secdrv.sys
18:30:10:875 2004 serenum (65a7c4d86c153c82e33a552c217abb29) C:\WINDOWS\System32\DRIVERS\serenum.sys
18:30:10:953 2004 Serial (ffea735f27122f0877d032b29f1659a2) C:\WINDOWS\System32\DRIVERS\serial.sys
18:30:10:984 2004 Sfloppy (4e1b8866f3d208dee3906a191cb493e3) C:\WINDOWS\System32\drivers\Sfloppy.sys
18:30:11:062 2004 SiS7018 (d3ba744433f14e5c77107d9d82297801) C:\WINDOWS\System32\drivers\ac97sis.sys
18:30:11:218 2004 SISNIC (3b78d345f0983f778345c1c817175109) C:\WINDOWS\System32\DRIVERS\sisnic.sys
18:30:11:421 2004 SLIP (1ffc44d6787ec1ea9a2b1440a90fa5c1) C:\WINDOWS\System32\DRIVERS\SLIP.sys
18:30:11:484 2004 splitter (32c54211e9e8a45cbcb097beaeb1999a) C:\WINDOWS\System32\drivers\splitter.sys
18:30:11:546 2004 sr (19e699e7a48e6b44c583111e0da6f123) C:\WINDOWS\System32\DRIVERS\sr.sys
18:30:11:656 2004 Srv (94619eb663216f9bf12f9b950fcab3c0) C:\WINDOWS\System32\DRIVERS\srv.sys
18:30:11:734 2004 ssmdrv (3ad0362cf68de3ac500e981700242cca) C:\WINDOWS\System32\DRIVERS\ssmdrv.sys
18:30:11:765 2004 streamip (a9f9fd0212e572b84edb9eb661f6bc04) C:\WINDOWS\System32\DRIVERS\StreamIP.sys
18:30:11:843 2004 swenum (616a013d3ea068b6dee83d905e92ee9f) C:\WINDOWS\System32\DRIVERS\swenum.sys
18:30:11:921 2004 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\System32\drivers\swmidi.sys
18:30:12:031 2004 sysaudio (b0b19f036f76333ab3338c7493e87b12) C:\WINDOWS\System32\drivers\sysaudio.sys
18:30:12:125 2004 Tcpip (244a2f9816bc9b593957281ef577d976) C:\WINDOWS\System32\DRIVERS\tcpip.sys
18:30:12:171 2004 TDPIPE (1a96630babbd59e8b885eae0dfbe6a3e) C:\WINDOWS\System32\drivers\TDPIPE.sys
18:30:12:234 2004 TDTCP (d1c578c6b37713694c5edd7c2d7f7451) C:\WINDOWS\System32\drivers\TDTCP.sys
18:30:12:265 2004 TermDD (194c51bc28a7ce9818012142b062e431) C:\WINDOWS\System32\DRIVERS\termdd.sys
18:30:12:343 2004 uagp35 (d85938f272d1bcf3db3a31fc0a048928) C:\WINDOWS\System32\DRIVERS\uagp35.sys
18:30:12:390 2004 Udfs (01ca8ec606522d2f60820b0c0086fdd5) C:\WINDOWS\System32\drivers\Udfs.sys
18:30:12:453 2004 Update (164cfae1d766905f56c432acfc54f28c) C:\WINDOWS\System32\DRIVERS\update.sys
18:30:12:515 2004 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\WINDOWS\System32\Drivers\usbaapl.sys
18:30:12:562 2004 usbccgp (79fee3cfec5b14194dbe0a703d82b2a4) C:\WINDOWS\System32\DRIVERS\usbccgp.sys
18:30:12:656 2004 usbehci (2d0c2f3836f72e85d41d9c50aeeb5423) C:\WINDOWS\System32\DRIVERS\usbehci.sys
18:30:12:734 2004 usbhub (d7bf70ac85e48b6c4df953401eccb75a) C:\WINDOWS\System32\DRIVERS\usbhub.sys
18:30:12:750 2004 usbohci (4e7d2f6df7a7e02d80fe0b109f0c9f02) C:\WINDOWS\System32\DRIVERS\usbohci.sys
18:30:12:812 2004 usbprint (c9a83be290c89730ae59f6c3085f072d) C:\WINDOWS\System32\DRIVERS\usbprint.sys
18:30:12:843 2004 usbscan (7691af2109474eb923004f3dca4c9559) C:\WINDOWS\System32\DRIVERS\usbscan.sys
18:30:12:875 2004 USBSTOR (4923c60f9c381eae679db04021d26abb) C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS
18:30:12:921 2004 VgaSave (08d2edfd7261242b8aea27f1fe11e120) C:\WINDOWS\System32\drivers\vga.sys
18:30:12:968 2004 VolSnap (3a0f57ccd37ed8eb0d59cf10bcd8035e) C:\WINDOWS\System32\drivers\VolSnap.sys
18:30:13:031 2004 Wanarp (484af08f15d1306ff2e8b64fe62a160c) C:\WINDOWS\System32\DRIVERS\wanarp.sys
18:30:13:125 2004 wdmaud (499b653356a9e5589ee83ac47e5d2a8c) C:\WINDOWS\System32\drivers\wdmaud.sys
18:30:13:203 2004 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\System32\DRIVERS\wpdusb.sys
18:30:13:234 2004 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:30:13:328 2004 WSTCODEC (233cdd1c06942115802eb7ce6669e099) C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS
18:30:13:375 2004 WudfPf (a78a2ceca73de110c3efb8f1a1410de6) C:\WINDOWS\System32\DRIVERS\WudfPf.sys
18:30:13:375 2004 File "C:\WINDOWS\System32\DRIVERS\WudfPf.sys" infected by TDSS rootkit ... 18:30:14:468 2004 Backup copy not found, trying to cure infected file..
18:30:14:468 2004 Cure success, using it..
18:30:14:468 2004 will be cured on next reboot
18:30:14:546 2004 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\System32\DRIVERS\wudfrd.sys
18:30:14:546 2004 Reboot required for cure complete..
18:30:14:718 2004 Cure on reboot scheduled successfully
18:30:14:718 2004
18:30:14:765 2004 Completed
18:30:14:828 2004
18:30:14:875 2004 Results:
18:30:14:937 2004 Registry objects infected / cured / cured on reboot: 4 / 0 / 4
18:30:14:984 2004 File objects infected / cured / cured on reboot: 2 / 0 / 2
18:30:15:046 2004
18:30:15:109 2004 KLMD(ARK) unloaded successfully
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 30 Mai 2010 18:21

Bonjour,

Ok, parfait.


  • Copie ces lignes ci dessous:

Code: Tout sélectionner
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified 
O2 - BHO: (no name) - {02F843F2-D898-4B70-A289-AF5E13BD84C0} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\diskcopy32.dll 
O43 - CFD:Common File Directory ----D- C:\Program Files\TryMedia
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26.05.2010 - 12:27:22 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\5909.exe [0] 
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26.05.2010 - 12:07:21 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\6907.exe [0] 
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 26.05.2010 - 11:47:21 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\31214.exe [0]
O47 - AAKE:Key Export SP - "C:\Program Files\PowerJass\sjOnline\powerjassonline.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\PowerJass\sjOnline\powerjassonline.exe 
O44 - LFC:[MD5.42E765188DD7515E79369785E033D7B0] - 10.05.2010 - 10:26:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\1558017581 [817] 
O44 - LFC:[MD5.4D9511C64FA2F86F6DA177481B795D4C] - 10.05.2010 - 08:10:56 -SHA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\210577021 [1061]
O44 - LFC:[MD5.E9D9927EF032BECA97C42B0F03E191A0] - 25.05.2010 - 19:45:06 R--A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SETAF.tmp [13923] 
O44 - LFC:[MD5.87D7EBA2D823656EEB29FE6938932298] - 25.05.2010 - 19:45:04 R--A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SETA3.tmp [1086182]


  • Ouvre ZHPDiag, puis clique sur l'icône Image
    Si l'icône n'apparait pas, relance un scan avec ZHPDiag, à la fin du scan elle apparaitra
  • Clique successivement sur l'icône Image,pour effacer le rapport qui s'est affiché
  • Clique ensuite sur Image pour coller la sélection
  • Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre
  • Clique sur "OK", ce qui fait apparaître un carré à gauche de chaque ligne.
  • Clique sur "Tous" puis sur "Nettoyer".
    Si on te demande de redémarrer l'ordi pour achever le nettoyage, fais le immmédiatement.
  • Copie/colle le rapport dans ton prochain post.

Remarque:Le rapport se situe aussi sous C:\Program Files\ZebHelpProcess\ZHPFixReport.txt


:learn: Télécharge Sécunia
Exécute le et mets tout ce qu'il trouve à jour stp.


A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 30 Mai 2010 18:32

Voici : (pas eu besoin de rebooter)

ZHPFix v1.12.3102 by Nicolas Coolman - Rapport de suppression du 30.05.2010 19:30:12
Fichier Registre : C:\ZHPExportRegistry-30.05.2010-19-30-12.txt
Web site : http://www.premiumorange.com/zeb-help-p ... hpfix.html
Contact : nicolascoolman@yahoo.fr

Processus mémoire :
(Néant)

Module mémoire :
(Néant)

Clé du Registre :
O2 - BHO: (no name) - {02F843F2-D898-4B70-A289-AF5E13BD84C0} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\diskcopy32.dll => Clé absente

Valeur du Registre :
O47 - AAKE:Key Export SP - "C:\Program Files\PowerJass\sjOnline\powerjassonline.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\PowerJass\sjOnline\powerjassonline.exe => Valeur supprimée avec succès
O47 - AAKE:Key Export SP - "C:\Program Files\PowerJass\sjOnline\powerjassonline.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\PowerJass\sjOnline\powerjassonline.exe => Valeur absente

Elément de données du Registre :
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified => Donnée supprimée avec succès

Préférences navigateur :
(Néant)

Dossier :
C:\Program Files\TryMedia => Supprimé et mis en quarantaine

Fichier :
c:\windows\system32\diskcopy32.dll => Fichier absent
c:\windows\system32\5909.exe => Supprimé et mis en quarantaine
c:\windows\system32\6907.exe => Supprimé et mis en quarantaine
c:\windows\system32\31214.exe => Supprimé et mis en quarantaine
c:\program files\powerjass\sjonline\powerjassonline.exe => Fichier absent
c:\windows\system32\1558017581 => Supprimé et mis en quarantaine
c:\windows\system32\210577021 => Supprimé et mis en quarantaine
c:\windows\setaf.tmp => Supprimé et mis en quarantaine
c:\windows\seta3.tmp => Supprimé et mis en quarantaine
c:\windows\system32\5909.exe => Fichier absent
c:\windows\system32\6907.exe => Fichier absent
c:\windows\system32\31214.exe => Fichier absent
c:\windows\system32\1558017581 => Fichier absent
c:\windows\system32\210577021 => Fichier absent
c:\windows\setaf.tmp => Fichier absent
c:\windows\seta3.tmp => Fichier absent

Logiciel :
(Néant)

Script Registre :
(Néant)

Master Boot Record :
(Néant)

Autre :
(Néant)


Récapitulatif :
Processus mémoire : 0
Module mémoire : 0
Clé du Registre : 1
Valeur du Registre : 2
Elément de données du Registre : 1
Dossier : 1
Fichier : 16
Logiciel : 0
Master Boot Record : 0
Préférences navigateur : 0
Autre : 0


End of the scan


Je lance Secunia.
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 30 Mai 2010 22:10

Dés que tu as fait toutes les mises à jours, refais moi un scan ZHPDiag stp.
As tu toujours des redirections de pages?

A++
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 30 Mai 2010 23:34

Et voilà, les mises à jour sont faites. Je n'ai plus de redirections de pages.

1ère partie
Rapport de ZHPDiag v1.25.1426 par Nicolas Coolman, Update du 06/05/2010
Run by Andrée at 31.05.2010 00:28:35
Web site : http://www.premiumorange.com/zeb-help-p ... pdiag.html
Contact : nicolascoolman@yahoo.fr

---\\ Web Browser
MSIE: Internet Explorer v8.0.6001.18702
MFIE: Mozilla Firefox (3.6.3)

---\\ System Information
Platform : Microsoft Windows XP (5.1.2600) Service Pack 3
Processor: x86 Family 15 Model 2 Stepping 9, GenuineIntel
Operating System: 32 Bits
Boot mode: Normal (Normal boot)
Total RAM: 511.5 MB (21% free)
System drive C: has 76 GB (65%) free of 115 GB

---\\ Logged in mode
Computer Name: PC-DE-DEDEE
User Name: Andrée
Unselected Option: O1,O45,O61,O65
Logged in as Administrator

---\\ DOS/Devices
A:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
C:\ Hard drive, Flash drive, Thumb drive (Free 76 Go of 115 Go)
D:\ CD-ROM drive (Not Inserted)
E:\ CD-ROM drive (Not Inserted)


---\\ Security Center & Tools Informations
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: OK
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK


---\\ Processus lancés
[MD5.234051C0D242A6F4A79AE5212C1323D4] - (.LogMeIn, Inc. - LogMeIn Desktop Application.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe [63048]
[MD5.29680A793F690EEF4AAA68479D2A6DF8] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [209153]
[MD5.FF473648E7B1B37C7F3249A6549FAC72] - (.Hewlett-Packard - HpqSRmon.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [150016]
[MD5.3B8C106587A57159639713EEE074EF83] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe [2780432]
[MD5.F91F52F4EA5D88DAB6245682A16F3A72] - (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [36272]
[MD5.DB1DB28467111A24664933AB8908CBCE] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [952768]
[MD5.FD89A30C8A9FF4929ABC5039E6A527A4] - (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe [47392]
[MD5.ED7A6D40B20DC34BE06F4AE196AE7D50] - (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe [421888]
[MD5.52DB6CDAC5BC7A1FC884E97C41C91213] - (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe [248040]
[MD5.21293443961A4E2597453EE7A9347F22] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [54840]
[MD5.59DC5BB82E4C8E0B3EADCFDBC44BA6E4] - (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe [15360]
[MD5.E13EA4860E8F2AA845B53BFD2B6FEC5B] - (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe [1695232]
[MD5.E60BD23059B3E0C8D59B71CAB743445D] - (.Logitech Inc. - Logitech Vid.) -- C:\Program Files\Logitech\Logitech Vid\vid.exe [5451536]
[MD5.9015BC03F62940527EC92D45EE89E46F] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [108289]
[MD5.B8720A787C1223492E6F319465E996CE] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [185089]
[MD5.ACB095E7E1663F1B83A41C22C5D75F90] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe [144672]
[MD5.E4BDF223CD75478BF44567B4D5C2634D] - (.Microsoft Corporation - Generic Host Process for Win32 Services.) -- C:\WINDOWS\System32\svchost.exe [14336]
[MD5.C3FB1D70CB88722267949694BA51759E] - (.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\WINDOWS\system32\services.exe [111104]
[MD5.1834C96FB1F9280BCF6DDFA6DE8338BF] - (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) -- C:\Program Files\Java\jre6\bin\jqs.exe [153376]
[MD5.500F1E4461075D602CE77109A9A3D634] - (.LogMeIn, Inc. - LogMeIn Maintenance Service.) -- C:\Program Files\LogMeIn\x86\RaMaint.exe [116032]
[MD5.9015122D04C195BDAB88FEBCBAE229DB] - (.LogMeIn, Inc. - LogMeIn.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe [63040]
[MD5.5C7B88695CE461D8BDA4FE0C0E57E71D] - (.Logitech Inc. - Logitech LVPrcSrv Module..) -- C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe [154136]
[MD5.91E6024D6D4DCDECDB36C43ECF9BBECB] - (.Microsoft Corporation - LSA Shell (Export Version).) -- C:\WINDOWS\System32\lsass.exe [13312]
[MD5.460E4CE148BD07218DA0B6A3D31885A9] - (.Microsoft Corporation - Spooler SubSystem App.) -- C:\WINDOWS\system32\spoolsv.exe [57856]


---\\ Modification d'une valeur Ini (Changed inifile value, mapped to Registry) (F2)
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,


---\\ Pages de recherche d'Internet Explorer (R1)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


---\\ Internet Explorer URLSearchHook (R3)
R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)) -- C:\WINDOWS\system32\ieframe.dll


---\\ Browser Helper Objects de navigateur (O2)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} . (.Hewlett-Packard Co. - HP Smart Web Printing add-on for Internet E.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} . (.Sun Microsystems, Inc. - Java(TM) Quick Starter binary.) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} . (.Hewlett-Packard Co. - HP Smart Web Printing add-on for Internet E.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll


---\\ Applications démarrées automatiquement par le registre (O4)
O4 - HKLM\..\Run: [LogMeIn GUI] . (.LogMeIn, Inc. - LogMeIn Desktop Application.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
O4 - HKLM\..\Run: [hpqSRMon] . (.Hewlett-Packard - HpqSRmon.) -- C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] . (.Apple Inc. - AppleSyncNotifier.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java(TM) Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [Logitech Vid] . (.Logitech Inc. - Logitech Vid.) -- C:\Program Files\Logitech\Logitech Vid\vid.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] . (.Microsoft Corporation - CTF Loader.) -- C:\WINDOWS\System32\CTFMON.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk . (.Hewlett-Packard Co. - HP Digital Imaging Monitor.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Secunia PSI.lnk . (.Secunia - Secunia PSI.) -- C:\Program Files\Secunia\PSI\psi.exe


---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
O9 - Extra button: Afficher ou masquer l'HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} . (.Hewlett-Packard Co. - HP Smart Web Printing add-on for Internet Explorer.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} . (.Microsoft Corporation - Windows Messenger.) -- C:\Program Files\Messenger\msmsgs.exe


---\\ Winsock hijacker (Layered Service Provider) (O10)
O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll


---\\ Objets ActiveX (Downloaded Program Files)(O16)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net ... plugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shoc ... tor/sw.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftup ... 9842410433
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 9842400681
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} () - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab


---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll
O20 - Winlogon Notify: LMIinit . (.LogMeIn, Inc. - LogMeIn Remote Control Helper.) -- C:\WINDOWS\System32\LMIinit.dll


---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\System32\stobject.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\WPDShServiceObj.dll


---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll


---\\ Liste des services NT non Microsoft et non désactivés (O23)
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) . (.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) . (.LogMeIn, Inc. - LogMeIn Maintenance Service.) - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn (LogMeIn) . (.LogMeIn, Inc. - LogMeIn.) - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Process Monitor (LVPrcSrv) . (.Logitech Inc. - Logitech LVPrcSrv Module..) - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe


---\\ Tâches planifiées en automatique (O39)
O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


---\\ Composants installés (ActiveSetup Installed Components) (O40)
O40 - ASIC: Personnalisation du navigateur - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS . (.Pas de propriétaire - Pas de description.) -- RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre6\bin\regutils.dll
O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
O40 - ASIC: Windows Messenger 4.7 - {5945c046-1e7d-11d1-bc44-00c04fd912be} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msmsgs.inf
O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\wmp.inf
O40 - ASIC: Adobe Flash Player - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 10.0 r45.) -- C:\WINDOWS\system32\Macromed\Flash\Flash10e.ocx


---\\ Pilotes lancés au démarrage (O41)
O41 - Driver: avgntdd (avgntdd) . (.Avira GmbH - Avira AntiVir File Filter Driver.) - C:\Windows\sysTEM32\DRIVERS\avgntdd.sys
O41 - Driver: avipbb (avipbb) . (.Avira GmbH - Avira Driver for RootKit Detection.) - C:\Windows\system32\DRIVERS\avipbb.sys
O41 - Driver: ssmdrv (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\Windows\system32\DRIVERS\ssmdrv.sys


---\\ Logiciels installés (O42)
O42 - Logiciel: 32 Bit HP CIO Components Installer - (.Hewlett-Packard.) [HKLM]
O42 - Logiciel: Adobe AIR - (.Adobe Systems Inc..) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 ActiveX - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Flash Player 10 Plugin - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Reader 9.3.2 - Français - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Adobe Shockwave Player 11.5 - (.Adobe Systems, Inc..) [HKLM]
O42 - Logiciel: Apple Application Support - (.Apple Inc..) [HKLM]
O42 - Logiciel: Apple Mobile Device Support - (.Apple Inc..) [HKLM]
O42 - Logiciel: Apple Software Update - (.Apple Inc..) [HKLM]
O42 - Logiciel: Assistant de connexion Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Avira AntiVir Personal - Free Antivirus - (.Avira GmbH.) [HKLM]
O42 - Logiciel: HP Customer Participation Program 10.0 - (.HP.) [HKLM]
O42 - Logiciel: HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3 - (.HP.) [HKLM]
O42 - Logiciel: HP Imaging Device Functions 10.0 - (.HP.) [HKLM]
O42 - Logiciel: HP Photosmart Essential 3.5 - (.HP.) [HKLM]
O42 - Logiciel: HP Smart Web Printing 4.60 - (.HP.) [HKLM]
O42 - Logiciel: HP Solution Center 13.0 - (.HP.) [HKLM]
O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM]
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Installation Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Java(TM) 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM]
O42 - Logiciel: Java(TM) 6 Update 20 - (.Sun Microsystems, Inc..) [HKLM]
O42 - Logiciel: LFP Manager 2004 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Lecteur Windows Media 11 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: LogMeIn - (.LogMeIn, Inc..) [HKLM]
O42 - Logiciel: Logitech Vid - (.Logitech Inc..) [HKLM]
O42 - Logiciel: Logitech Webcam Software - (.Logitech Inc..) [HKLM]
O42 - Logiciel: MSVCRT - (.Microsoft.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB954430) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 4.0 SP2 (KB973688) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MSXML 6 Service Pack 2 (KB973686) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Malwarebytes' Anti-Malware - (.Malwarebytes Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 2.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.0 Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft .NET Framework 3.5 SP1 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Choice Guard - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Compression Client Pack 1.0 for Windows XP - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Silverlight - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft User-Mode Driver Framework Feature Pack 1.0 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: MobileMe Control Panel - (.Apple Inc..) [HKLM]
O42 - Logiciel: Mozilla Firefox (3.6.3) - (.Mozilla.) [HKLM]
O42 - Logiciel: OpenOffice.org 3.2 - (.OpenOffice.org.) [HKLM]
O42 - Logiciel: Outil de téléchargement Windows Live - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: QuickTime - (.Apple Inc..) [HKLM]
O42 - Logiciel: Safari - (.Apple Inc..) [HKLM]
O42 - Logiciel: Secunia PSI - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Security Update for CAPICOM (KB931906) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Segoe UI - (.Microsoft Corp.) [HKLM]
O42 - Logiciel: Shop for HP Supplies - (.HP.) [HKLM]
O42 - Logiciel: Spelling Dictionaries Support For Adobe Reader 9 - (.Adobe Systems Incorporated.) [HKLM]
O42 - Logiciel: Uninstall 1.0.0.1 - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: VC 9.0 Runtime - (.Check Point Software Technologies Ltd.) [HKLM]
O42 - Logiciel: VLC media player 1.0.2 - (.VideoLAN Team.) [HKLM]
O42 - Logiciel: Windows Genuine Advantage Validation Tool (KB892130) - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Internet Explorer 8 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Call - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Communications Platform - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Live Messenger - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Format 11 runtime - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows Media Format 11 runtime - (.Pas de propriétaire.) [HKLM]
O42 - Logiciel: Windows Media Player 11 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows XP Service Pack 2 - (.Microsoft Corporation.) [HKLM]
O42 - Logiciel: Windows XP Service Pack 3 - (.Microsoft Corporation.) [HKLM]

---\\ HKCU & HKLM Software Keys
[HKCU\Software\Adobe]
[HKCU\Software\AppDataLow]
[HKCU\Software\Apple Computer, Inc.]
[HKCU\Software\Apple Inc.]
[HKCU\Software\Applications locales générées par AppWizard]
[HKCU\Software\Aurigma]
[HKCU\Software\Avira]
[HKCU\Software\Borland]
[HKCU\Software\Classes]
[HKCU\Software\Cyanide]
[HKCU\Software\DVDVideoSoft]
[HKCU\Software\Hewlett-Packard]
[HKCU\Software\IM Providers]
[HKCU\Software\ImageViewer]
[HKCU\Software\JEDI-VCL]
[HKCU\Software\JavaSoft]
[HKCU\Software\Local AppWizard-Generated Applications]
[HKCU\Software\LogMeIn]
[HKCU\Software\LogiShrd]
[HKCU\Software\Logitech]
[HKCU\Software\Macromedia]
[HKCU\Software\Magnet]
[HKCU\Software\Malwarebytes' Anti-Malware]
[HKCU\Software\Mozilla]
[HKCU\Software\Netscape]
[HKCU\Software\Oigixdeors]
[HKCU\Software\OpenOffice.org]
[HKCU\Software\Policies]
[HKCU\Software\SecuROM]
[HKCU\Software\Secunia]
[HKCU\Software\Skype]
[HKCU\Software\Team17SoftwareLTD]
[HKCU\Software\Trolltech]
[HKCU\Software\YahooPartnerToolbar]
[HKCU\Software\mgSoftware]
[HKCU\Software\perforce]
[HKCU\Software\shockwave.com]
[HKCU\Software\yahooinstall]
[HKLM\Software\ATI Technologies]
[HKLM\Software\Adobe]
[HKLM\Software\AppDataLow]
[HKLM\Software\Apple Computer, Inc.]
[HKLM\Software\Apple Inc.]
[HKLM\Software\Avira]
[HKLM\Software\BrowserChoice]
[HKLM\Software\C07ft5Y]
[HKLM\Software\CA561B]
[HKLM\Software\Classes]
[HKLM\Software\Clients]
[HKLM\Software\Cyanide]
[HKLM\Software\DVDVideoSoft]
[HKLM\Software\Digital Now]
[HKLM\Software\EA SPORTS]
[HKLM\Software\GEAR Software]
[HKLM\Software\Gemplus]
[HKLM\Software\Google]
[HKLM\Software\HP]
[HKLM\Software\Hewlett-Packard]
[HKLM\Software\ICE]
[HKLM\Software\InstallShield]
[HKLM\Software\Intel]
[HKLM\Software\JavaSoft]
[HKLM\Software\JreMetrics]
[HKLM\Software\LogMeIn, Inc.]
[HKLM\Software\LogMeIn]
[HKLM\Software\LogiShrd]
[HKLM\Software\Logitech]
[HKLM\Software\Macromedia]
[HKLM\Software\MozillaPlugins]
[HKLM\Software\Mozilla]
[HKLM\Software\ODBC]
[HKLM\Software\OpenOffice.org]
[HKLM\Software\Policies]
[HKLM\Software\Program Groups]
[HKLM\Software\RegisteredApplications]
[HKLM\Software\Schlumberger]
[HKLM\Software\Secunia]
[HKLM\Software\Secure]
[HKLM\Software\Sun Microsystems]
[HKLM\Software\TENCENT]
[HKLM\Software\TrendMicro]
[HKLM\Software\Trymedia Systems]
[HKLM\Software\VideoLAN]
[HKLM\Software\Windows 3.1 Migration Status]
[HKLM\Software\Windows]
[HKLM\Software\X-AVCSD]
[HKLM\Software\Zone Labs]
[HKLM\Software\mozilla.org]
[HKLM\Software\perforce]
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar HyperPat » 30 Mai 2010 23:36

2ème partie

---\\ Contenu des dossiers Fichiers Communs (O43)
O43 - CFD:Common File Directory ----D- C:\Program Files\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files\Apple Software Update
O43 - CFD:Common File Directory ----D- C:\Program Files\Avira
O43 - CFD:Common File Directory ----D- C:\Program Files\ComPlus Applications
O43 - CFD:Common File Directory ----D- C:\Program Files\EA SPORTS
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers communs
O43 - CFD:Common File Directory ----D- C:\Program Files\Hewlett-Packard
O43 - CFD:Common File Directory ----D- C:\Program Files\HP
O43 - CFD:Common File Directory ----D- C:\Program Files\InstallShield Installation Information
O43 - CFD:Common File Directory ----D- C:\Program Files\Internet Explorer
O43 - CFD:Common File Directory ----D- C:\Program Files\iTunes
O43 - CFD:Common File Directory ----D- C:\Program Files\Java
O43 - CFD:Common File Directory ----D- C:\Program Files\JRE
O43 - CFD:Common File Directory ----D- C:\Program Files\LimeWire
O43 - CFD:Common File Directory ----D- C:\Program Files\Logitech
O43 - CFD:Common File Directory ----D- C:\Program Files\LogMeIn
O43 - CFD:Common File Directory ----D- C:\Program Files\Malwarebytes' Anti-Malware
O43 - CFD:Common File Directory ----D- C:\Program Files\Messenger
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft CAPICOM 2.1.0.2
O43 - CFD:Common File Directory ----D- C:\Program Files\microsoft frontpage
O43 - CFD:Common File Directory ----D- C:\Program Files\Microsoft Silverlight
O43 - CFD:Common File Directory ----D- C:\Program Files\Movie Maker
O43 - CFD:Common File Directory ----D- C:\Program Files\Mozilla Firefox
O43 - CFD:Common File Directory ----D- C:\Program Files\MSBuild
O43 - CFD:Common File Directory ----D- C:\Program Files\MSECACHE
O43 - CFD:Common File Directory ----D- C:\Program Files\msn
O43 - CFD:Common File Directory ----D- C:\Program Files\MSN Gaming Zone
O43 - CFD:Common File Directory ----D- C:\Program Files\MSXML 4.0
O43 - CFD:Common File Directory ----D- C:\Program Files\MSXML 6.0
O43 - CFD:Common File Directory ----D- C:\Program Files\NetMeeting
O43 - CFD:Common File Directory ----D- C:\Program Files\OpenOffice.org 3
O43 - CFD:Common File Directory ----D- C:\Program Files\Outlook Express
O43 - CFD:Common File Directory ----D- C:\Program Files\QuickTime
O43 - CFD:Common File Directory ----D- C:\Program Files\Reference Assemblies
O43 - CFD:Common File Directory ----D- C:\Program Files\Safari
O43 - CFD:Common File Directory ----D- C:\Program Files\Secunia
O43 - CFD:Common File Directory ----D- C:\Program Files\Services en ligne
O43 - CFD:Common File Directory ----D- C:\Program Files\Trend Micro
O43 - CFD:Common File Directory --H-D- C:\Program Files\Uninstall Information
O43 - CFD:Common File Directory ----D- C:\Program Files\VideoLAN
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Live
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Live SkyDrive
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Connect 2
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows Media Player
O43 - CFD:Common File Directory ----D- C:\Program Files\Windows NT
O43 - CFD:Common File Directory --H-D- C:\Program Files\WindowsUpdate
O43 - CFD:Common File Directory ----D- C:\Program Files\xerox
O43 - CFD:Common File Directory ----D- C:\Program Files\ZHPDiag
O43 - CFD:Common File Directory ----D- C:\Program Files\Zone Labs
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Adobe
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Adobe AIR
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Apple
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\DVDVideoSoft
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Hewlett-Packard
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\HP
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\InstallShield
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Java
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\logishrd
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Microsoft Shared
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\MSSoap
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\ODBC
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Services
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\SpeechEngines
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\System
O43 - CFD:Common File Directory ----D- C:\Program Files\Fichiers Communs\Windows Live


---\\ Derniers fichiers modifiés ou crées sous Windows et System32 (O44)
O44 - LFC:[MD5.00000000000000000000000000000000] - 30.05.2010 - 23:22:33 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WindowsUpdate.log [1408258]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 30.05.2010 - 23:21:02 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\0.log [0]
O44 - LFC:[MD5.00000000000000000000000000000000] - 30.05.2010 - 23:19:04 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiadebug.log [159]
O44 - LFC:[MD5.00000000000000000000000000000000] - 30.05.2010 - 23:19:03 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wiaservc.log [50]
O44 - LFC:[MD5.6A2CB42966136854F4464516FBB4AE72] - 30.05.2010 - 23:18:45 -S-A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\bootstat.dat [2048]
O44 - LFC:[MD5.00000000000000000000000000000000] - 30.05.2010 - 23:18:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SchedLgU.Txt [32578]
O44 - LFC:[MD5.7CFFB23F102DC485E7A4860ED577D797] - 30.05.2010 - 23:17:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB981332-IE8.log [16561]
O44 - LFC:[MD5.072008BB0143BF812A81B3284A2CADEE] - 30.05.2010 - 23:17:41 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\updspapi.log [381169]
O44 - LFC:[MD5.76B0511C9C9C401851B4FB30FC46B2B2] - 30.05.2010 - 23:17:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB976662-IE8.log [16396]
O44 - LFC:[MD5.3BDFC3FE80501AA1F75E7FC0068F49C5] - 30.05.2010 - 23:17:23 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB952069.log [69159]
O44 - LFC:[MD5.F02B3944A9A02ADA6F343A85E357D9D7] - 30.05.2010 - 23:17:19 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB968816.log [74851]
O44 - LFC:[MD5.F38BCF7B745CF940E0CA77B75D783B4C] - 30.05.2010 - 23:17:15 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB971961-IE8.log [17099]
O44 - LFC:[MD5.C1F6566651B8947817461C05390577B7] - 30.05.2010 - 23:17:08 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB956744.log [16448]
O44 - LFC:[MD5.0133254026195843A1F937E3B0205DD9] - 30.05.2010 - 23:16:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB951978.log [240266]
O44 - LFC:[MD5.897195DD317906A1958C66BDF812328F] - 30.05.2010 - 23:13:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wpa.dbl [13646]
O44 - LFC:[MD5.466FEF5E408AAE200EA856BF8368E2E3] - 30.05.2010 - 23:10:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB946648.log [49970]
O44 - LFC:[MD5.7060C75A5617A4CD696B9EDC8A126B89] - 30.05.2010 - 23:07:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\wmsetup.log [221529]
O44 - LFC:[MD5.B808E4EDBFE6022524A1B0F048133E95] - 30.05.2010 - 23:04:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfc009.dat [67312]
O44 - LFC:[MD5.2025FE38D1C7B38064F1E46A96C46F59] - 30.05.2010 - 23:04:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfc00C.dat [80508]
O44 - LFC:[MD5.9318FEB56697487A38DCDAAE43B3E8C3] - 30.05.2010 - 23:04:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfh009.dat [432356]
O44 - LFC:[MD5.A14C1455FF3A9C5C72A3D9FD3843209B] - 30.05.2010 - 23:04:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\perfh00C.dat [500482]
O44 - LFC:[MD5.DCA891CF393CA342394443E5E489E35F] - 30.05.2010 - 23:04:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\PerfStringBackup.INI [1094606]
O44 - LFC:[MD5.861A41CA15475C825646A8DAEBDF8230] - 30.05.2010 - 23:04:19 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB971737.log [27871]
O44 - LFC:[MD5.0AB2B31FB2EF4FDE6E6FF6E7F83B493D] - 30.05.2010 - 23:04:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\spupdsvc.log [241600]
O44 - LFC:[MD5.F19289D86568D0B5263001DC7B7D87D1] - 30.05.2010 - 23:03:50 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\DtcInstall.log [1284]
O44 - LFC:[MD5.DC17DD0189B0C36D863B4DD0A036C10F] - 30.05.2010 - 23:01:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WMSysPr9.prx [316640]
O44 - LFC:[MD5.8B8F4C7422869A2B14F2525ECC1EEAB3] - 30.05.2010 - 23:00:34 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\spupdsvc.log.1.log [517]
O44 - LFC:[MD5.1C5EA4F171A68BA067AB82FF9C618496] - 30.05.2010 - 23:00:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\spupdwxp.log [261]
O44 - LFC:[MD5.01A3D8BED15CA892B664B1DC52B0BD45] - 30.05.2010 - 23:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setuplog.txt [507683]
O44 - LFC:[MD5.B9F8E0F5372CA086B61AACF204307CE0] - 30.05.2010 - 22:59:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\FNTCACHE.DAT [123728]
O44 - LFC:[MD5.F06948C4805B23C0619A9C55779A5F77] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\comsetup.log [541261]
O44 - LFC:[MD5.18585BE8E63F73AF8197EC558D33F213] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\iis6.log [279592]
O44 - LFC:[MD5.2FF1450BE25A831DF3F410B14A45CB75] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\imsins.log [2675]
O44 - LFC:[MD5.C9885609A624BF354CD4D27778F1B678] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ntdtcsetup.log [327848]
O44 - LFC:[MD5.80D25C72F076E223CF444C94A68B6F2B] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ocmsn.log [84611]
O44 - LFC:[MD5.3CA4D86149FCF02FECC19832A0AC2397] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\svcpack.log [1409077]
O44 - LFC:[MD5.A200FCD1D5847EF1DADC61FA5BE49370] - 30.05.2010 - 22:57:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\tsoc.log [712710]
O44 - LFC:[MD5.4D65B627CA3307CDEFB3D6170F2A7F74] - 30.05.2010 - 22:57:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB980232.log [245749]
O44 - LFC:[MD5.F4340F3EF3EA43C5D13BACAA25B92117] - 30.05.2010 - 22:57:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\FaxSetup.log [1801631]
O44 - LFC:[MD5.7BEEE1FE03DCAB763B26DA9E60CDF825] - 30.05.2010 - 22:57:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\msgsocm.log [92711]
O44 - LFC:[MD5.A2DAB20F153B7E6F1E8839422B14389C] - 30.05.2010 - 22:57:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ocgen.log [945070]
O44 - LFC:[MD5.5243AFBE8B52421E1AA7872FEDEF1B57] - 30.05.2010 - 22:57:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupapi.log [735354]
O44 - LFC:[MD5.B82B758C9E80660537A77359A8613E8B] - 30.05.2010 - 22:57:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB980182.log [63009]
O44 - LFC:[MD5.7AF77C74718B1DD6BB393B3EE79339ED] - 30.05.2010 - 22:57:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB979683.log [251407]
O44 - LFC:[MD5.D9162DE9837ABAF279D1388B278D2A3A] - 30.05.2010 - 22:57:13 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB979309.log [268539]
O44 - LFC:[MD5.4453466F3BAC57415AE19A7A51F2D9E5] - 30.05.2010 - 22:57:07 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB978706.log [256864]
O44 - LFC:[MD5.F2A78FCD579159F2566476754AEF8C2A] - 30.05.2010 - 22:57:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB978601.log [264239]
O44 - LFC:[MD5.6B160A3385006EE800F856A39FBFBAAC] - 30.05.2010 - 22:56:53 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB978542.log [262729]
O44 - LFC:[MD5.8BD53423000961E5E6F7BA5C6DAE7674] - 30.05.2010 - 22:56:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB978338.log [264017]
O44 - LFC:[MD5.D768DAF5E23046248FD45FB242D076D3] - 30.05.2010 - 22:56:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB978037.log [257979]
O44 - LFC:[MD5.A0D2EE68C33B285C8215901BC0993772] - 30.05.2010 - 22:56:26 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB977914.log [260705]
O44 - LFC:[MD5.B3FE167CB7EB59709832246FDA79DCD6] - 30.05.2010 - 22:56:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB975713.log [259937]
O44 - LFC:[MD5.10FFB1DD15CDB46107708B43133BDEF7] - 30.05.2010 - 22:55:59 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB975561.log [239721]
O44 - LFC:[MD5.47246721962CE5B8A51889D7C33F3B44] - 30.05.2010 - 22:55:51 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB975560.log [258493]
O44 - LFC:[MD5.9BE66DCABA943626B0CA178D6BE1DAA2] - 30.05.2010 - 22:55:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB975467.log [255996]
O44 - LFC:[MD5.CD2988747BA28BAF696B83633936431C] - 30.05.2010 - 22:55:37 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB975025.log [250609]
O44 - LFC:[MD5.7F9A9FF619462BA83832EFF66D7AAF6C] - 30.05.2010 - 22:55:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB974571.log [252824]
O44 - LFC:[MD5.B869F2B1D19AA03458BBE0E2295BFF0C] - 30.05.2010 - 22:55:19 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB974392.log [257576]
O44 - LFC:[MD5.6FBBE1EF1A7CE7D469B6825ADB44ECE9] - 30.05.2010 - 22:55:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB974318.log [264493]
O44 - LFC:[MD5.E4137596FB2FD1F121DE3154BB8AED2F] - 30.05.2010 - 22:55:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB974112.log [251307]
O44 - LFC:[MD5.D9065B6B598F3040AFA4D6AE82B1754E] - 30.05.2010 - 22:54:52 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB973869.log [232918]
O44 - LFC:[MD5.731947E8546D30B4C89E481D6BD59F8B] - 30.05.2010 - 22:54:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB973815.log [249320]
O44 - LFC:[MD5.0FECA2D1AF243B64F36C87D891F8AB6C] - 30.05.2010 - 22:54:37 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB973687.log [431158]
O44 - LFC:[MD5.0D19A075084D38114A542DAC123948E9] - 30.05.2010 - 22:54:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB973507.log [250447]
O44 - LFC:[MD5.EA9439981AE0DCB4DB5597B0217805A0] - 30.05.2010 - 22:54:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB972270.log [238902]
O44 - LFC:[MD5.61F801D28CF27E29B6F1DB3FC6DF486F] - 30.05.2010 - 22:54:01 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB971657.log [250014]
O44 - LFC:[MD5.C5BE1EF4D82650E149AF8A0D60C4DAF3] - 30.05.2010 - 22:53:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB971468.log [241078]
O44 - LFC:[MD5.3A786449D5FBC3B924BFD4F6E15B275A] - 30.05.2010 - 22:53:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB970238.log [430506]
O44 - LFC:[MD5.78B905C685DA13C909089893C586706F] - 30.05.2010 - 22:53:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB969947.log [254257]
O44 - LFC:[MD5.EEBB125AC5F81DB3ECBEAE98F600D0C5] - 30.05.2010 - 22:53:23 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB969059.log [252525]
O44 - LFC:[MD5.B594FB5C5D8DED5AC37245DAE5DCF98E] - 30.05.2010 - 22:53:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB968389.log [286590]
O44 - LFC:[MD5.394655903596BC7DEE2442EBBCAF9A9D] - 30.05.2010 - 22:52:59 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB967715.log [444741]
O44 - LFC:[MD5.09BCFF33A6F9A9F7CDFD522CC71AF88E] - 30.05.2010 - 22:52:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB961503.log [248626]
O44 - LFC:[MD5.7E9BE9005E9A5A14F93E263B67F10380] - 30.05.2010 - 22:52:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB961501.log [454338]
O44 - LFC:[MD5.1255D5941D2138738079457813212378] - 30.05.2010 - 22:52:30 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB961118.log [219082]
O44 - LFC:[MD5.01CEDC693F5BBA7FB25CB7E1E13DFFAD] - 30.05.2010 - 22:52:18 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB960859.log [248669]
O44 - LFC:[MD5.6D5BFA05E5E8343E8485E73452C1F771] - 30.05.2010 - 22:52:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB960803.log [233621]
O44 - LFC:[MD5.CD8AF8DB2BFFF43A31AA1896F0129CDB] - 30.05.2010 - 22:52:03 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB960225.log [449526]
O44 - LFC:[MD5.BE4B1856F73C70001C3EF59EF2746D9D] - 30.05.2010 - 22:51:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB959426.log [462381]
O44 - LFC:[MD5.DA1908EE5AD1A88CD8DB799C4939DC40] - 30.05.2010 - 22:50:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB958644.log [222913]
O44 - LFC:[MD5.01023E0A6B4EDC3693DE21F284AA399B] - 30.05.2010 - 22:50:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB956844.log [261463]
O44 - LFC:[MD5.5499AD96CACB454D7DFE0A3CC26C954A] - 30.05.2010 - 22:49:55 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB956803.log [254758]
O44 - LFC:[MD5.43084D4085E25A600D82D3F2384C67C0] - 30.05.2010 - 22:49:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB956802.log [415768]
O44 - LFC:[MD5.E23784EDD26782C7CB253E94733B8431] - 30.05.2010 - 22:49:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB956572.log [274526]
O44 - LFC:[MD5.01FB495E1E7B5579CBDCDAE797D5F7E7] - 30.05.2010 - 22:49:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB955759.log [241120]
O44 - LFC:[MD5.40E86FD558E284E3EA9AE7F250DEEA11] - 30.05.2010 - 22:49:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB955069.log [221948]
O44 - LFC:[MD5.12CC56C88CA53FA443CCC16DDC0BAE71] - 30.05.2010 - 22:48:53 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB952954.log [442859]
O44 - LFC:[MD5.D08459F801B5B77D5ADEAF0703AE49EE] - 30.05.2010 - 22:48:43 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB952287.log [246353]
O44 - LFC:[MD5.78D085B26874442211428169A8EDDB85] - 30.05.2010 - 22:48:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB952004.log [455530]
O44 - LFC:[MD5.FD13D3F73DF841A3441D43752F0FCC9B] - 30.05.2010 - 22:48:26 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB951748.log [414321]
O44 - LFC:[MD5.69ECF27E9EE41BB245AB14F57C5C524C] - 30.05.2010 - 22:48:13 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB950974.log [443775]
O44 - LFC:[MD5.96A177B17764485831DDEBE0DF9484CB] - 30.05.2010 - 22:48:06 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB950762.log [242816]
O44 - LFC:[MD5.9CA704DACFAA5A08C2D746E128C4C1D9] - 30.05.2010 - 22:47:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB923561.log [226655]
O44 - LFC:[MD5.8A9BAAB1816698BBD8E3C9CBA1DAA7D9] - 30.05.2010 - 22:46:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\cmsetacl.log [719]
O44 - LFC:[MD5.7763BFB5B67A184F7E0216B65E6DBA50] - 30.05.2010 - 22:46:18 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\sessmgr.setup.log [4210]
O44 - LFC:[MD5.7794C3221F670DE270586A2CF6E68383] - 30.05.2010 - 22:36:50 RSHA- . (.Pas de propriétaire - Pas de description.) -- C:\ntldr [252240]
O44 - LFC:[MD5.DAA451D92B7010E0990DC623BE4E2A25] - 30.05.2010 - 22:24:19 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\lvcoinst.log [12175]
O44 - LFC:[MD5.C2238E326159DA9006978311BE9A010D] - 30.05.2010 - 22:17:07 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ie8_main.log [236556]
O44 - LFC:[MD5.F03FF6615D89EA811866A6E2394C22CB] - 30.05.2010 - 22:16:57 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB982632-IE8.log [32356]
O44 - LFC:[MD5.A9943C830AD32DBD0ADE87B99C2256B1] - 30.05.2010 - 22:16:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB980182-IE8.log [58946]
O44 - LFC:[MD5.703C30B257906D716ADE8180194481F0] - 30.05.2010 - 22:15:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ie8.log [86875]
O44 - LFC:[MD5.D41D8CD98F00B204E9800998ECF8427E] - 30.05.2010 - 22:10:08 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\nsreg.dat [0]
O44 - LFC:[MD5.8737F6F4C8EC1E2A9EA5516F1B3AE1AD] - 30.05.2010 - 21:59:10 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\005907_.tmp [19569]
O44 - LFC:[MD5.07AE3FF35A96BCFE253E241B4E122990] - 30.05.2010 - 20:51:15 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\hpoins27.dat [177706]
O44 - LFC:[MD5.5A10617C493B51F18C8D271B9E6343C9] - 30.05.2010 - 20:47:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB981793.log [41286]
O44 - LFC:[MD5.85B02AD38BD055DBBE76353C150D694E] - 30.05.2010 - 20:46:59 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\TZLog.log [223278]
O44 - LFC:[MD5.05801D63D4A47C599542774D8BBDD5F7] - 30.05.2010 - 20:45:59 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB981350.log [55558]
O44 - LFC:[MD5.DFA5AC489B6544BF763D20E9641027C0] - 30.05.2010 - 20:45:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB977816.log [67500]
O44 - LFC:[MD5.EB2CF3867217AB0C6175DE4AD1D996F5] - 30.05.2010 - 20:44:06 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB973904.log [47189]
O44 - LFC:[MD5.5F3B67EBBB86CD85AE119FCA6FE35D67] - 30.05.2010 - 20:43:24 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\msxml6-KB973686-fra-x86.LOG [390216]
O44 - LFC:[MD5.3DFED9927612445FAD85225968ECD700] - 30.05.2010 - 20:42:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB958869.log [35626]
O44 - LFC:[MD5.8F509F538D1B50C033334953F78F4F4C] - 30.05.2010 - 20:42:07 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB971961.log [32611]
O44 - LFC:[MD5.116BF1DD0ED13C54E9D24DAC389C6B91] - 30.05.2010 - 20:41:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB932823-v3.log [73260]
O44 - LFC:[MD5.90609CF5C9AE42590BE39E203D128C67] - 30.05.2010 - 20:40:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB958470.log [38353]
O44 - LFC:[MD5.314BBB7E41DC4CC4F65247C85F5241C6] - 30.05.2010 - 20:36:55 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB944338-v2.log [23806]
O44 - LFC:[MD5.831C15B2E226BD84690A7A985B610E46] - 30.05.2010 - 20:36:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB925720.log [19856]
O44 - LFC:[MD5.066DC8DF17FBE6AB5EC5CB1C15B07466] - 30.05.2010 - 19:52:04 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB873333.log [36541]
O44 - LFC:[MD5.453EF87D35BF2786ADDB1329362AE92F] - 30.05.2010 - 19:51:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB904706.log [33457]
O44 - LFC:[MD5.B61E803ED86D499C3D503E79A5578DFC] - 30.05.2010 - 19:31:01 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB899587.log [59892]
O44 - LFC:[MD5.03B6E033D8969AF9F51C9B8F464CFF7E] - 30.05.2010 - 19:30:55 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB924191.log [58214]
O44 - LFC:[MD5.D6FD8CD724A4887DF4012F076F5B2531] - 30.05.2010 - 19:30:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB922819.log [58362]
O44 - LFC:[MD5.D35D4798EDB8AA8C68D9B7D60212433E] - 30.05.2010 - 19:30:40 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB885835.log [55574]
O44 - LFC:[MD5.341B3418621FF9E57F207EA6498C35EB] - 30.05.2010 - 19:30:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB885836.log [53729]
O44 - LFC:[MD5.5EE31F569A6B45EE1923600500A5E1EC] - 30.05.2010 - 19:30:23 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB923414.log [55544]
O44 - LFC:[MD5.73484C24EC0A8ED0A95F44FBF3D2F630] - 30.05.2010 - 19:30:17 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB921883.log [55513]
O44 - LFC:[MD5.895A101FB02D450A07A672E4273FE359] - 30.05.2010 - 19:30:08 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB911927.log [54682]
O44 - LFC:[MD5.E440897283AFEA8F122ACA093B563472] - 30.05.2010 - 19:29:04 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB922616.log [52884]
O44 - LFC:[MD5.4753EDC4D47FE77FE12B95B5D0C1FDE1] - 30.05.2010 - 19:28:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB901017.log [53579]
O44 - LFC:[MD5.8CAAE6D43FBB924031D8325DCDB254CD] - 30.05.2010 - 19:28:26 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB899591.log [54177]
O44 - LFC:[MD5.EF8E07AABEC5F07BDE0C31C80BC40819] - 30.05.2010 - 19:28:13 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB920685.log [53521]
O44 - LFC:[MD5.728072155D040CC4E5539272E15AAA94] - 30.05.2010 - 19:27:58 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB896424.log [53853]
O44 - LFC:[MD5.304DBDE37F37176D79A533BFC52C3F86] - 30.05.2010 - 19:27:51 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB893756.log [53082]
O44 - LFC:[MD5.7327628631C3182B9BF2692237FED2F7] - 30.05.2010 - 19:27:45 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB911280.log [52244]
O44 - LFC:[MD5.B0CBB4A4876788DB5C064E4DD8D78D04] - 30.05.2010 - 19:27:38 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB911562.log [53428]
O44 - LFC:[MD5.22AF625D039BE75870744290CACDAD6F] - 30.05.2010 - 19:27:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB896423.log [52080]
O44 - LFC:[MD5.6C291099AE7D5BA76CDE684524E05EB2] - 30.05.2010 - 19:27:19 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB873339.log [48644]
O44 - LFC:[MD5.EA202D43623548AEF409871CB0B9183F] - 30.05.2010 - 19:27:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB924496.log [50393]
O44 - LFC:[MD5.8F5BF42679E010C71208A02B6EC0C5F0] - 30.05.2010 - 19:27:05 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB921398.log [50643]
O44 - LFC:[MD5.8D07E0844E6AE14DD14CF7857F69D9D0] - 30.05.2010 - 19:26:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB896358.log [49362]
O44 - LFC:[MD5.087948549BDC3B4981519D7067AE8F86] - 30.05.2010 - 19:26:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB910437.log [38093]
O44 - LFC:[MD5.6BD04ACBFD87A92E887C8C96C3E8FB8E] - 30.05.2010 - 19:26:35 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB911564.log [29720]
O44 - LFC:[MD5.7455BD2D51FB89B70F154524CDA925F8] - 30.05.2010 - 19:26:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB920670.log [47592]
O44 - LFC:[MD5.0C42C3B491148A0A082BD10B7D21E487] - 30.05.2010 - 19:26:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB891781.log [46543]
O44 - LFC:[MD5.FB32F64A115B0F7318D803187FBED447] - 30.05.2010 - 19:25:51 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB890046.log [48354]
O44 - LFC:[MD5.A31AD5DB3AB8996DBFC81F12CFBC89DC] - 30.05.2010 - 19:25:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB919007.log [47288]
O44 - LFC:[MD5.E6CA11C09768E28337E099F7B23964B2] - 30.05.2010 - 19:25:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB914388.log [48271]
O44 - LFC:[MD5.FE36596D67CEB4E151E8A9BC0769E708] - 30.05.2010 - 19:25:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB917344.log [45692]
O44 - LFC:[MD5.F67399AA132F289EF51EF7191A553201] - 30.05.2010 - 19:24:01 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB905414.log [45691]
O44 - LFC:[MD5.FB7A812331D4DA0713522F785172272D] - 30.05.2010 - 19:23:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB917953.log [44123]
O44 - LFC:[MD5.9DCF2BC541E53345C89F62C1A4621486] - 30.05.2010 - 19:23:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Control Panel.) -- C:\WINDOWS\System32\javacpl.cpl [73728]
O44 - LFC:[MD5.43F7CA0473BB0FC9DD44ECF328B8D1FA] - 30.05.2010 - 19:23:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\WINDOWS\System32\java.exe [145184]
O44 - LFC:[MD5.4E8CC8BDEBED5AD93539612D4D316FDF] - 30.05.2010 - 19:23:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\WINDOWS\System32\javaw.exe [145184]
O44 - LFC:[MD5.9D452D6B1ED99F88C327349A644EB3A2] - 30.05.2010 - 19:23:27 ---A- . (.Sun Microsystems, Inc. - Java(TM) Web Start Launcher.) -- C:\WINDOWS\System32\javaws.exe [153376]
O44 - LFC:[MD5.B8F7C6CA5F8E97249853DBE1DADD1FBC] - 30.05.2010 - 19:23:26 ---A- . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\WINDOWS\System32\deployJava1.dll [411368]
O44 - LFC:[MD5.8C3B99AB6EAC23B190F24ACB68611795] - 30.05.2010 - 19:23:25 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB901214.log [43908]
O44 - LFC:[MD5.12C8DD41F2FB5F2F5259E230DACA25CE] - 30.05.2010 - 19:23:07 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB923191.log [37948]
O44 - LFC:[MD5.CFF7C1F7CEB90C81DE0DE068EEB752BD] - 30.05.2010 - 19:22:54 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB917422.log [42284]
O44 - LFC:[MD5.E8CDE9978F3D560DACDCD5671A03F2D8] - 30.05.2010 - 19:22:42 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB888302.log [40339]
O44 - LFC:[MD5.085547CB26D21080942BAF30D5F5EFD6] - 30.05.2010 - 19:22:29 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB900725.log [43625]
O44 - LFC:[MD5.2B6CFC8059D1D7D124E9ADC3AFF347BB] - 30.05.2010 - 19:22:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB912919.log [39224]
O44 - LFC:[MD5.4A89963642D836F7A7F58231A51AF215] - 30.05.2010 - 19:21:32 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB908531.log [38255]
O44 - LFC:[MD5.F4480F81202DED8DDE5F0E8080F54042] - 30.05.2010 - 19:19:48 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB905749.log [37615]
O44 - LFC:[MD5.01D53F01B7CAFF3626BEEA0C38B4738D] - 30.05.2010 - 19:19:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB913580.log [36610]
O44 - LFC:[MD5.088249A5A27DF0D60E0E341BEA8C7AA0] - 30.05.2010 - 19:19:15 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB896428.log [33091]
O44 - LFC:[MD5.A7E57879A1D2F69CAF8F435C7E197CB4] - 30.05.2010 - 19:18:59 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB908519.log [33328]
O44 - LFC:[MD5.5BA052D9D7E0557138C4AF3395F5ED36] - 30.05.2010 - 19:18:47 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB920683.log [33972]
O44 - LFC:[MD5.100B4B5BAF14B8235DA0BA0613F4072C] - 30.05.2010 - 19:18:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB914389.log [32900]
O44 - LFC:[MD5.2E333A5898555A20AA00948C489E8EC4] - 30.05.2010 - 19:17:29 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB890859.log [35416]
O44 - LFC:[MD5.02529017D85F2DC50EEA5F1E61B1A9FC] - 30.05.2010 - 19:07:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\svcpack.log.1.log [445718]
O44 - LFC:[MD5.2DD45D0879992D420BB2F86E5B72AE5F] - 30.05.2010 - 19:03:46 RSHA- . (.Pas de propriétaire - Pas de description.) -- C:\boot.ini [216]
O44 - LFC:[MD5.B2DE3452DE03674C6CEC68B8C8CE7C78] - 30.05.2010 - 18:56:05 RSHA- . (.Pas de propriétaire - Pas de description.) -- C:\NTDETECT.COM [47564]
O44 - LFC:[MD5.10CB8898E46050E2F10F09C6085FBE2F] - 30.05.2010 - 18:30:10 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\ZHPExportRegistry-30.05.2010-19-30-10.txt [11870]
O44 - LFC:[MD5.D16E158B285BA79D465DC8271AC02229] - 30.05.2010 - 18:20:47 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ieuinit.inf [57667]
O44 - LFC:[MD5.9BDC5FD356118998526F51EF4A1CF6DD] - 30.05.2010 - 17:59:27 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB905495.log [9098]
O44 - LFC:[MD5.9C756739FC07D71F8F12A610CE994CA1] - 30.05.2010 - 17:59:23 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB902400.log [8894]
O44 - LFC:[MD5.0024264871C86768F596B9C1E0F355FA] - 30.05.2010 - 17:58:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB835409.log [6848]
O44 - LFC:[MD5.05D6CF39C146DE75D22C05A85887E07A] - 30.05.2010 - 17:52:28 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB893803v2.log [18705]
O44 - LFC:[MD5.2CB947A487EE6D627C687D716B3FEA89] - 30.05.2010 - 17:50:44 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\KB842773.log [15575]
O44 - LFC:[MD5.604A7A0BD649A5AEC8E92638C78CF32B] - 30.05.2010 - 17:50:31 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupact.log [318138]
O44 - LFC:[MD5.E423A6A5184A2D30E689A89CE4332E4C] - 30.05.2010 - 17:30:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\drivers\WudfPf.sys [77568]
O44 - LFC:[MD5.02CE4E628D51F71DAFC71151DE4DB4C4] - 30.05.2010 - 17:30:33 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\COM+.log [3072]
O44 - LFC:[MD5.C39CDD9D675043A59F72A966188662AC] - 30.05.2010 - 17:30:15 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\TDSSKiller.2.3.1.0_30.05.2010_18.29.28_log.txt [37528]
O44 - LFC:[MD5.E2605C3264FD7DF4839E5795ACD08FAD] - 30.05.2010 - 17:18:39 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\DirectX.log [369334]
O44 - LFC:[MD5.8255FE8ABF1C35497F5A9FBDBBF99D27] - 30.05.2010 - 17:15:49 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\$winnt$.inf [288]
O44 - LFC:[MD5.A3CCB3485B71C8F7AD06E4B82755DF50] - 30.05.2010 - 17:12:13 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\amcompat.tlb [16832]
O44 - LFC:[MD5.89293A243DEB6DC3CCFCE54C0F00D87D] - 30.05.2010 - 17:12:13 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\nscompat.tlb [23392]
O44 - LFC:[MD5.F9F53D8752A1AD1991B897A44B10106D] - 30.05.2010 - 17:12:13 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wmpscheme.xml [25065]
O44 - LFC:[MD5.94940A5C4D5219EE0F4F9D5355C6C1E8] - 30.05.2010 - 17:12:11 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WMSysPrx.prx [299552]
O44 - LFC:[MD5.4273F40767E119C4D175D48355892FEC] - 30.05.2010 - 17:12:07 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\OEWABLog.txt [2343]
O44 - LFC:[MD5.E4CF20EB892520497CF7F8BBAFC032BC] - 30.05.2010 - 17:12:02 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ODBCINST.INI [4207]
O44 - LFC:[MD5.2C8D496BE02B2F75245994C85A3C8B1C] - 30.05.2010 - 17:11:20 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\Windows Update.log [836]
O44 - LFC:[MD5.5D76C3FB736514E1D7C88791E7322784] - 30.05.2010 - 17:10:52 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\WindowsLogon.manifest [488]
O44 - LFC:[MD5.5D76C3FB736514E1D7C88791E7322784] - 30.05.2010 - 17:10:52 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\logonui.exe.manifest [488]
O44 - LFC:[MD5.2009435046784387CE547966D7865F31] - 30.05.2010 - 17:10:45 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setuperr.log [1055]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 30.05.2010 - 17:10:45 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\cdplayer.exe.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 30.05.2010 - 17:10:45 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ncpa.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 30.05.2010 - 17:10:45 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\nwc.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 30.05.2010 - 17:10:45 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\sapi.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 30.05.2010 - 17:10:45 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\wuaucpl.cpl.manifest [749]
O44 - LFC:[MD5.5A5CFF37F1BD0F86B9BDAAD7A9445882] - 30.05.2010 - 17:10:45 R-HA- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\WindowsShell.Manifest [749]
O44 - LFC:[MD5.33C3013F2376FA839EEC112FAE3DA9FB] - 30.05.2010 - 17:10:37 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\win.ini [596]
O44 - LFC:[MD5.6070F2247E564CD5AE61B259F7825423] - 30.05.2010 - 17:10:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\emptyregdb.dat [23056]
O44 - LFC:[MD5.9A125451933DD183893AD276C4CA1952] - 30.05.2010 - 17:05:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\regopt.log [6470]
O44 - LFC:[MD5.A0E02492452D4E237465D99D005D91FD] - 30.05.2010 - 17:05:36 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system.ini [231]
O44 - LFC:[MD5.FA511331A48B582A7D584FC2408E8C1A] - 30.05.2010 - 17:05:31 ---A- . (.Perle Systems Ltd. - Specialix MPS NT Upgrade CoInstaller.) -- C:\WINDOWS\System32\spxcoins.dll [24661]
O44 - LFC:[MD5.E9D9927EF032BECA97C42B0F03E191A0] - 30.05.2010 - 17:05:17 R--A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SET42.tmp [13923]
O44 - LFC:[MD5.87D7EBA2D823656EEB29FE6938932298] - 30.05.2010 - 17:05:15 R--A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\SET36.tmp [1086182]
O44 - LFC:[MD5.14E6FB92F1788982E2BBC81D915B1F02] - 28.05.2010 - 12:04:52 ---A- . (.Secunia - Secunia PSI Driver.) -- C:\WINDOWS\System32\drivers\psi_mf.sys [14896]
O44 - LFC:[MD5.DEB3697D0C1BAD7556450491F403B26C] - 27.05.2010 - 18:30:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\setupapi.old [479287]
O44 - LFC:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 25.05.2010 - 22:04:43 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [38224]
O44 - LFC:[MD5.A1CD8EEC777F05DE505B76BB96709498] - 25.05.2010 - 22:04:41 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\System32\drivers\mbam.sys [19288]
O44 - LFC:[MD5.71ECBA795A063026843F70F31EF02689] - 25.05.2010 - 19:54:09 ---A- . (.Intel Corporation - ISR Debug 32-bit Engine.) -- C:\WINDOWS\System32\isrdbg32.dll [32768]
O44 - LFC:[MD5.6A1D9675F87094A7FAB33A67A4C25F1C] - 25.05.2010 - 19:52:41 ---A- . (.Hilgraeve, Inc. - Bibliothèque d'applications HyperTerminal.) -- C:\WINDOWS\System32\hypertrm.dll [354304]
O44 - LFC:[MD5.3FBB6EF8B5A71A2FA11F5F461BB73219] - 25.05.2010 - 19:48:31 ---A- . (.SiS Corporation - SiS PCI Fast Ethernet Adapter Driver.) -- C:\WINDOWS\System32\drivers\sisnic.sys [32768]
O44 - LFC:[MD5.71973E4F8CA4164825A95C1C02B190D1] - 25.05.2010 - 19:31:46 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\ntbtlog.txt [68696]
O44 - LFC:[MD5.2A6C516CB474B2D667AD059E909D9CE6] - 21.05.2010 - 18:36:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\c5d712a [20]


---\\ Opérations et fonctions au démarrage de Windows Explorer (O46)
O46 - SEH:ShellExecuteHooks - URL Exec Hook - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - shell32.dll
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar HyperPat » 30 Mai 2010 23:37

3ème partie

---\\ Export de clé d'application autorisée (ECAA) (O47)
O47 - AAKE:Key Export SP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export SP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Cyanide\GameCenter\GameCenter.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Cyanide\GameCenter\GameCenter.exe
O47 - AAKE:Key Export SP - "C:\Program Files\LimeWire\LimeWire.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\LimeWire\LimeWire.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Skype\Plugin Manager\skypePM.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) (.not file.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\PCM.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\PCM.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\Autorun\Exe\Autorun.exe" [Enabled] .(.Pas de propriétaire - .) (.not file.) -- C:\Program Files\Cyanide\Pro Cycling Manager - Season 2009\Autorun\exe\Autorun.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" [Enabled] .(.Hewlett-Packard Co. - NewCopy Application.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - hpqsudi.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential Software.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" [Enabled] .(.Hewlett-Packard Co. - HP Guided Solutions.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" [Enabled] .(.Hewlett-Packard - GPCore COM object.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\HP Software Update\hpwucli.exe" [Enabled] .(.Hewlett-Packard - HP Software Update Client.) (.not file.) -- C:\Program Files\HP\HP Software Update\hpwucli.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" [Enabled] .(.Hewlett-Packard Co. - .) (.not file.) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintexe.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Team17\Worms 2\Frontend.exe" [Disabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\Program Files\Team17\Worms 2\Frontend.exe
O47 - AAKE:Key Export SP - "C:\WINDOWS\explorer.exe" [Enabled] .(.Microsoft Corporation - Explorateur Windows.) (.not file.) -- C:\WINDOWS\explorer.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" [Enabled] .(.Hewlett-Packard Co. - HP Digital Imaging Monitor.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" [Enabled] .(.Hewlett-Packard Co. - HP CUE Status Root.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" [Enabled] .(.Hewlett-Packard Co. - HP All-in-One Launcher Utility.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" [Enabled] .(.Hewlett-Packard - MFC HP Scan Application.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
O47 - AAKE:Key Export SP - "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" [Enabled] .(.Hewlett-Packard - HP CUE-Scanning Flow Component.) (.not file.) -- C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
O47 - AAKE:Key Export SP - "C:\Program Files\Logitech\Logitech Vid\Vid.exe" [Enabled] .(.Logitech Inc. - Logitech Vid.) (.not file.) -- C:\Program Files\Logitech\Logitech Vid\Vid.exe
O47 - AAKE:Key Export DP - "%windir%\system32\sessmgr.exe" [Enabled] .(.Microsoft Corporation - Gestionnaire de session de l'aide sur le Bureau à distance de Microsoft®.) -- C:\WINDOWS\system32\sessmgr.exe
O47 - AAKE:Key Export DP - "%windir%\Network Diagnostic\xpnetdiag.exe" [Enabled] .(.Microsoft Corporation - Network Diagnostic for Windows XP.) -- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" [Enabled] .(.Microsoft Corporation - Windows Live Call.) -- C:\Program Files\Windows Live\Messenger\wlcsdk.exe
O47 - AAKE:Key Export DP - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [Enabled] .(.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" [Enabled] .(.Hewlett-Packard Co. - HP CUE Status Root.) -- C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" [Enabled] .(.Hewlett-Packard Co. - HP All-in-One Launcher Utility.) -- C:\Program Files\HP\Digital Imaging\bin\hposid01.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" [Enabled] .(.Hewlett-Packard - HP CUE-Scanning Flow Component.) -- C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe" [Enabled] .(.Hewlett-Packard Co. - NewCopy Application.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcopy2.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe" [Enabled] .(.Hewlett-Packard - MFC HP Scan Application.) -- C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - hpqsudi.) -- C:\Program Files\HP\Digital Imaging\bin\hpqsudi.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe" [Enabled] .(.Hewlett-Packard Development Co. L.P. - HP Photosmart Essential Software.) -- C:\Program Files\HP\Digital Imaging\bin\hpqpse.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe" [Enabled] .(.Hewlett-Packard Co. - HP Guided Solutions.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgplgtupl.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe" [Enabled] .(.Hewlett-Packard - GPCore COM object.) -- C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgm.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe" [Enabled] .(.Hewlett-Packard Co. - HP Customer Participation Program.) -- C:\Program Files\HP\Digital Imaging\bin\hpqusgh.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\HP Software Update\hpwucli.exe" [Enabled] .(.Hewlett-Packard - HP Software Update Client.) -- C:\Program Files\HP\HP Software Update\hpwucli.exe
O47 - AAKE:Key Export DP - "C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintExe.exe" [Enabled] .(.Hewlett-Packard Co. - .) -- C:\Program Files\HP\Digital Imaging\Smart Web Printing\SmartWebPrintexe.exe
O47 - AAKE:Key Export DP - "C:\WINDOWS\explorer.exe" [Enabled] .(.Microsoft Corporation - Explorateur Windows.) -- C:\WINDOWS\explorer.exe


---\\ Image File Execution Options (IFEO) (O50)
O50 - IFEO:Image File Execution Options - Your Image File Name Here without a path - ntsd -d


---\\ Trojan Driver Search Data (HKLM)(TDSD) (O52)
O52 - TDSD: \Drivers32\"msacm.trspch"="tssoft32.acm" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
O52 - TDSD: \Drivers32\"vidc.cvid"="iccvid.dll" . (.Radius Inc. - Cinepak® Codec.) -- C:\WINDOWS\System32\iccvid.dll
O52 - TDSD: \Drivers32\"vidc.iv31"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"vidc.iv32"="ir32_32.dll" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \Drivers32\"msacm.sl_anet"="sl_anet.acm" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
O52 - TDSD: \Drivers32\"msacm.l3acm"="C:\WINDOWS\System32\l3codeca.acm" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"sl_anet.acm"="Sipro Lab Telecom Audio Codec" . (.Sipro Lab Telecom Inc. - Audio codec for MS ACM.) -- C:\WINDOWS\System32\sl_anet.acm
O52 - TDSD: \drivers.desc\"C:\WINDOWS\System32\l3codeca.acm"="Fraunhofer IIS MPEG Layer-3 Codec" . (.Fraunhofer Institut Integrierte Schaltungen - MPEG Layer-3 Audio Codec for MSACM.) -- C:\WINDOWS\System32\l3codeca.acm
O52 - TDSD: \drivers.desc\"msg711.acm"="Microsoft CCITT G.711 Audio CODEC" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"msgsm32.acm"="Microsoft GSM 6.10 Audio CODEC" . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"tssoft32.acm"="DSP Group TrueSpeech(TM) Audio CODEC" . (.DSP GROUP, INC. - Codec audio TrueSpeech(TM) DSP Group pour MSACM V3.50.) -- C:\WINDOWS\System32\tssoft32.acm
O52 - TDSD: \drivers.desc\"iccvid.dll"="Cinepak Codec by Radius Inc." . (.Pas de propriétaire - Pas de description.) -- (.not file.)
O52 - TDSD: \drivers.desc\"ir32_32.dll"="Indeo codec by Intel" . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\System32\ir32_32.dll
O52 - TDSD: \drivers.desc\"lvcodec2.dll"="lvcodec2.dll" . (.Logitech Inc. - Video Codec.) -- C:\WINDOWS\System32\lvcodec2.dll


---\\ Microsoft Control Security Providers (MCSP) (O54)
O54 - MCSP:[HKLM\...\CurrentControlSet\Control] - "SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
O54 - MCSP:[HKLM\...\ControlSet001\Control] - "SecurityProviders"=msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


---\\ Microsoft Windows Policies System (MWPS) (O55)
O55 - MWPS:[HKLM\...\Policies\System] - "dontdisplaylastusername"=0
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticecaption"=
O55 - MWPS:[HKLM\...\Policies\System] - "legalnoticetext"=
O55 - MWPS:[HKLM\...\Policies\System] - "shutdownwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "undockwithoutlogon"=1
O55 - MWPS:[HKLM\...\Policies\System] - "EnableLUA"=0
O55 - MWPS:[HKCU\...\Policies\System] - "DisableTaskMgr"=0


---\\ Microsoft Windows Policies Explorer (MWPE) (O56)
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoDriveTypeAutoRun"=145
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoActiveDesktopChanges"=1
O56 - MWPE:[HKCU\...\Policies\Explorer] - "NoSetActiveDesktop"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "HonorAutoRunSetting"=1
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoActiveDesktopChanges"=0
O56 - MWPE:[HKLM\...\Policies\Explorer] - "NoSetActiveDesktop"=0


---\\ Liste des Drivers Système (SDL) (O58)
O58 - SDL:[MD5.D3BA744433F14E5C77107D9D82297801] - 17.08.2001 - 20:20:16 ---A- . (.Silicon Integrated Systems Corp. - SiS 7018 Audio Device WDM Driver.) -- C:\WINDOWS\system32\drivers\ac97sis.sys
O58 - SDL:[MD5.95B4FB835E28AA1336CEEB07FD5B9398] - 13.04.2008 - 19:36:39 ---A- . (.Advanced Micro Devices, Inc. - AMD Win2000 AGP Filter.) -- C:\WINDOWS\system32\drivers\amdagp.sys
O58 - SDL:[MD5.A2F791E99FD6EECEBCCFB1953A1D6F24] - 20.08.2004 - 23:53:38 ---A- . (.ATI Technologies Inc. - Pilote de miniport ATI RAGE 128.) -- C:\WINDOWS\system32\drivers\ati2mtaa.sys
O58 - SDL:[MD5.417352592432F5368A8296F7FB73BECF] - 20.08.2004 - 23:53:40 ---A- . (.ATI Technologies Inc. - Pilote de miniport ATI RAGE 128.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys
O58 - SDL:[MD5.993E7BD6438FE989E328C6B4BCA246A9] - 04.08.2004 - 06:29:27 ---A- . (.ATI Technologies Inc. - ATI WDM BT829 MiniDriver (A).) -- C:\WINDOWS\system32\drivers\atinbtxx.sys
O58 - SDL:[MD5.ED4C2BF8403F4437987C0BA09CF48716] - 04.08.2004 - 06:29:28 ---A- . (.ATI Technologies Inc. - ATI Specialized MVD VBI Codec RT2.) -- C:\WINDOWS\system32\drivers\atinmdxx.sys
O58 - SDL:[MD5.E90AC2B14E98F1A4372E5891B4278784] - 04.08.2004 - 06:29:29 ---A- . (.ATI Technologies Inc. - ATI Specialized PCD VBI Codec RT2.) -- C:\WINDOWS\system32\drivers\atinpdxx.sys
O58 - SDL:[MD5.DA36687D701C833430605A298731410B] - 04.08.2004 - 06:29:29 ---A- . (.ATI Technologies Inc. - ATI Rage Theater Audio WDM Minidriver.) -- C:\WINDOWS\system32\drivers\atinraxx.sys
O58 - SDL:[MD5.A7A01B907DB63898D40B0A14248FF9A2] - 04.08.2004 - 06:29:30 ---A- . (.ATI Technologies Inc. - ATI WDM Rage Theater MiniDriver RT2.) -- C:\WINDOWS\system32\drivers\atinrvxx.sys
O58 - SDL:[MD5.CEDDEE2E0591894D19654D458FD3B9BE] - 04.08.2004 - 06:29:30 ---A- . (.ATI Technologies Inc. - ATI WDM TV Sound MiniDriver.) -- C:\WINDOWS\system32\drivers\atinsnxx.sys
O58 - SDL:[MD5.D80A8F6C0A717446496C3A06D33B0D9C] - 04.08.2004 - 06:29:30 ---A- . (.ATI Technologies Inc. - ATI WDM Teletext Decoder.) -- C:\WINDOWS\system32\drivers\atinttxx.sys
O58 - SDL:[MD5.EDD66332608D27F4FD5069BCD0BC5164] - 04.08.2004 - 06:29:31 ---A- . (.ATI Technologies Inc. - ATI WDM TVTuner MiniDriver.) -- C:\WINDOWS\system32\drivers\atintuxx.sys
O58 - SDL:[MD5.3E7D485CBD0B0D9F6EA2AD9442411831] - 04.08.2004 - 06:29:31 ---A- . (.ATI Technologies Inc. - ATI WDM CrossBar MiniDriver.) -- C:\WINDOWS\system32\drivers\atinxbxx.sys
O58 - SDL:[MD5.77B575D7AAB35D5908AE6CE681608D62] - 04.08.2004 - 06:29:31 ---A- . (.ATI Technologies Inc. - ATI WDM TVAUDIO_CrossBar MiniDriver RT2.) -- C:\WINDOWS\system32\drivers\atinxsxx.sys
O58 - SDL:[MD5.5B44C214F9CD9F590BE9125347610380] - 13.02.2009 - 11:17:49 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver.) -- C:\WINDOWS\system32\drivers\avgntdd.sys
O58 - SDL:[MD5.2DAA8CC2670720DEDDCC74A20EDE2EE9] - 13.02.2009 - 11:28:39 ---A- . (.Avira GmbH - Avira AntiVir File Filter Driver Manager.) -- C:\WINDOWS\system32\drivers\avgntmgr.sys
O58 - SDL:[MD5.AD9BD66A862116E79CB45BB6BE46055F] - 30.03.2009 - 09:32:47 ---A- . (.Avira GmbH - Avira Driver for RootKit Detection.) -- C:\WINDOWS\system32\drivers\avipbb.sys
O58 - SDL:[MD5.C9B25AE9B8ABD983C5AD3F8CBFAB0F9C] - 24.04.2003 - 13:00:00 ---A- . (.RAVISENT Technologies Inc. - Pilote principal CineMaster C 1.2 WDM.) -- C:\WINDOWS\system32\drivers\cinemst2.sys
O58 - SDL:[MD5.9624293E55AD405415862B504CA95B73] - 24.04.2003 - 13:00:00 ---A- . (.Compaq Computer Corporation - Compaq PA-1 Player Driver.) -- C:\WINDOWS\system32\drivers\cpqdap01.sys
O58 - SDL:[MD5.D03D10F7DED688FECF50F8FBF1EA9B8A] - 30.10.2007 - 10:25:53 R--A- . (.HP - IEEE-1284.4-1999 Driver (Windows 2000).) -- C:\WINDOWS\system32\drivers\HPZid412.sys
O58 - SDL:[MD5.89F41658929393487B6B7D13C8528CE3] - 30.10.2007 - 10:25:54 R--A- . (.HP - IEEE-1284.4-1999 Print Class Driver.) -- C:\WINDOWS\system32\drivers\HPZipr12.sys
O58 - SDL:[MD5.ABCB05CCDBF03000354B9553820E39F8] - 30.10.2007 - 10:25:55 R--A- . (.HP - 1284.4<->Usb Datalink Driver (Windows 2000).) -- C:\WINDOWS\system32\drivers\HPZius12.sys
O58 - SDL:[MD5.4477689E2D8AE6B78BA34C9AF4CC1ED1] - 24.07.2008 - 17:45:20 ---A- . (.LogMeIn, Inc. - LogMeIn Mirror Miniport Driver.) -- C:\WINDOWS\system32\drivers\lmimirr.sys
O58 - SDL:[MD5.3FAA563DDF853320F90259D455A01D79] - 24.07.2008 - 17:46:10 ---A- . (.LogMeIn, Inc. - LogMeIn Rfs Drivemap Driver.) -- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
O58 - SDL:[MD5.D2D2FA02B722336960EEAE0AE7107891] - 30.04.2009 - 21:56:32 ---A- . (.Logitech Inc. - Logitech Video Driver.) -- C:\WINDOWS\system32\drivers\LV561AV.SYS
O58 - SDL:[MD5.C57C48FB9AE3EFB9848AF594E3123A63] - 30.04.2009 - 15:00:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys
O58 - SDL:[MD5.A1CD8EEC777F05DE505B76BB96709498] - 29.04.2010 - 14:39:24 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\system32\drivers\mbam.sys
O58 - SDL:[MD5.C7DD7D9739785BD3A6B8499EEC1DEE7E] - 29.04.2010 - 14:39:38 ---A- . (.Malwarebytes Corporation - Malwarebytes' Anti-Malware.) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
O58 - SDL:[MD5.BE984D604D91C217355CDD3737AAD25D] - 24.04.2003 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - NikeDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\nikedrv.sys
O58 - SDL:[MD5.2B298519EDBFCF451D43E0F1E8F1006D] - 04.08.2004 - 06:29:54 ---A- . (.NVIDIA Corporation - NVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73.) -- C:\WINDOWS\system32\drivers\nv4_mini.sys
O58 - SDL:[MD5.14E6FB92F1788982E2BBC81D915B1F02] - 28.05.2010 - 12:04:52 ---A- . (.Secunia - Secunia PSI Driver.) -- C:\WINDOWS\system32\drivers\psi_mf.sys
O58 - SDL:[MD5.80D317BD1C3DBC5D4FE7B1678C60CADD] - 24.04.2003 - 13:00:00 ---A- . (.Parallel Technologies, Inc. - Parallel Technologies DirectParallel IO Library.) -- C:\WINDOWS\system32\drivers\ptilink.sys
O58 - SDL:[MD5.A56FE08EC7473E8580A390BB1081CDD7] - 24.04.2003 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - Rio8Drv.sys Usb Driver.) -- C:\WINDOWS\system32\drivers\rio8drv.sys
O58 - SDL:[MD5.0A854DF84C77A0BE205BFEAB2AE4F0EC] - 24.04.2003 - 13:00:00 ---A- . (.S3/Diamond Multimedia Systems - RioDrv Usb Driver.) -- C:\WINDOWS\system32\drivers\riodrv.sys
O58 - SDL:[MD5.A6886CAF9D03DADE7144171E471ECA6F] - 15.04.2009 - 07:32:36 R--A- . (.Ralink Technology, Corp. - Ralink 802.11 USB Wireless Adapter Driver.) -- C:\WINDOWS\system32\drivers\rt2870.sys
O58 - SDL:[MD5.90A3935D05B494A5A39D37E71F09A677] - 13.04.2008 - 17:39:15 ---A- . (.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) -- C:\WINDOWS\system32\drivers\secdrv.sys
O58 - SDL:[MD5.6B33D0EBD30DB32E27D1D78FE946A754] - 13.04.2008 - 19:36:39 ---A- . (.Silicon Integrated Systems Corporation - SiS NT AGP Filter.) -- C:\WINDOWS\system32\drivers\sisagp.sys
O58 - SDL:[MD5.3FBB6EF8B5A71A2FA11F5F461BB73219] - 04.08.2004 - 06:31:34 ---A- . (.SiS Corporation - SiS PCI Fast Ethernet Adapter Driver.) -- C:\WINDOWS\system32\drivers\sisnic.sys
O58 - SDL:[MD5.3AD0362CF68DE3AC500E981700242CCA] - 11.05.2009 - 09:11:52 ---A- . (.Avira GmbH - AVIRA SnapShot Driver.) -- C:\WINDOWS\system32\drivers\ssmdrv.sys
O58 - SDL:[MD5.D74A8EC75305F1D3CFDE7C7FC1BD62A9] - 24.04.2003 - 13:00:00 ---A- . (.Toshiba Corporation - WDM Toshiba Tecra Video Capture Driver.) -- C:\WINDOWS\system32\drivers\tsbvcap.sys
O58 - SDL:[MD5.E8C1B9EBAC65288E1B51E8A987D98AF6] - 16.10.2009 - 01:33:06 ---A- . (.Apple, Inc. - Apple Mobile Device USB Driver.) -- C:\WINDOWS\system32\drivers\usbaapl.sys
O58 - SDL:[MD5.55E01061C74A8CEFFF58DC36114A8D3F] - 24.04.2003 - 13:00:00 ---A- . (.RAVISENT Technologies Inc. - CineMaster C WDM DVD Minidriver.) -- C:\WINDOWS\system32\drivers\vdmindvd.sys
O58 - SDL:[MD5.E423A6A5184A2D30E689A89CE4332E4C] - 30.05.2010 - 17:30:56 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\drivers\WudfPf.sys
O58 - SDL:[MD5.6D3ADA4CE95CECA7BCE527A08C4C474E] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ansi.sys
O58 - SDL:[MD5.0FE9F16075C9ACB941C957B7C649176E] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\country.sys
O58 - SDL:[MD5.C6D29F29DE7427B1B0775E53E577B623] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\himem.sys
O58 - SDL:[MD5.582BCDD47CF4B68B5CB528F18E3CB808] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\key01.sys
O58 - SDL:[MD5.FBBCFEC1379C5C02D88A361993EDF1B8] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\keyboard.sys
O58 - SDL:[MD5.7D30A74B5FB9FE3B245A6CE5FBCD71D5] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos.sys
O58 - SDL:[MD5.CF9ED169FF86D935E47999E82359E898] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos404.sys
O58 - SDL:[MD5.03B945AC0481CD8BB161C3569D8ED1C3] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos411.sys
O58 - SDL:[MD5.BBC957DC18C17CC027EB80B7C77F2AEA] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos412.sys
O58 - SDL:[MD5.3CFFAEFFF23B0D208214A6D3061A5B1B] - 24.04.2003 - 13:00:00 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntdos804.sys
O58 - SDL:[MD5.CAAA108FD7BF71989946B39704323455] - 04.08.2004 - 06:45:25 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio.sys
O58 - SDL:[MD5.6F73F50162DEF60C84B725C18CD9140F] - 04.08.2004 - 06:45:14 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio404.sys
O58 - SDL:[MD5.0FDD5E69C1FF3B58043D44F2CC743D45] - 04.08.2004 - 06:45:10 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio411.sys
O58 - SDL:[MD5.8842837C4D8311BF8E72BEE8CCC42217] - 04.08.2004 - 06:45:15 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio412.sys
O58 - SDL:[MD5.6B56CEB3C6F9D5CD7293DBD9FE23B311] - 04.08.2004 - 06:45:12 ---A- . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\ntio804.sys


---\\ Liste des outils de nettoyage (LATC) (O63)
O63 - Logiciel: HijackThis 2.0.2 - (.TrendMicro.)
O63 - Logiciel: ZHPDiag 1.25 - (.Nicolas Coolman.)


---\\ Liste des services Legacy (LALS) (O64)
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\sched.exe - Avira AntiVir Planificateur (AntiVirSchedulerService) .(.Avira GmbH - Antivirus Scheduler.) - LEGACY_ANTIVIRSCHEDULERSERVICE
O64 - Services: CurCS - C:\Program Files\Avira\AntiVir Desktop\avguard.exe - Avira AntiVir Guard (AntiVirService) .(.Avira GmbH - Antivirus On-Access Service.) - LEGACY_ANTIVIRSERVICE
O64 - Services: CurCS - (.not file.) - appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946} (appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}) .(.Pas de propriétaire - Pas de description.) - LEGACY_APPDRV01.FS.{A7E56839-0B44-4261-8167-6DCA58E79946}
O64 - Services: CurCS - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe - Apple Mobile Device (Apple Mobile Device) .(.Apple Inc. - Apple Mobile Device Service.) - LEGACY_APPLE_MOBILE_DEVICE
O64 - Services: CurCS - C:\Windows\sysTEM32\DRIVERS\avgntdd.sys - avgntdd (avgntdd) .(.Avira GmbH - Avira AntiVir File Filter Driver.) - LEGACY_AVGNTDD
O64 - Services: CurCS - C:\Windows\sysTEM32\DRIVERS\avgntmgr.sys - avgntmgr (avgntmgr) .(.Avira GmbH - Avira AntiVir File Filter Driver Manager.) - LEGACY_AVGNTMGR
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\avipbb.sys - avipbb (avipbb) .(.Avira GmbH - Avira Driver for RootKit Detection.) - LEGACY_AVIPBB
O64 - Services: CurCS - (.not file.) - catchme (catchme) .(.Pas de propriétaire - Pas de description.) - LEGACY_CATCHME
O64 - Services: CurCS - (.not file.) - Lanceur de processus serveur DCOM (DcomLaunch) .(.Pas de propriétaire - Pas de description.) - LEGACY_DCOMLAUNCH
O64 - Services: CurCS - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe - InstallDriver Table Manager (IDriverT) .(.Macrovision Corporation - IDriverT Module.) - LEGACY_IDRIVERT
O64 - Services: CurCS - C:\Program Files\Java\jre6\bin\jqs.exe - Java Quick Starter (JavaQuickStarterService) .(.Sun Microsystems, Inc. - Java(TM) Quick Starter Service.) - LEGACY_JAVAQUICKSTARTERSERVICE
O64 - Services: CurCS - (.not file.) - klmd23 (klmd23) .(.Pas de propriétaire - Pas de description.) - LEGACY_KLMD23
O64 - Services: CurCS - (.not file.) - klmdb (klmdb) .(.Pas de propriétaire - Pas de description.) - LEGACY_KLMDB
O64 - Services: CurCS - C:\Program Files\LogMeIn\x86\RaInfo.sys - LogMeIn Kernel Information Provider (LMIInfo) .(.LogMeIn, Inc. - RemotelyAnywhere Kernel Information Provide.) - LEGACY_LMIINFO
O64 - Services: CurCS - C:\Program Files\LogMeIn\x86\RaMaint.exe - LogMeIn Maintenance Service (LMIMaint) .(.LogMeIn, Inc. - LogMeIn Maintenance Service.) - LEGACY_LMIMAINT
O64 - Services: CurCS - (.not file.) - LMIRfsClientNP (LMIRfsClientNP) .(.Pas de propriétaire - Pas de description.) - LEGACY_LMIRFSCLIENTNP
O64 - Services: CurCS - C:\WINDOWS\system32\drivers\LMIRfsDriver.sys - LogMeIn Remote File System Driver (LMIRfsDriver) .(.LogMeIn, Inc. - LogMeIn Rfs Drivemap Driver.) - LEGACY_LMIRFSDRIVER
O64 - Services: CurCS - C:\Program Files\LogMeIn\x86\LogMeIn.exe - LogMeIn (LogMeIn) .(.LogMeIn, Inc. - LogMeIn.) - LEGACY_LOGMEIN
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\LVPr2Mon.sys - Logitech LVPr2Mon Driver (LVPr2Mon) .(.Pas de propriétaire - Pas de description.) - LEGACY_LVPR2MON
O64 - Services: CurCS - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe - Process Monitor (LVPrcSrv) .(.Logitech Inc. - Logitech LVPrcSrv Module..) - LEGACY_LVPRCSRV
O64 - Services: CurCS - (.not file.) - mbr (mbr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MBR
O64 - Services: CurCS - (.not file.) - mountmgr (mountmgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_MOUNTMGR
O64 - Services: CurCS - (.not file.) - Mup (Mup) .(.Pas de propriétaire - Pas de description.) - LEGACY_MUP
O64 - Services: CurCS - (.not file.) - Pilote système NDIS (NDIS) .(.Pas de propriétaire - Pas de description.) - LEGACY_NDIS
O64 - Services: CurCS - (.not file.) - nwncz (nwncz) .(.Pas de propriétaire - Pas de description.) - LEGACY_NWNCZ
O64 - Services: CurCS - (.not file.) - PartMgr (PartMgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_PARTMGR
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\psi_mf.sys - PSI (PSI) .(.Secunia - Secunia PSI Driver.) - LEGACY_PSI
O64 - Services: CurCS - (.not file.) - RDPNP (RDPNP) .(.Pas de propriétaire - Pas de description.) - LEGACY_RDPNP
O64 - Services: CurCS - (.not file.) - Appel de procédure distante (RPC) (RpcSs) .(.Pas de propriétaire - Pas de description.) - LEGACY_RPCSS
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\secdrv.sys - Secdrv (Secdrv) .(.Macrovision Corporation, Macrovision Europe - Macrovision SECURITY Driver.) - LEGACY_SECDRV
O64 - Services: CurCS - (.not file.) - srescan (srescan) .(.Pas de propriétaire - Pas de description.) - LEGACY_SRESCAN
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\ssmdrv.sys - ssmdrv (ssmdrv) .(.Avira GmbH - AVIRA SnapShot Driver.) - LEGACY_SSMDRV
O64 - Services: CurCS - (.not file.) - Services Terminal Server (TermService) .(.Pas de propriétaire - Pas de description.) - LEGACY_TERMSERVICE
O64 - Services: CurCS - (.not file.) - Gestionnaire de téléchargement (uploadmgr) .(.Pas de propriétaire - Pas de description.) - LEGACY_UPLOADMGR
O64 - Services: CurCS - (.not file.) - vsdatant (vsdatant) .(.Pas de propriétaire - Pas de description.) - LEGACY_VSDATANT
O64 - Services: CurCS - (.not file.) - Numéro de série du média portable (WmdmPmSp) .(.Pas de propriétaire - Pas de description.) - LEGACY_WMDMPMSP
O64 - Services: CurCS - C:\Windows\system32\DRIVERS\WudfPf.sys - Windows Driver Foundation - User-mode Driver Framework Platform Driver (WudfPf) .(.Pas de propriétaire - Pas de description.) - LEGACY_WUDFPF


---\\ File Associations Shell Spawning (O67)
O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe
O67 - Shell Spawning: <.bat> <batfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.cpl> <cplfile>[HKCR\..\cplopen\Command] (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\Windows\System32\shell32.dll
O67 - Shell Spawning: <.cmd> <cmdfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.com> <comfile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.exe> <exefile>[HKCR\..\open\Command] "%1" %* (.not file.)
O67 - Shell Spawning: <.html> <htmlfile>[HKCR\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\IEXPLORE.exe
O67 - Shell Spawning: <.js> <JSFile>[HKCR\..\open\Command] (.Microsoft Corporation - Microsoft (R) Windows Based Script Host.) -- C:\WINDOWS\System32\WScript.exe
O67 - Shell Spawning: <.reg> <regfile>[HKCR\..\open\Command] (.Microsoft Corporation - Éditeur du Registre.) -- C:\WINDOWS\regedit.exe


---\\ Start Menu Internet (SMI) (O68)
O68 - StartMenuInternet: <FIREFOX.EXE> <Mozilla Firefox>[HKLM\..\Shell\open\Command] (.Mozilla Corporation - Firefox.) -- C:\Program Files\Mozilla Firefox\firefox.exe
O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe
O68 - StartMenuInternet: <Safari.exe> <Safari>[HKLM\..\Shell\open\Command] (.Apple Inc. - Safari.) -- C:\Program Files\Safari\Safari.exe


---\\ Recherche d'infection Master Boot Record (O80)
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
Run by Andrée at 31.05.2010 00:31:12
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK



End of the scan (879 lines in 02mn 38s)
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Re: PC infecté

Messagepar Florinator » 31 Mai 2010 09:51

Relance une seule fois ZHPFix et colle cette ligne:
O64 - Services: CurCS - (.not file.) - nwncz (nwncz) .(.Pas de propriétaire - Pas de description.) - LEGACY_NWNCZ


1:
  • Clique droit sur l'icône ZHPFix
  • Sélectionne 'Exécuter en tant qu'administrateur'.
  • Clique sur le A rougeImage.
  • Clique sur Nettoyer.
  • Fais redémarrer l'ordi pour terminer le nettoyage.

2:

Télécharge ATF Cleaner crée par Atribune
  • Double-clique dessus afin de lancer le programme.
  • Sous l'onglet Main, choisis : Select All
  • Clique sur le bouton Empty Selected


Si tu utilises le navigateur Firefox :
Sauvegarde au préalable les paramètres de Firefox comme décrit ICI
    Clique Firefox au haut et choisis : Select All
    Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Si tu utilises le navigateur Opera :


    Clique Opera au haut et choisis : Select All
    Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Clique Exit, du menu principal, afin de fermer le programme.
Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.


3:

Il te faut supprimer tes points de restauration infectés, et recréer un point sain.

  • Va sur "Démarrer" puis clique droit sur "Poste de travail"
  • Va ensuite sur "Propriété", et sur l'onglet "Restauration Système"
  • Coche"Désactiver La Restauration..." puis fais Appliquer
  • Décoche cette même case, et refais "Appliquer"


D'autres soucis?

A++
Dernière édition par Florinator le 01 Juin 2010 09:11, édité 1 fois.
Le savoir n'est utile que si il est transmis.
Avatar de l’utilisateur
Florinator
Maître Libellulien
Maître Libellulien
 
Messages: 661
Inscription: 28 Déc 2009 16:19

Re: PC infecté

Messagepar HyperPat » 31 Mai 2010 10:29

Super, Merci beaucoup ! Je regarde ça ce soir et te retiens au courant. :supers:
Avatar de l’utilisateur
HyperPat
Libellulien
Libellulien
 
Messages: 94
Inscription: 21 Avr 2005 13:50
Localisation: Neuchâtel

Suivante

Retourner vers Désinfections et demandes d'analyse

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 4 invités