Comment supprimer backdoor

Fermé
noe - 4 févr. 2009 à 10:00
 Utilisateur anonyme - 4 févr. 2009 à 10:50
Bonjour,

Impossible de télécharger des MAJ, de se connecter sur un site antivirus, j'ai reussi à installer Spyware Terminator (apres l echec cuisant de HijackThis et Malwarebytes ). Apres un scan, il a trouvé 3 backdoor, impossible à mettre en quarantaine ou à supprimer.
Sachant que je suis très limitée au niveau telechargement de logiciels puisque tout est bloqué, que puis je faire pour les supprimer ? Solution radicale ? le formatage ? N y a t il vraiment pas d autres moyens ?

Merci d'avance pour votre réponse
Rapport de scann




Logfile of Spyware Terminator v2.3.0.507 (db:3.002.004.000)
Scan Time: 04/02/2009 09:45:03 length: 652 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Fast_Spyware_Scan
Scanned Objects: 47038 (Critical:4)
Filter: No System items, No Safe items, No Invalid items

Running Processes
EvtEng.exe [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
S24EvMon.exe [Intel Corporation ] : C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
WLKeeper.exe [Intel® Corporation] : C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
ZcfgSvc.exe [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
LEXBCES.EXE [Lexmark International, Inc.] : C:\WINDOWS\system32\LEXBCES.EXE
LEXPPS.EXE [Lexmark International, Inc.] : C:\WINDOWS\system32\LEXPPS.EXE
Apoint.exe [Alps Electric Co., Ltd.] : C:\Program Files\Apoint\Apoint.exe
igfxpers.exe [Intel Corporation] : C:\WINDOWS\system32\igfxpers.exe
SpywarefighterUser.exe [SPAMfighter] : C:\Program Files\Fighters\spywarefighter\SpywarefighterUser.exe
igfxsrvc.exe [Intel Corporation] : C:\WINDOWS\system32\igfxsrvc.exe
E_FATIBIE.EXE [SEIKO EPSON CORPORATION] : C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE
MMonitor.exe [OLYMPUS IMAGING CORP.] : C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
DLG.exe [BVRP Software] : C:\Program Files\Digital Line Detect\DLG.exe
Apntex.exe [Alps Electric Co., Ltd.] : C:\Program Files\Apoint\Apntex.exe
1XConfig.exe [Intel] : C:\Program Files\Intel\Wireless\Bin\1XConfig.exe
NICCONFIGSVC.exe [Dell Inc.] : C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
configservice.exe [SPAMfighter] : C:\Program Files\Fighters\configservice.exe
RegSrvc.exe [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
msnmsgr.exe [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
licenseservice.exe [SPAMfighter] : C:\Program Files\Fighters\licenseservice.exe
updateservice.exe [SPAMfighter] : C:\Program Files\Fighters\updateservice.exe
ScannerService.exe [SPAMfighter] : C:\Program Files\Fighters\ScannerService.exe

Internet Settings
R - HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DR
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchcust.htm
R - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyOverride = *.local
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =

BHO
02 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - [Adobe Systems Incorporated] : C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
02 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - [Microsoft Corporation] : C:\Program Files\Windows Live Toolbar\msntb.dll

Toolbars
03 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - [Microsoft Corporation] : C:\Program Files\Windows Live Toolbar\msntb.dll
03 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, EPSON Stylus DX6000 Series : [SEIKO EPSON CORPORATION] : C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, OM2_Monitor : [OLYMPUS IMAGING CORP.] : C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msnmsgr : [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msnmsgr.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Apoint : [Alps Electric Co., Ltd.] : C:\Program Files\Apoint\Apoint.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, igfxpers : [Intel Corporation] : C:\WINDOWS\system32\igfxpers.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, OM2_Monitor : [OLYMPUS IMAGING CORP.] : C:\Program Files\OLYMPUS\OLYMPUS MASTER 2\FIRSTSTART.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, spywarefighterguard : [SPAMfighter] : C:\Program Files\Fighters\spywarefighter\SpywarefighterUser.exe
04 - Startup: %STARTUPALL%\Digital Line Detect.lnk [BVRP Software] : C:\Program Files\Digital Line Detect\DLG.exe
04 - Startup: %STARTUPALL%\dlbcserv.lnk : C:\Program Files\Dell Photo Printer 720\dlbcserv.exe

Shell Extensions
Outlook File Icon Extension - {0006F045-0000-0000-C000-000000000046} - [Microsoft Corporation] : C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL
YMailShellExt Class - {5464D816-CF16-4784-B9F3-75C0DB52B499} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Common\ymmapi.dll
Mes dossiers de partage - {FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} - [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll

Protocol Handler
- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
- {828030A1-22C1-4009-854F-8E305202313F} - [Microsoft Corporation] : C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
Data Page Pluggable Protocol mso-offdap Handler - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - [Microsoft Corporation] : C:\Program Files\Fichiers communs\Microsoft Shared\Web Components\10\OWC10.DLL

Services
23 - [Meetinghouse Data Communications] : C:\WINDOWS\system32\DRIVERS\AegisP.sys
23 - [Alps Electric Co., Ltd.] : C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
23 - [Dell Inc] : C:\WINDOWS\system32\DRIVERS\APPDRV.SYS
23 - [ALWIL Software] : C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
23 - [Broadcom Corporation] : C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\drvmcdb.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\drvnddm.sys
23 - [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\iwca.sys
23 - [Lexmark International, Inc.] : C:\WINDOWS\system32\LEXBCES.EXE
23 - [Dell Inc.] : C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
23 - [Dell Inc] : C:\WINDOWS\system32\DRIVERS\omci.sys
23 - [SPAMfighter] : C:\Program Files\Fighters\licenseservice.exe
23 - [SPAMfighter] : C:\Program Files\Fighters\updateservice.exe
23 - [SPAMfighter] : C:\Program Files\Fighters\ScannerService.exe
23 - [SPAMfighter] : C:\Program Files\Fighters\configservice.exe
23 - [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
23 - [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
23 - [Intel Corporation] : C:\WINDOWS\system32\DRIVERS\s24trans.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\sscdbhk5.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\drivers\ssrtln.sys
23 - [SigmaTel, Inc.] : C:\WINDOWS\system32\drivers\STAC97.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnboio.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsncofs.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsndrct.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsndres.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnifs.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnopio.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnpool.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnudf.sys
23 - [Sonic Solutions] : C:\WINDOWS\system32\dla\tfsnudfa.sys
23 - : C:\WINDOWS\system32\DRIVERS\vffilter.sys
23 - [Intel® Corporation] : C:\WINDOWS\system32\DRIVERS\w29n51.sys
23 - [Conexant Systems, Inc.] : C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
23 - [Intel® Corporation] : C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Winlogon Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui, DLLName : [Intel Corporation] : C:\WINDOWS\system32\igfxdev.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless, DLLName : [Intel Corporation] : C:\Program Files\Intel\Wireless\Bin\LgNotify.dll

IE URL Search Hooks
Yahoo! ¤u¨ã¦C - {{EF99BD32-C1FB-11D2-892F-0090271D4F88}} - [Yahoo! Inc.] : C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

Threat Files
<MyWebSearch.MySearch> : C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
<Backdoor.TDSS.asz> [Microsoft Corporation] : C:\WINDOWS\system32\TDSSnrsr.dll
<Backdoor.TDSS.atb> [Microsoft Corporation] : C:\WINDOWS\system32\TDSSriqp.dll
<Backdoor.TDSS.ade> [Microsoft Corporation] : C:\WINDOWS\system32\TDSSofxh.dll

Advanced Files Report
%PROGRAMFILES%\Intel\Wireless\Bin\LgNotify.dll [Intel Corporation] [LogonNotify Dynamic Link Library] MD5=E0305040E70BE2AE657987CE0D7D14DF SIZE=110592
%PROGRAMFILES%\Intel\Wireless\Bin\EvtEng.exe [Intel Corporation] [EvtEng Module] MD5=D335183519E6814DFAB4ED3DD806A943 SIZE=86016
%PROGRAMFILES%\Intel\Wireless\Bin\PsRegApi.dll [Intel Corporation] [PsRegApi] MD5=B21C70DE64782A756CE69271C95E3F0A SIZE=184320
%PROGRAMFILES%\Intel\Wireless\Bin\TraceAPI.DLL [Intel Corporation] [TraceAPI Module] MD5=76D279F83F8A0A1487AB3C263A4BF509 SIZE=135168
%PROGRAMFILES%\Intel\Wireless\Bin\S24EvMon.exe [Intel Corporation] [Mobile Unit Support Service] MD5=79A647519CA3E700E9738153F788FB7D SIZE=360521
%PROGRAMFILES%\Intel\Wireless\Bin\WLKeeper.exe [Intel® Corporation] [SSOFSet Service] MD5=43ED73F10DE96E0A23244BD9CF04F5C2 SIZE=225353
%PROGRAMFILES%\Intel\Wireless\Bin\PfMgrApi.dll [Intel Corporation] [ProfileMgrApi Dynamic Link Library] MD5=631917C9A8A123DDB6B14BA40216A2C6 SIZE=450560
%PROGRAMFILES%\Intel\Wireless\Bin\MurocApi.dll [Intel Corporation] [MurocApi Dynamic Link Library] MD5=9437368165F1DBB08B474CC9943AE96D SIZE=237568
%PROGRAMFILES%\Intel\Wireless\Bin\S24MUDLL.dll [Intel Corporation] [Intel Mobile Unit Support Service] MD5=FC775273061FC3CEB5939DE227A22CE8 SIZE=61440
%PROGRAMFILES%\Intel\Wireless\Bin\C1XStngs.dll [Intel Corporation] [C8021XSettings Dynamic Link Library] MD5=5E908ACB97CA671FFBB4B1CCA5D7DC22 SIZE=323584
%PROGRAMFILES%\Intel\Wireless\Bin\C8021FRA.dll [Intel Corporation] [C8021XSettings Dynamic Link Library] MD5=44E68801AD79ED30BA30D26A46625842 SIZE=86016
%PROGRAMFILES%\Intel\Wireless\Bin\LSAWRAPI.dll [Intel Corporation] [Intel Corporation LSAWRAPI] MD5=1EAEFFBD6492359E578072CB5928794A SIZE=49226
%PROGRAMFILES%\Alwil Software\Avast4\French\Base.dll [ALWIL Software] [avast! Antivirus] MD5=056DECD877CD89F32EFDF65BD21AD3CD SIZE=98304
%PROGRAMFILES%\Intel\Wireless\Bin\ZcfgSvc.exe [Intel Corporation] [ZeroCfgSvc Application] MD5=17F5221A41F70386CD352AEE30CEA56F SIZE=389120
%PROGRAMFILES%\Intel\Wireless\Bin\ZcSvcFRA.dll [Intel Corporation] [ZeroCfgSvc Application] MD5=85A90EDA15F58D76DA98702A10FBF6FD SIZE=57344
%PROGRAMFILES%\Intel\Wireless\Bin\D8021Xps.DLL MD5=4672652E7F06BCEF5B4998EF5C6AF6FF SIZE=73728
%SYSDIR%\LEXBCES.EXE [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=E19C8550B4C6C67FABFFD998EACF440A SIZE=311296
%SYSDIR%\lexp2p32.dll [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=9F2FD42D010FE6408D202ED4139BCDCB SIZE=201216
%SYSDIR%\lex2kusb.dll [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=F1E07F5BB22E4568B8E2C0159E74EFD5 SIZE=197120
%SYSDIR%\LEXLMPM.DLL [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=C2671D78109644694DEA04B845092727 SIZE=192512
%SYSDIR%\LexBce.dll [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=2FCC7D083C925365C9D6414495F3FC01 SIZE=147456
%SYSDIR%\E_FLBBIE.DLL [SEIKO EPSON CORPORATION] [EPSON Bi-directional Printer] MD5=99C51F86CE35F6C0621A7C801EEAA718 SIZE=75264
%SYSDIR%\LEXPPS.EXE [Lexmark International, Inc.] [MarkVision for Windows (32 bit)] MD5=7A48C1D07A4445F622882833CAE9AB32 SIZE=174592
%SYSDIR%\VXDIF.DLL [Alps Electric Co., Ltd.] [Vxdif] MD5=AE5272D42117D5ECDBEC64A1CED31EDF SIZE=94235
%PROGRAMFILES%\Apoint\Apoint.DLL [Alps Electric Co., Ltd.] [Alps Pointing-device Driver] MD5=0A9204B851293890D2BF268D75151AF5 SIZE=1122304
%PROGRAMFILES%\Apoint\EzAuto.dll [Alps Electric Co., Ltd.] [Alps Utility for Pointing device] MD5=0EFD126AA2A4F17489EF30F8D1CAFB53 SIZE=49152
%PROGRAMFILES%\Apoint\EzLaunch.DLL [Alps Electric Co., Ltd.] [AlpsPoint] MD5=F0F6AA96F4EEAC1F20B5BE69976E55B0 SIZE=204800
%SYSDIR%\hccutils.DLL [Intel Corporation] [Intel(R) Common User Interface] MD5=3EA40C03BB20A68F5F49798296112EF9 SIZE=73728
%SYSDIR%\igfxsrvc.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=841A401331B3EC5C5662517FFFD3EA12 SIZE=57344
%SYSDIR%\igfxres.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=577720FBF05E2E08AB451F365D4794C8 SIZE=147456
%PROGRAMFILES%\Intel\Wireless\Bin\FrWrkFRA.dll [Intel Corporation] [Intel PROSet/Wireless] MD5=81A6494ED129D7DAA7E79D88F75499FC SIZE=36864
%PROGRAMFILES%\Intel\Wireless\Bin\FrameworkPlugins\ConnMgr.dll [Intel Corporation] [Intel PROSet/Wireless] MD5=096E9E3D0DAE30484EC088F2082A6115 SIZE=712704
%PROGRAMFILES%\Intel\Wireless\Bin\IntWAFRA.dll [Intel Corporation] [Intel PROSet/Wireless] MD5=CF1F24FA3BC42D41B9C057017601AB71 SIZE=241664
%PROGRAMFILES%\Dell\QuickSet\dadkeyb.dll MD5=C22A85D12B362E6D33660AD02B4D33B9 SIZE=69632
%SYSDIR%\tfswapi.dll [Sonic Solutions] MD5=B5C05CE075F48CC44C154F0CE25C4CFE SIZE=61498
%SYSDIR%\dla\tfswcres.dll [Sonic Solutions] MD5=ED49F01E88257594D96F93DE5EFFDE73 SIZE=634943
%SYSDIR%\PNCRT.dll [Real Networks, Inc] [RealPlayer/RealServer] MD5=B9807BDDD55D3D4DA93A0BF5F67E4144 SIZE=278528
%PROGRAMFILES%\Real\RealPlayer\rpap3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=809544B4C2AF383F21EDA6A7F99E7873 SIZE=395264
%COMMONFILES%\Real\Common\pngu3266.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=F41D63EEAAED116AF9EB20FE34A6F39D SIZE=387072
%COMMONFILES%\Real\Common\pnrs3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=0D2D341471C77BB41ADAC4FD16542E5A SIZE=11264
%COMMONFILES%\Real\Common\rpcl3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=2C76F63B90CE49A293625EF212DAC996 SIZE=247808
%COMMONFILES%\Real\Common\pnen3260.dll [RealNetworks, Inc.] [RealMedia® Client Core (32-bit)] MD5=FC035D73E2D57E09FB09DC6C917A6F2F SIZE=985600
%COMMONFILES%\Real\Plugins\audp3260.dll [RealNetworks, Inc.] [Audio Renderer/File Format plugin for RealMedia® (32-bit)] MD5=1A0E05DF11304F80ACFFB4BEB1E8AA58 SIZE=64000
%COMMONFILES%\Real\Plugins\auth3260.dll [RealNetworks, Inc.] [Authentication Manager plugin for RealMedia® (32-bit)] MD5=BE4120DFE0A2D77E68405D09599FF355 SIZE=30720
%COMMONFILES%\Real\Plugins\basc3260.dll [RealNetworks, Inc.] [Basic Authenticator plugin for RealMedia® (32-bit)] MD5=9C32643C6DAAEF689AC1A631AC65F789 SIZE=25088
%COMMONFILES%\Real\Plugins\Dbc_hbrf.dll [Digital Bitcasting Corporation.] [DBC(tm) High Bit Rate File Format Plug-In (32-bit) 1.0] MD5=4B44CD97FAD48E8271B6FB1455D3BE3E SIZE=105472
%COMMONFILES%\Real\Plugins\Dbc_hbrr.dll [Digital Bitcasting Corporation.] [DBC(tm) High Bit Rate Renderer Plug-In (32-bit) 1.2] MD5=7C7A07C984328D850F8AEE47E9713CF5 SIZE=75776
%COMMONFILES%\Real\Plugins\http3260.dll [RealNetworks, Inc.] [HTTP File System plugin for RealMedia® (32-bit)] MD5=DCC694FE896B7DB09DE06BA2C23B7E8A SIZE=121344
%COMMONFILES%\Real\Plugins\memf3260.dll [RealNetworks, Inc.] [Memory File System plugin for RealMedia® (32-bit)] MD5=39CE32F384C2A719801E0F0DF56E5406 SIZE=48640
%COMMONFILES%\Real\Plugins\meta3260.dll [RealNetworks, Inc.] [RTSL plugin for RealMedia® (32-bit)] MD5=B76E62F74713BCB3A5577B375DF92FDE SIZE=26624
%COMMONFILES%\Real\Plugins\mp3f3260.dll [RealNetworks, Inc.] [MPEG Audio File Format plugin for RealSystem G2 (32-bit)] MD5=06F1FE774C71B228E2EC952CE0B9CC5B SIZE=28160
%COMMONFILES%\Real\Plugins\mp3m3260.dll [RealNetworks, Inc.] [MP3 Plugin for RealPlayer® (32-bit)] MD5=DD383002C5558C6C55B7547CF84832E7 SIZE=44544
%COMMONFILES%\Real\Plugins\mp3r3260.dll [RealNetworks, Inc.] [MPEG Audio Rendering plugin for RealSystem G2 (32-bit)] MD5=2E8E733736B722290505D40A63621682 SIZE=83968
%COMMONFILES%\Real\Plugins\ntau3260.dll [RealNetworks, Inc.] [NTLM Authenticator plugin for RealMedia® (32-bit)] MD5=1C7E46CA0EA5A8094B11A1E838CC499C SIZE=28160
%COMMONFILES%\Real\Plugins\plus3260.dll [RealNetworks, Inc.] [RealAudio File Format plugin for RealMedia® (32-bit)] MD5=6820F36DD611081D9A4C2C6E625CAFAD SIZE=28160
%COMMONFILES%\Real\Plugins\ppff3260.dll [RealNetworks, Inc.] [Scalable Multicast File Format plugin for RealMedia® (32-bit)] MD5=D670CF2CC42B1156BE70539C0BBF121A SIZE=82432
%COMMONFILES%\Real\Plugins\pxcg3260.dll [RealNetworks, Inc.] [RealPix JPEG Codec plugin for RealMedia® (32-bit)] MD5=85A0025D45A5D812B7A33DCE8D541237 SIZE=27648
%COMMONFILES%\Real\Plugins\pxcj3260.dll [RealNetworks, Inc.] [RealPix JPEG Codec plugin for RealMedia® (32-bit)] MD5=66F7D4BE5CFA423705E459219F943F91 SIZE=80896
%COMMONFILES%\Real\Plugins\pxcp3260.dll [RealNetworks, Inc.] [RealPix PNG Codec plugin for RealMedia® (32-bit)] MD5=27F427E88386B1B7FCDD3DA98305040A SIZE=83456
%COMMONFILES%\Real\Plugins\pxff3260.dll [RealNetworks, Inc.] [RealPix File Format plugin for RealMedia® (32-bit)] MD5=55DFA0E7F934D02993CD991AF2D877EF SIZE=131072
%COMMONFILES%\Real\Plugins\pxgf3260.dll [RealNetworks, Inc.] [GIF File Format plugin for RealMedia® (32-bit)] MD5=5C5090A4C46BC3A6C8AD5E5D6E891976 SIZE=45568
%COMMONFILES%\Real\Plugins\pxgr3260.dll [RealNetworks, Inc.] [GIF Renderer plugin for RealMedia® (32-bit)] MD5=0F29AAB6A1494309B6973BFF396930B4 SIZE=55808
%COMMONFILES%\Real\Plugins\pxjf3260.dll [RealNetworks, Inc.] [JPEG File Format plugin for RealMedia® (32-bit)] MD5=C7BF37634173F7A6548A50DB88859A83 SIZE=38912
%COMMONFILES%\Real\Plugins\pxjr3260.dll [RealNetworks, Inc.] [JPEG Renderer plugin for RealMedia® (32-bit)] MD5=5F8AA37AC207D5B986D2769B4A38D9FA SIZE=93696
%COMMONFILES%\Real\Plugins\pxpf3260.dll [RealNetworks, Inc.] [PNG File Format plugin for RealMedia® (32-bit)] MD5=CED550A1123CC307E6CEEEAEA071799A SIZE=39936
%COMMONFILES%\Real\Plugins\pxpr3260.dll [RealNetworks, Inc.] [PNG Renderer plugin for RealMedia® (32-bit)] MD5=FC78DBB52355661084294C62B1B08E32 SIZE=84480
%COMMONFILES%\Real\Plugins\pxre3260.dll [RealNetworks, Inc.] [RealPix Renderer plugin for RealMedia® (32-bit)] MD5=9FE1BFC1B173E90439DF6D2C1C72F507 SIZE=90112
%COMMONFILES%\Real\Plugins\rare3260.dll [RealNetworks, Inc.] [RealAudio Renderer plugin for RealMedia® (32-bit)] MD5=65598E58F90F280D129AA2EFB19017F2 SIZE=118784
%COMMONFILES%\Real\Plugins\rmff3260.dll [RealNetworks, Inc.] [RealVideo File Format plugin for RealMedia® (32-bit)] MD5=8C63BD33A1A31B800AFF636AA8C04F97 SIZE=140288
%COMMONFILES%\Real\Plugins\rn5a3260.dll [RealNetworks, Inc.] [RN5 Private Authenticator plugin for RealMedia® (32-bit)] MD5=4030384EC43052E3DB496C507F7AD8F8 SIZE=28160
%COMMONFILES%\Real\Plugins\rtff3260.dll [RealNetworks, Inc.] [RealText File Format plugin for RealMedia® (32-bit)] MD5=04DC75108D0B521E912C2A27B8937420 SIZE=93184
%COMMONFILES%\Real\Plugins\rtre3260.dll [RealNetworks, Inc.] [RealText Renderer plugin for RealMedia® (32-bit)] MD5=9EF9275939A09C6EFF44447420DC9FD5 SIZE=84992
%COMMONFILES%\Real\Plugins\rupf3260.dll [RealNetworks, Inc.] [RealUpdate plugin for RealMedia® (32-bit)] MD5=7C368CB8AFE5595EEBE12A6D6A44AD66 SIZE=9728
%COMMONFILES%\Real\Plugins\rupr3260.dll [RealNetworks, Inc.] [RealUpdate Renderer plugin for RealMedia® (32-bit)] MD5=DA7B70B6FB1B660A721A55DE0E550EE2 SIZE=96768
%COMMONFILES%\Real\Plugins\rvre3260.dll [RealNetworks, Inc.] [RealVideo Renderer plugin for RealMedia® (32-bit)] MD5=5026F1E6C736B0B2B2E4E951B376F129 SIZE=126976
%COMMONFILES%\Real\Plugins\sdpp3260.dll [RealNetworks, Inc.] [SDP plugin for RealMedia® (32-bit)] MD5=2A7AB5143AED13E5ECB3A19F9412215D SIZE=42496
%COMMONFILES%\Real\Plugins\smlf3260.dll [RealNetworks, Inc.] [SMIL File Format plugin for RealMedia® (32-bit)] MD5=158AF568AD04BBF5B2409DFC337C2B70 SIZE=41984
%COMMONFILES%\Real\Plugins\smlr3260.dll [RealNetworks, Inc.] [SMIL Renderer plugin for RealMedia® (32-bit)] MD5=B9282EF358B0410A418524424AC06AD4 SIZE=142336
%COMMONFILES%\Real\Plugins\smmr3260.dll [RealNetworks, Inc.] [SMM Renderer plugin for RealMedia® (32-bit)] MD5=1236D8A30F46102F684C9350A76AE451 SIZE=18944
%COMMONFILES%\Real\Plugins\smpl3260.dll [RealNetworks, Inc.] [Simple File System plugin for RealMedia® (32-bit)] MD5=25FE72BACDDF256CAA21D9731239E43C SIZE=41472
%COMMONFILES%\Real\Plugins\stub3260.dll [RealNetworks, Inc.] [DRM Configuration plugin for RealMedia® (32-bit)] MD5=F4D6668304062003C2C926BD9613089E SIZE=71680
%COMMONFILES%\Real\Plugins\swff3260.dll [RealNetworks, Inc.] [Macromedia Flash File Format plugin for RealMedia® (32-bit)] MD5=741EF2A53B958C63148FDB266C080D21 SIZE=70656
%COMMONFILES%\Real\Plugins\swfr3260.dll [RealNetworks, Inc.] [Macromedia Flash Renderer plugin for RealPlayer7® (32-bit)] MD5=DEE4C27517F208F4157D906B3E4F1EC6 SIZE=505856
%COMMONFILES%\Real\Plugins\vidp3260.dll [RealNetworks, Inc.] [Video Renderer/File Format plugin for RealMedia® (32-bit)] MD5=9D5928E567AA4BAA5D56DA33410FBCE8 SIZE=101888
%COMMONFILES%\Real\Plugins\pnxr3260.dll [RealNetworks, Inc.] [Cross Platform Resource Handler for RealMedia® (32-bit)] MD5=4E70829217051F4405B04813A22005D2 SIZE=36864
%PROGRAMFILES%\Real\RealPlayer\pngui_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=493D55948D270E4E2AB56EE8586006D7 SIZE=11264
%PROGRAMFILES%\Real\RealPlayer\psethvy_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=23E8287F03BCFC335F6693734F2E9A62 SIZE=36864
%PROGRAMFILES%\Real\RealPlayer\rnath_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=1088CEB0531095D16183ABF1D1074784 SIZE=13824
%PROGRAMFILES%\Real\RealPlayer\rnmsg_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=A9591316D2409BF2486FCB4B7DB25FAE SIZE=53248
%PROGRAMFILES%\Real\RealPlayer\rpclsvc_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=492F248E1A1068FD73D78E74F0AAAA00 SIZE=51712
%PROGRAMFILES%\Real\RealPlayer\rpmnpane_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=8B15ADC8AC68427895EE5F0093A6EBA7 SIZE=233984
%PROGRAMFILES%\Real\RealPlayer\rpdestpn_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=8683D3903D416F7C126DFCB336AC3E5D SIZE=36864
%PROGRAMFILES%\Real\RealPlayer\rnereg_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=95743ADE1AD6270609AC15EDFAC173E0 SIZE=47616
%PROGRAMFILES%\Real\RealPlayer\rpapp_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=A7B165BF7BDD0C0F5E8974B6021583F4 SIZE=68096
%PROGRAMFILES%\Real\RealPlayer\rpclutil_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=457797A877F2AB5EE7C50CC16FC1B390 SIZE=266752
%COMMONFILES%\Real\Common\rjbviz_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=535284CC22BB0BE6843C63D111AF92D0 SIZE=18432
%PROGRAMFILES%\Real\RealPlayer\rpplus_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=0232BDD5B4F7549890A0B5F9EE88B757 SIZE=265216
%PROGRAMFILES%\Real\RealPlayer\rpupgrd_fr.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=9D5D28DD7BB03ED9D63718DD8AEB17CE SIZE=59392
%PROGRAMFILES%\Real\RealPlayer\embedgui_fr.dll [RealNetworks, Inc.] [RealPlayer (32 bits)] MD5=8FA7347CA863D5DEE1ADD21561B95D5C SIZE=38912
%PROGRAMFILES%\Real\RealPlayer\rnms3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=9265248E670255B8C1A792AF948099DB SIZE=146432
%PROGRAMFILES%\Real\RealPlayer\pnmi3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=ABA39B94237FEB5361A12D3AF10D95B3 SIZE=10752
%COMMONFILES%\Real\Update\rnqu3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=C8E241FB54432E49ADFDEE4C1ECCE999 SIZE=143360
%COMMONFILES%\Real\Update\rpup3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=4DB36D0E0732C857FD66A07069A8396A SIZE=158720
%COMMONFILES%\Real\Update\upgr3260.dll [RealNetworks, Inc.] [Upgrade Support Library (32-bit)] MD5=7E99A54DB6C29A3921EFFF5D603CF9A5 SIZE=168960
%COMMONFILES%\Real\Update\setu3260.dll [RealNetworks, Inc.] [RealPlayer (32-bit)] MD5=A835E842D9079127A0ED22AAD639CDA9 SIZE=189952
%PROGRAMFILES%\Alwil Software\Avast4\French\Lang.dll [ALWIL Software] [avast! Antivirus] MD5=02FDA873282D5EA52492327363E2AE16 SIZE=2568192
%PROGRAMFILES%\Fighters\spywarefighter\ScannerClient.dll [SPAMfighter] [SPYWAREfighter] MD5=CE94954CCD708B57F579E1FA5CC0F7D8 SIZE=217736
%PROGRAMFILES%\Fighters\spywarefighter\IProduct.dll [SPAMfighter] [SPAMfighter Tookit] MD5=288E42619A8D3CC75EE883D65FDD2269 SIZE=197256
%PROGRAMFILES%\Fighters\spywarefighter\ConfigClient.dll [SPAMfighter] [SPAMfighter Toolkit] MD5=C22D123443495C1E65C45C8F0D1C27EA SIZE=250504
%PROGRAMFILES%\Fighters\spywarefighter\LicenseClient.dll [SPAMfighter] [SPAMfighter Toolkit] MD5=E50F04BDD08DF12330D2B864005AA83D SIZE=209544
%SYSDIR%\igfxsrvc.exe [Intel Corporation] [Intel(R) Common User Interface] MD5=476A0876C16D2CC3F5A46697CF37BEE7 SIZE=159744
%SYSDIR%\igfxdev.dll [Intel Corporation] [Intel(R) Common User Interface] MD5=BFC2A40FE739C453F5D02B7EEF41CA28 SIZE=135168
%SYSDIR%\spool\DRIVERS\W32X86\3\E_FAUDBIE.DLL [SEIKO EPSON Corporation] [EPSON Color Printing System] MD5=5F11E4FB2DA804B7ECA054197895F4E2 SIZE=20480
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlyUICtl2.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=5B6BB38C14C8555130F2805EDC8BC902 SIZE=528384
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlylwApi2.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=8DFE557672201CAA2F62F19637E9AD9C SIZE=49152
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\olyuiskindrw.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=7DF14EC12600E25EC3FCE5FADC56BF61 SIZE=81920
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\olycms.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=19787B1341C4275B0A01A60E61A785E7 SIZE=36864
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlySkinMgr.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=7A0B2FB2D829BE3F90B98E4D0802F8EF SIZE=27136
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlyCamDetect.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Digital Camera Detect Library] MD5=8FF876CDF278C6D7905650EB239C734A SIZE=126976
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\glossary.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Glossaries Library] MD5=970016AED515C03EB626C309EBB27FDA SIZE=22528
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlAPCEvent.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=81F1031494140F178D0FE8C9FC887938 SIZE=69632
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlILEvent.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Master] MD5=DFEEE3DD0230E5EC1919DD2EDC9524FB SIZE=118784
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\OlyRum.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Rum Library] MD5=E37DD08CA363E989626E871E312D0820 SIZE=278528
%PROGRAMFILES%\OLYMPUS\OLYMPUS Master 2\PTP-IL.dll [OLYMPUS IMAGING CORP.] [OLYMPUS Ptp-IL Library] MD5=0D7A568E6979EEE866940A4C9626B5F8 SIZE=282624
%PROGRAMFILES%\Digital Line Detect\DLG.exe [BVRP Software] [BVRP Software TestLine] MD5=B66E56733E2CD6A10FDA5919625FBF46 SIZE=24576
%PROGRAMFILES%\Digital Line Detect\BVRPDIAG.dll [BVRP Software] [BVRP Software BVRPDiag] MD5=A476968C08667B1E09F2A95234E8CEEF SIZE=24576
%PROGRAMFILES%\Apoint\Apntex.exe [Alps Electric Co., Ltd.] [Alps Pointing-device Driver for Windows NT/2000/XP] MD5=0AA31DE4E40861EAF259D194A58D4317 SIZE=45056
%PROGRAMFILES%\Intel\Wireless\Bin\1XConfig.exe [Intel] [8021XConfig Module] MD5=16525F9337737D6EBCC5EA2BA296147B SIZE=245760
%PROGRAMFILES%\Intel\Wireless\Bin\IntelAE5.dll [Meetinghouse Data Communications] [AEGIS Client API] MD5=7AD18E44159DDC28AFDC979780B6D298 SIZE=1384535
%PROGRAMFILES%\Dell\NICCONFIGSVC\NICCONFIGSVC.exe [Dell Inc.] [NicConfigSvc] MD5=F24BCFEFE471F4D34A5786B7FCB9235C SIZE=356352
%PROGRAMFILES%\Fighters\configservice.exe [SPAMfighter] [SPAMfighter Toolkitt] MD5=B62B573B5F175F6339F98E68CDF404D7 SIZE=139912
%PROGRAMFILES%\Fighters\IProduct.dll [SPAMfighter] [SPAMfighter Tookit] MD5=22AE7C56EF9B15DEEA057D68C1EBB8F8 SIZE=197256
%PROGRAMFILES%\Fighters\ConfigClient.dll [SPAMfighter] [SPAMfighter Toolkit] MD5=CED59CFA71543DFDBD5F5C5F1D79FCC4 SIZE=250504
%PROGRAMFILES%\Fighters\Spywarefighter\Spywarefighter.dll [SPAMfighter] [SPYWAREfighter] MD5=44CA5E08F0846C0975A3544BC25FF3B7 SIZE=496264
%PROGRAMFILES%\Fighters\ScannerClient.dll [SPAMfighter] [SPYWAREfighter] MD5=285B95DBD7AF265B67993A85AE9A93C6 SIZE=217736
%PROGRAMFILES%\Fighters\LicenseClient.dll [SPAMfighter] [SPAMfighter Toolkit] MD5=BFE0F6242ADDB55370BF8C76659E490E SIZE=209544
%PROGRAMFILES%\Fighters\UpdateClient.dll [SPAMfighter] [SPAMfighter Toolkit] MD5=CAFDB1F5506D9D78E8E0628B3A21029D SIZE=184968
%PROGRAMFILES%\Fighters\Spywarefighter\engine.dll [ewido networks GmbH & Co. KG] [ewido security suite - engine] MD5=21D35585AC0D5BBBC1382AFC5EE7B4F3 SIZE=463496
%PROGRAMFILES%\Intel\Wireless\Bin\RegSrvc.exe [Intel Corporation] [RegSrvc Module] MD5=15BA3BCEEB32C4279B27F5C3389E4847 SIZE=139264
%PROGRAMFILES%\Fighters\licenseservice.exe [SPAMfighter] [SPAMfighter Toolkit] MD5=079F8DDC9C9D402670BEB82D06782DC3 SIZE=283272
%PROGRAMFILES%\Fighters\updateservice.exe [SPAMfighter] [SPAMfighter Toolkit] MD5=2EC196026E31014194FFC99B21E3C140 SIZE=307848
%PROGRAMFILES%\Fighters\ScannerService.exe [SPAMfighter] [SPYWAREfighter] MD5=13FC3A5D996C36D8FFF8BEC3DFF452A3 SIZE=311944
%SYSDIR%\userinit.exe,C:\WINDOWS\system32\twex.exe,
%PROGRAMFILES%\Dell Photo Printer 720\dlbcserv.exe MD5=D0D1B7429881A2F0465D73E1403B513D SIZE=315392
%PROGRAMFILES%\Windows Live Toolbar\msntb.dll [Microsoft Corporation] [Windows Live Toolbar] MD5=D638AFC241FCC42D15886CD26A3F1461 SIZE=544032
%PROGRAMFILES%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Inc.] [Yahoo! Toolbar] MD5=5A9E77C71D6D7030BC170DD7CF04CF5D SIZE=817936
%PROGRAMFILES%\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [Adobe Systems Incorporated] [AcroIEHelper Library] MD5=FC7850324464E4D19A24A03D882B5CC4 SIZE=54248
deskpan.dll
%PROGRAMFILES%\Microsoft Office\Office10\OLKFSTUB.DLL [Microsoft Corporation] [Microsoft Outlook] MD5=40544562EF356A8C76EB1371A447FD85 SIZE=55632
%PROGRAMFILES%\Yahoo!\Common\ymmapi.dll [Yahoo! Inc.] [YMMAPI Module] MD5=A0C86DB296BBE76145377D56C5975175 SIZE=190496
%PROGRAMFILES%\Windows Live\Messenger\fsshext.8.5.1302.1018.dll [Microsoft Corporation] [Messenger] MD5=8BDE1F61DFBAAE7A2916170E8B75FE0F SIZE=329240
%SYSDIR%\DRIVERS\AegisP.sys [Meetinghouse Data Communications] [AEGIS Client 3.1.0.1] MD5=076394A345EE5E9E3911FC0F058F4F38 SIZE=17056
%SYSDIR%\DRIVERS\Apfiltr.sys [Alps Electric Co., Ltd.] [Alps Touch Pad Driver for Windows 2000/XP] MD5=AEB775A2BAE0F392BA6ADC0BB706233A SIZE=108791
%SYSDIR%\DRIVERS\APPDRV.SYS [Dell Inc] [Application Driver] MD5=EC94E05B76D033B74394E7B2175103CF SIZE=16128
%SYSDIR%\DRIVERS\aswFsBlk.sys [ALWIL Software] [avast! Antivirus System] MD5=976E2AD5A62044629C2DE2CA8563722A SIZE=20560
%SYSDIR%\svchost.exe -k netsvcs
%SYSDIR%\DRIVERS\bcm4sbxp.sys [Broadcom Corporation] [Broadcom 440x 10/100 Integrated Controller] MD5=78123F44BE9E4768852A3A017E02D637 SIZE=44928
%SYSDIR%\svchost -k DcomLaunch
%SYSDIR%\svchost.exe -k NetworkService
%SYSDIR%\drivers\drvmcdb.sys [Sonic Solutions] MD5=E814854E6B246CCF498874839AB64D77 SIZE=87488
%SYSDIR%\drivers\drvnddm.sys [Sonic Solutions] MD5=EE83A4EBAE70BC93CF14879D062F548B SIZE=40480
%SYSDIR%\DRIVERS\HSFHWICH.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=140BA850417896B6B3322048DE280368 SIZE=200064
%SYSDIR%\DRIVERS\HSF_DP.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=B2DFC168D6F7512FAEA085253C5A37AD SIZE=1041536
%SYSDIR%\DRIVERS\ialmnt5.sys [Intel Corporation] [Intel Graphics Accelerator Drivers for Windows NT(R)] MD5=240D0F5D7CAAFD87BD8D801A97BBE041 SIZE=1049180
%SYSDIR%\DRIVERS\iwca.sys [Intel Corporation] [Intel Wireless Connection Agent] MD5=872D090CA5C306F62D1982BCE6302376 SIZE=234496
%SYSDIR%\svchost.exe -k LocalService
%SYSDIR%\DRIVERS\omci.sys [Dell Inc] [OMCI Driver] MD5=B17228142CEC9B3C222239FD935A37CA SIZE=17153
%SYSDIR%\svchost -k rpcss
%SYSDIR%\DRIVERS\s24trans.sys [Intel Corporation] [Intel Wireless LAN Packet Driver] MD5=81AA6F0D6A2BE1C550F814B036215888 SIZE=11354
%SYSDIR%\drivers\sscdbhk5.sys [Sonic Solutions] MD5=D7968049BE0ADBB6A57CEE3960320911 SIZE=5627
%SYSDIR%\drivers\ssrtln.sys [Sonic Solutions] MD5=C3FFD65ABFB6441E7606CF74F1155273 SIZE=23545
%SYSDIR%\drivers\STAC97.sys [SigmaTel, Inc.] [AC'97 Audio Controller with SigmaTel CODEC device driver.] MD5=305CC42945A713347F978D78566113F3 SIZE=273168
%SYSDIR%\svchost.exe -k imgsvc
%SYSDIR%\dla\tfsnboio.sys [Sonic Solutions] MD5=30698355067D07DA5F9EB81132C9FDD6 SIZE=25883
%SYSDIR%\dla\tfsncofs.sys [Sonic Solutions] MD5=FB9D825BB4A2ABDF24600F7505050E2B SIZE=34843
%SYSDIR%\dla\tfsndrct.sys [Sonic Solutions] MD5=CAFD8CCA11AA1E8B6D2EA1BA8F70EC33 SIZE=4123
%SYSDIR%\dla\tfsndres.sys [Sonic Solutions] MD5=16DB47E37D7289C12522FCCCD514431D SIZE=2271
%SYSDIR%\dla\tfsnifs.sys [Sonic Solutions] MD5=B92F67A71CC8176F331B8AA8D9F555AD SIZE=86586
%SYSDIR%\dla\tfsnopio.sys [Sonic Solutions] MD5=85985FAA9A71E2358FCC2EDEFC2A3C5C SIZE=15227
%SYSDIR%\dla\tfsnpool.sys [Sonic Solutions] MD5=BBA22094F0F7C210567EFDAF11F64495 SIZE=6363
%SYSDIR%\dla\tfsnudf.sys [Sonic Solutions] MD5=81340BEF80B9811E98CE64611E67E3FF SIZE=98714
%SYSDIR%\dla\tfsnudfa.sys [Sonic Solutions] MD5=C035FD116224CCC8325F384776B6A8BB SIZE=100603
%SYSDIR%\DRIVERS\vffilter.sys MD5=E35589090DDCB0A0D30067C9A97575B4 SIZE=15496
%SYSDIR%\DRIVERS\w29n51.sys [Intel® Corporation] [Intel® Wireless LAN Adapter] MD5=F0F902220910C4FBE42A51964BD33599 SIZE=3210496
%SYSDIR%\DRIVERS\HSF_CNXT.sys [Conexant Systems, Inc.] [SoftK56 Modem Driver] MD5=2DC7C0B6175A0A8ED84A4F70199C93B5 SIZE=685056
%PROGRAMFILES%\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll [Microsoft Corporation] [Messenger] MD5=56319E6B4D190A2DEB4463A9CE4D4F74 SIZE=66072
%COMMONFILES%\Microsoft Shared\Web Components\10\OWC10.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=6C1F34B3609BBD42E9B4A2A25548FAF0 SIZE=7445600
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\ACE.dll [Adobe Systems Incorporated] [ACE] MD5=CC954BD96AC969F9CDCC34E0349570DE SIZE=845824
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\AGM.dll [Adobe Systems Incorporated] [AGM] MD5=0B6A7C548C07EE28AFE05E6ABB96CD2E SIZE=5345280
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\Adobe DNG Converter.exe [Adobe Systems Incorporated] [Adobe DNG Converter] MD5=740F204E91A64455C60C7866664E742F SIZE=6183088
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\AdobeLM_libFNP.dll [Macrovision Europe Ltd.] [FLEXnet Publisher (32 bit)] MD5=1D6BFFBC5CDDA17E4812288FC5C5CE22 SIZE=2531328
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\AdobeUpdater.dll [Adobe Systems Incorporated] [Adobe Updater Library] MD5=88EAB5C445EB10829513D076B4E3675A SIZE=496128
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\BIB.dll [Adobe Systems Incorporated] [BIB] MD5=AF000DDB9802F88C3E40FA8378B835F7 SIZE=276480
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\FNP_Act_Installer.dll [Macrovision Europe Ltd.] [FLEXnet Publisher (32 bit)] MD5=6F2E09108202E5EB008C69488FAFD27C SIZE=934400
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\MPS.dll [Adobe Systems Incorporated] [MPS] MD5=63FFF89A754FC2B2D9DC37320B04547B SIZE=3798016
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\OperaMgr.dll [Adobe Systems Incorporated] [Adobe Opera Manager] MD5=DE0C3BB21AA525F07786BD748D6BD6DB SIZE=73728
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\Photodownloader.exe [Adobe Systems Incorporated] [Adobe Photo Downloader] MD5=47714AEAFFAB5A29DE9EA08CB4A74C04 SIZE=4937904
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\Plug-Ins\ASEFormat.8bi MD5=B13A5EBEEDF948B99F4817A7E4750579 SIZE=290816
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\Plug-Ins\Cineon.8bi [Adobe Systems, Incorporated] [Adobe Photoshop CS3] MD5=81F9ACB9E9C30B6766CF21B775D51EB2 SIZE=29184
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\Plug-Ins\MMXCore.8BX [Adobe Systems, Incorporated] [Adobe Photoshop CS3] MD5=6E5259852ACB4E964FEBD7FA5B5F9216 SIZE=245760
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\adobe_personalization.dll [Adobe Systems Incorporated] [Adobe EPIC Personalization] MD5=157E5B28440B22797106EC574805E10B SIZE=346624
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\libagli18n28.dll [IBM Corporation and others] [International Components for Unicode] MD5=E110D3350932FD8F193AB3D8A75F51D4 SIZE=671744
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\libagluc28.dll [IBM Corporation and others] [International Components for Unicode] MD5=B9460E79EC16BE1416869EB13CE68D2C SIZE=589824
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\libmmd.dll [Intel Corporation] [Intel(r) C Compiler, Intel(r) C++ Compiler, Intel(r) Fortran Compiler] MD5=A8E9F6ED6912CE1B03A172DB99CC1823 SIZE=2797660
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\libmysqld.dll MD5=6A9DC6FB11A6BF111171AF8FADDC2809 SIZE=2748416
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\ols.dll [Adobe Systems Incorporated] [Adobe Online Services] MD5=EC903FC197E43A61EC1B7B3B3C025584 SIZE=290816
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\pspluginsupport.dll [Adobe Systems Incorporated] [Adobe Photo Downloader 4.0 component] MD5=AC6417E173833D9B0E6738CE1485F783 SIZE=114688
%PROGRAMFILES%\Adobe\Adobe Bridge CS3\zlib.dll [ZLib.DLL] MD5=038F501695724FF0A44A0129DE8279DE SIZE=618496
%PROGRAMFILES%\Adobe\Adobe Device Central CS3\SCL.dll [Adobe Systems Incorporated] [Adobe SCL] MD5=70C98B718A3C72922A212C5762DC9F2A SIZE=1410048
%PROGRAMFILES%\Adobe\Adobe Stock Photos CS3\adobe_caps.dll [Adobe Systems Incorporated] [Adobe CAPS] MD5=C4A9FBE8B7D32E29880AE41738166C4B SIZE=220856
%COMMONFILES%\Adobe\Adobe Asset Services CS3\ARE.dll [Adobe Systems Incorporated] [ARE] MD5=8B507D67731B1C6244BD61E0E92621CD SIZE=319160
%COMMONFILES%\Adobe\Adobe Asset Services CS3\AXE8SharedExpat.dll [Adobe Systems Incorporated] [AXE8SharedExpat] MD5=EF6873EF162288CD053C31EFAAF366AD SIZE=167936
%COMMONFILES%\Adobe\Adobe Asset Services CS3\AdobeXMPFiles.dll [Adobe XMP Files] MD5=456D65C2543902E768CF6105386ABCBE SIZE=339968
%COMMONFILES%\Adobe\Adobe Asset Services CS3\BIB.dll [Adobe Systems Incorporated] [BIB] MD5=A864913759544CB26093B792206C0894 SIZE=282816
%COMMONFILES%\Adobe\Adobe Asset Services CS3\BIBUtils.dll [Adobe Systems Incorporated] [BIBUtils] MD5=2BD9F80EF217317935D9513320CF9CA6 SIZE=249552
%COMMONFILES%\Adobe\Adobe Asset Services CS3\Plug-Ins\Cineon.8bi [Adobe Systems, Incorporated] [Adobe Photoshop CS3] MD5=81F9ACB9E9C30B6766CF21B775D51EB2 SIZE=29184
%COMMONFILES%\Adobe\Adobe Asset Services CS3\Plug-Ins\FastCore.8BX [Adobe Systems, Incorporated] [Adobe Photoshop CS3] MD5=EA820925DED97BF9EDACD6A0FCBFD05C SIZE=32768
%COMMONFILES%\Adobe\Adobe Asset Services CS3\Plug-Ins\PCX.8BI [Adobe Systems, Incorporated] [Adobe Photoshop CS3] MD5=65CFE9BE2452FC842B8EF107107972FC SIZE=22528
%COMMONFILES%\Adobe\Linguistics\Providers\Plugins\WRLiloPlugin1.0\NFTWin_MacEnc.dll [Winsoft SA - NeuroSoft SA] [NFTWin_MacEnc.dll Dynamic Link Library] MD5=167FC2C88CB8366C2189E82A70281162 SIZE=221184
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.ar_AE [Adobe Systems Incorporated] [Adobe Updater] MD5=37C241539946B96B1C3C83AE06F43079 SIZE=60608
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.bg_BG [Adobe Systems Incorporated] [Adobe Updater] MD5=9E888FA177852B86278AAC34B8D0FDDF SIZE=64704
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.et_EE [Adobe Systems Incorporated] [Adobe Updater] MD5=8973BF847409AE84191BBE8A24A4B167 SIZE=63168
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.lt_LT [Adobe Systems Incorporated] [Adobe Updater] MD5=310EAE4D478D85DD6FBE0F05F42F2B2B SIZE=63168
%COMMONFILES%\Adobe\Updater5\AdobeUpdater.uk_UA [Adobe Systems Incorporated] [Adobe Updater] MD5=7766741BF52B87D901453EC62AE9EFCF SIZE=63680
%SYSDIR%\pxinsa64.exe [Sonic Solutions] MD5=A2838AF1113B5D5DC5837AD780A3647A SIZE=53760
%WINDIR%\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll [Microsoft Corporation] [Microsoft® Visual Studio® 2005] MD5=CB23B162AC655F24C6711A5F5DF348C6 SIZE=61440
%WINDIR%\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll [Microsoft Corporation] [Microsoft® Visual Studio® 2005] MD5=1B7524806D0270B81360C63A2FA047CB SIZE=1101824
%SYSDIR%\MFC71DEU.DLL [Microsoft Corporation] [Microsoft® Visual Studio .NET] MD5=C94D9D5B96D385586063093BAAD8F206 SIZE=65536
%COMMONFILES%\Microsoft Shared\Smart Tag\FPERSON.DLL [Microsoft Corporation] [Microsoft Office XP] MD5=595FC7AC26E2653A343F1FE787EB8561 SIZE=288160
%SYSDIR%\drivers\aswRdr.sys [ALWIL Software] [avast! Antivirus System] MD5=D78653E357BFADB9A432AA1F66D50269 SIZE=23152

End of Report


Déplacement en quarantaine:

Préparation…
Création d'un point de restauration
Quarantaine Backdoor.TDSS.asz
Les fichiers sélectionnés ont été déplacés.: C:\WINDOWS\system32\TDSSnrsr.dll
Les fichiers sélectionnés ont été déplacés.: C:\WINDOWS\system32\TDSSnrsr.dll
La suppression du fichier a échoué.: C:\WINDOWS\system32\TDSSnrsr.dll
Quarantaine Backdoor.TDSS.atb
Les fichiers sélectionnés ont été déplacés.: C:\WINDOWS\system32\TDSSriqp.dll
Les fichiers sélectionnés ont été déplacés.: C:\WINDOWS\system32\TDSSriqp.dll
La suppression du fichier a échoué.: C:\WINDOWS\system32\TDSSriqp.dll
Quarantaine Backdoor.TDSS.ade
Le déplacement du fichier a échoué. (Failed) : C:\WINDOWS\system32\TDSSofxh.dll
La suppression du fichier a échoué.: C:\WINDOWS\system32\TDSSofxh.dll
Quarantaine MyWebSearch
Supprimer le répertoire: C:\Program Files\MyWebSearch\
Fermeture du point de restauration système
Analyse(s) terminée(s)
A voir également:

1 réponse

Utilisateur anonyme
4 févr. 2009 à 10:50
salut :desactive tes protection le temps de la manip et :


Télécharges http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe ( de Cyrildu17 / C_XX ) sur ton bureau :


/!\ Déconnectes toi et fermes toutes applications en cours

? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
? Double clique sur l'icône Ad-removersituée sur ton bureau
? Au menu principal choisi l'option "Recherche"
? Postes le rapport qui apparait à la fin .

( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :

"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall)
0