Bonjour,
voici les raport
le raport de hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:05, on 13/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Administrateur\Bureau\Anti Spams\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{D741B173-A972-421B-9D15-D3A0B20EB53A}: NameServer = 41.221.20.244 213.140.2.21
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
End of file - 2758 bytes
et le raport de vundofix
VundoFix V6.5.9
Checking Java version...
Scan started at 22:41:13 10/10/2007
Listing files found while scanning....
C:\windows\system32\fhkmp.bak1
C:\windows\system32\fhkmp.bak2
C:\windows\system32\fhkmp.ini
C:\windows\system32\fhkmp.ini2
C:\windows\system32\fhkmp.tmp
C:\windows\system32\pmkhf.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhkmp.bak1
C:\windows\system32\fhkmp.bak1 Has been deleted!
Attempting to delete C:\windows\system32\fhkmp.bak2
C:\windows\system32\fhkmp.bak2 Has been deleted!
Attempting to delete C:\windows\system32\fhkmp.ini
C:\windows\system32\fhkmp.ini Has been deleted!
Attempting to delete C:\windows\system32\fhkmp.ini2
C:\windows\system32\fhkmp.ini2 Has been deleted!
Attempting to delete C:\windows\system32\fhkmp.tmp
C:\windows\system32\fhkmp.tmp Has been deleted!
Attempting to delete C:\windows\system32\pmkhf.dll
C:\windows\system32\pmkhf.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhkmp.ini
C:\windows\system32\fhkmp.ini Has been deleted!
Attempting to delete C:\windows\system32\fhkmp.ini2
C:\windows\system32\fhkmp.ini2 Has been deleted!
Attempting to delete C:\windows\system32\pmkhf.dll
C:\windows\system32\pmkhf.dll Has been deleted!
Performing Repairs to the registry.
Done!
et le raprte de combofix
ComboFix 07-10-12.1 - Administrateur 2007-10-10 22:50:04.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.117 [GMT 1:00]
Running from: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\Administrateur\Application Data\WinAntiSpyware 2006
C:\Documents and Settings\Administrateur\Application Data\WinAntiSpyware 2006\Logs\update.log
C:\Documents and Settings\Administrateur\Application Data\WinAntiSpyware 2006\Logs\update.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((((((( Fichiers créés 2007-09-12 to 2007-10-12 ))))))))))))))))))))))))))))))))))))
.
2007-10-10 22:49 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-10 22:48 <REP> d-------- C:\Program Files\CCleaner
2007-10-10 22:41 <REP> d-------- C:\VundoFix Backups
2007-10-10 21:00 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\TuneUp Software
2007-10-10 20:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-10 20:57 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-10-10 20:56 <REP> d-------- C:\Program Files\TuneUp Utilities 2007
2007-10-10 20:55 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-10-10 15:53 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\IDM
2007-10-10 15:52 <REP> d-------- C:\Program Files\Internet Download Manager
2007-10-10 15:41 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-10 14:43 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-10-10 14:43 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-10-10 14:43 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-10-10 14:43 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-10-09 23:49 32,768 --a------ C:\WINDOWS\system32\awtsssp.dll
2007-10-09 13:19 <REP> d-------- C:\Program Files\Alcohol Soft
2007-10-09 12:23 214,528 --------- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-09 12:23 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2007-10-09 11:02 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-08 23:27 149,776 --a------ C:\WINDOWS\system32\MSJINT35.DLL
2007-10-08 20:14 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-10-06 17:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2007-10-06 01:18 <REP> d-------- C:\Program Files\Windows Live
2007-10-06 01:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-10-06 01:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2007-10-04 00:22 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-10-04 00:22 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-10-04 00:07 <REP> d-------- C:\Program Files\Microsoft Works
2007-10-04 00:06 <REP> d-------- C:\Program Files\MSBuild
2007-10-04 00:04 <REP> d-------- C:\Program Files\Microsoft.NET
2007-10-04 00:04 <REP> d-------- C:\Program Files\Fichiers communs\ODBC
2007-10-03 23:58 <REP> d-------- C:\Program Files\Microsoft Visual Studio 8
2007-10-03 23:55 <REP> d-------- C:\WINDOWS\SHELLNEW
2007-10-03 23:53 <REP> dr-h----- C:\MSOCache
2007-10-03 23:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-03 01:15 <REP> d-------- C:\WINDOWS\Sun
2007-10-02 21:42 <REP> d-------- C:\Program Files\Adssite Advanced Toolbar
2007-10-02 21:42 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Adssite Advanced Toolbar
2007-10-02 21:39 40,733 --a------ C:\WINDOWS\system32\rightonadz-uninst.exe
2007-10-02 17:48 <REP> d-------- C:\Documents and Settings\Administrateur\Incomplete
2007-10-02 17:48 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\LimeWire
2007-10-01 19:37 <REP> d-------- C:\Program Files\Infinity USB
2007-10-01 19:36 11,520 -ra------ C:\WINDOWS\system32\drivers\infusb.sys
2007-10-01 12:36 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Anuman Interactive
2007-09-28 22:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-09-28 22:44 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-09-28 22:42 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-09-28 22:40 <REP> d-------- C:\Program Files\Passware
2007-09-28 22:40 6,058,496 --a------ C:\WINDOWS\system32\dllcache\ieframe.dll
2007-09-28 22:40 383,488 --a------ C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-09-28 21:06 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Password Manager
2007-09-28 20:23 8,509,952 --a------ C:\WINDOWS\system32\dllcache\shell32.dll
2007-09-28 20:23 135,168 --a------ C:\WINDOWS\system32\dllcache\shsvcs.dll
2007-09-28 20:08 1,843,712 --a------ C:\WINDOWS\system32\dllcache\win32k.sys
2007-09-28 20:08 578,560 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2007-09-28 20:08 282,112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-09-28 20:08 40,960 --a------ C:\WINDOWS\system32\dllcache\mf3216.dll
2007-09-28 20:04 549,376 --a------ C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-09-28 20:03 1,314,816 --a------ C:\WINDOWS\system32\dllcache\msoe.dll
2007-09-28 20:03 683,520 --a------ C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-09-28 20:03 510,976 --a------ C:\WINDOWS\system32\dllcache\wab32.dll
2007-09-28 20:03 86,528 --a------ C:\WINDOWS\system32\dllcache\directdb.dll
2007-09-28 20:03 85,504 --a------ C:\WINDOWS\system32\dllcache\wabimp.dll
2007-09-28 19:57 293,376 --a------ C:\WINDOWS\system32\dllcache\winsrv.dll
2007-09-28 19:55 536,576 --a------ C:\WINDOWS\system32\dllcache\msado15.dll
2007-09-28 19:55 200,704 --a------ C:\WINDOWS\system32\dllcache\msadox.dll
2007-09-28 19:55 180,224 --a------ C:\WINDOWS\system32\dllcache\msadomd.dll
2007-09-28 19:55 102,400 --a------ C:\WINDOWS\system32\dllcache\msjro.dll
2007-09-28 19:54 334,336 --a------ C:\WINDOWS\system32\dllcache\wiaservc.dll
2007-09-28 19:49 2,182,400 --a------ C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-09-28 19:49 2,138,112 --a------ C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2007-09-28 19:49 2,059,648 --a------ C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2007-09-28 19:49 2,017,792 --a------ C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2007-09-28 19:46 1,104,896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-09-28 19:45 1,037,312 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-09-28 19:44 981,760 --a------ C:\WINDOWS\system32\dllcache\mfc42u.dll
2007-09-28 19:44 927,504 --a------ C:\WINDOWS\system32\dllcache\mfc40u.dll
2007-09-28 19:41 364,160 --a------ C:\WINDOWS\system32\dllcache\update.sys
2007-09-28 19:32 124,928 --a------ C:\WINDOWS\system32\dllcache\oledlg.dll
2007-09-28 19:28 144,896 --a------ C:\WINDOWS\system32\dllcache\schannel.dll
2007-09-28 19:27 1,049,600 --a------ C:\WINDOWS\system32\dllcache\kernel32.dll
2007-09-28 17:10 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Lavasoft
2007-09-28 17:02 185,344 --a------ C:\WINDOWS\system32\dllcache\upnphost.dll
2007-09-28 16:54 57,344 --a------ C:\WINDOWS\system32\dllcache\agentdpv.dll
2007-09-28 16:53 539,136 --a------ C:\WINDOWS\system32\dllcache\msftedit.dll
2007-09-28 16:53 433,152 --a------ C:\WINDOWS\system32\dllcache\riched20.dll
2007-09-28 16:52 574,464 --a------ C:\WINDOWS\system32\dllcache\ntfs.sys
2007-09-28 16:50 765,952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-09-28 15:57 <REP> d-------- C:\Program Files\Skype
2007-09-28 15:57 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2007-09-28 15:39 <REP> d-------- C:\Program Files\ODM
2007-09-28 15:39 <REP> d-------- C:\Program Files\directx
2007-09-28 15:14 <REP> d-------- C:\Program Files\Java
2007-09-28 15:14 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-09-28 15:10 <REP> d-------- C:\Program Files\SuperCopier2
2007-09-28 15:00 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\DMCache
2007-09-28 14:53 <REP> d--h----- C:\WINDOWS\PIF
2007-09-28 14:53 <REP> d-------- C:\Program Files\Total Video Converter
2007-09-28 14:50 <REP> d-------- C:\Documents and Settings\Administrateur\Contacts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-10 21:46 52,520 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-10 21:46 11,552 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-10 20:37 --------- d-----w C:\Program Files\Ad-Aware
2007-09-27 22:44 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 01:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 01:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-20 14:29 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 09:59 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 09:59 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 09:59 52,224 ----a-w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 09:59 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 09:59 459,264 ----a-w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 09:59 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 09:59 384,512 ----a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 09:59 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 09:59 267,776 ----a-w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 09:59 232,960 ----a-w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 09:59 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 09:59 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 09:59 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 09:59 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 09:59 124,928 ----a-w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 09:59 105,984 ----a-w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 09:59 102,400 ----a-w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 09:59 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:22 63,488 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:22 625,152 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 13,824 ----a-w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-16 15:17 51,568 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-08-15 23:33 9,464 ----a-w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-08-15 23:33 9,336 ----a-w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-08-15 23:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 23:33 43,528 ----a-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-08-15 23:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 23:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 23:33 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2007-08-15 23:33 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 23:33 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2007-08-15 23:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 23:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 23:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 23:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 23:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 23:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 23:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 23:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-07-30 18:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 18:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 18:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 18:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 18:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 18:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 18:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 18:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-23 08:39 202,160 ----a-w C:\WINDOWS\system32\idmmbc.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4B9ECF81-666D-4B07-A71C-CEDCBD50B4F4}]
2007-10-09 23:49 32768 --a------ C:\WINDOWS\system32\awtsssp.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{91521DFF-A8B7-4541-8BCD-8456E6DC44D5}]
C:\WINDOWS\system32\pmkhf.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="soundman.exe" [2002-03-21 12:23 C:\WINDOWS\soundman.exe]
"VisualTaskTips"="C:\Windows\System32\VisualTaskTips.exe" [2004-08-28 14:00]
"Vistadrv"="C:\WINDOWS\system32\Vistadrive\vsdrv.exe" [2006-07-30 03:37]
"TransBar"="C:\Windows\System32\TransBar.exe" [2001-08-28 12:00]
"Styler"="C:\Program Files\styler\Styler.exe" [2006-05-03 10:48]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2007-01-10 21:59]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"AtiPTA"="atiptaxx.exe" [2001-10-27 07:32 C:\WINDOWS\system32\atiptaxx.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-20 13:04]
"UberIcon"="C:\Program Files\UberIcon\UberIcon Manager.exe" [2005-08-12 20:52]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-12-06 16:56]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-04 17:53]
"uTorrent"="C:\Program Files\uTorrent\uTorrent.exe" [2007-09-28 12:31]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 11:29]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nltide_3"=rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4B9ECF81-666D-4B07-A71C-CEDCBD50B4F4}"= C:\WINDOWS\system32\awtsssp.dll [2007-10-09 23:49 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsssp]
awtsssp.dll 2007-10-09 23:49 32768 C:\WINDOWS\system32\awtsssp.dll
R0 Si3112;Si3112;C:\WINDOWS\system32\drivers\Si3112.sys
R3 ADPTEHCD;Adaptec USB 2.0 Enhanced Host Controller Driver;C:\WINDOWS\system32\DRIVERS\asusehcd.sys
R3 AUSBD_FilterService;Adaptec USB 2.0 Port Enumeration Driver;C:\WINDOWS\system32\DRIVERS\asususbd.sys
S2 ATITUNEP;ATI WDM TV Tuner;C:\WINDOWS\system32\DRIVERS\atintuxx.sys
S2 ATIXSAudio;ATI WDM TV Audio Crossbar;C:\WINDOWS\system32\DRIVERS\atinxsxx.sys
S2 TTDec;ATI WDM Teletext Decoder;C:\WINDOWS\system32\DRIVERS\ATINTTXX.sys
S2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe -k netsvcs
S3 ativraxx;ATI WDM Rage Theater Audio;C:\WINDOWS\system32\DRIVERS\atinraxx.sys
S3 DCamUSBNW800;CIF USB Camera (2110);C:\WINDOWS\system32\DRIVERS\pcam800.sys
S3 INFUSB;INFUSB;C:\WINDOWS\system32\drivers\infusb.sys
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalService WebClient LmHosts upnphost SSDPSRV
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{67e345be-6da6-11dc-8012-00e04ce201e2}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL systems.com
read\command - explorer.exe
start\command - systems.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fff0a78a-6dc5-11dc-801e-00e04ce201e2}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL systems.com
read\command - explorer.exe
start\command - systems.com
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-10-10 20:00:51 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-10-12 21:50:09 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2007-10-12 22:53:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-12 22:54:33 - machine was rebooted
.
--- E O F ---
et le raporte de purity
fix lancé en mode sans echec
Rapport Purity 0.02 lancé [1] fois! le 10/10/2007 à 22:34:24,64
Liste des éléments rencontrés au cours de la Recherche...
C:\Program Files\Outerinfo
fichiers,dossiers sauvegardés dans C:\Documents and Settings\Administrateur\Bureau\Purity\Purity40.zip
Fin du rapport