SmitFraudFix v2.328
Rapport fait à 22:44:11,95, 23/06/2008
Executé à partir de D:\Documents and Settings\admi\Bureau\Nouveau dossier\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{168cf174-6dab-461c-a761-a7adfa5a5719}"="campy"
[HKEY_CLASSES_ROOT\CLSID\{168cf174-6dab-461c-a761-a7adfa5a5719}\InProcServer32]
@="C:\WINDOWS\system32\wuwbxp.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{168cf174-6dab-461c-a761-a7adfa5a5719}\InProcServer32]
@="C:\WINDOWS\system32\wuwbxp.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{c27abdde-8a43-4a7f-81c0-3fc3c952284f}"="chicot"
[HKEY_CLASSES_ROOT\CLSID\{c27abdde-8a43-4a7f-81c0-3fc3c952284f}\InProcServer32]
@="C:\WINDOWS\system32\sgntu.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{c27abdde-8a43-4a7f-81c0-3fc3c952284f}\InProcServer32]
@="C:\WINDOWS\system32\sgntu.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
C:\WINDOWS\system32\sgntu.dll -> Hoax.Win32.Renos.gen.o
C:\WINDOWS\system32\sgntu.dll -> Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
D:\DOCUME~1\ALLUSE~1\MENUDM~1\Antivirus Scan.url supprimé
D:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Spyware Test.url supprimé
D:\DOCUME~1\ALLUSE~1\Bureau\Antivirus Scan.url supprimé
D:\DOCUME~1\ALLUSE~1\Bureau\Online Spyware Test.url supprimé
D:\DOCUME~1\admi\Favoris\Antivirus Scan.url supprimé
C:\Program Files\AntiSpyCheck 2.1\ supprimé
C:\Program Files\Web Technologies\ supprimé
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
DNS Server Search Order: 208.67.220.220
DNS Server Search Order: 208.67.222.222
Description: Broadcom USB Remote NDIS Device - Miniport d'ordonnancement de paquets
DNS Server Search Order: 208.67.220.220
DNS Server Search Order: 208.67.222.222
Description: Broadcom USB Remote NDIS Device - Miniport d'ordonnancement de paquets
DNS Server Search Order: 208.67.220.220
DNS Server Search Order: 208.67.222.222
Description: Broadcom USB Remote NDIS Device - Miniport d'ordonnancement de paquets
DNS Server Search Order: 208.67.220.220
DNS Server Search Order: 208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{02841A57-DDB2-4D94-961E-1322440B0323}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{02841A57-DDB2-4D94-961E-1322440B0323}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{2A61E4C7-4DE2-4D3A-88B8-590F4B7353E0}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{2A61E4C7-4DE2-4D3A-88B8-590F4B7353E0}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{3CAC6358-B775-415F-BD1B-548C1A611B23}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{3CAC6358-B775-415F-BD1B-548C1A611B23}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{45DBFE95-AAFA-4387-B9E6-388E951732BC}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{45DBFE95-AAFA-4387-B9E6-388E951732BC}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{555D7EFC-3F45-4011-97FB-A809436C67AD}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CCS\Services\Tcpip\..\{555D7EFC-3F45-4011-97FB-A809436C67AD}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8448C906-80B3-4E50-B5E8-B49C011802B1}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8448C906-80B3-4E50-B5E8-B49C011802B1}: NameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS1\Services\Tcpip\..\{02841A57-DDB2-4D94-961E-1322440B0323}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{02841A57-DDB2-4D94-961E-1322440B0323}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{2A61E4C7-4DE2-4D3A-88B8-590F4B7353E0}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{2A61E4C7-4DE2-4D3A-88B8-590F4B7353E0}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3CAC6358-B775-415F-BD1B-548C1A611B23}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3CAC6358-B775-415F-BD1B-548C1A611B23}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{45DBFE95-AAFA-4387-B9E6-388E951732BC}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{45DBFE95-AAFA-4387-B9E6-388E951732BC}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{555D7EFC-3F45-4011-97FB-A809436C67AD}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS1\Services\Tcpip\..\{555D7EFC-3F45-4011-97FB-A809436C67AD}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8448C906-80B3-4E50-B5E8-B49C011802B1}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8448C906-80B3-4E50-B5E8-B49C011802B1}: NameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS3\Services\Tcpip\..\{02841A57-DDB2-4D94-961E-1322440B0323}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{02841A57-DDB2-4D94-961E-1322440B0323}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{2A61E4C7-4DE2-4D3A-88B8-590F4B7353E0}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{2A61E4C7-4DE2-4D3A-88B8-590F4B7353E0}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{3CAC6358-B775-415F-BD1B-548C1A611B23}: DhcpNameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{3CAC6358-B775-415F-BD1B-548C1A611B23}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{45DBFE95-AAFA-4387-B9E6-388E951732BC}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{45DBFE95-AAFA-4387-B9E6-388E951732BC}: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\..\{555D7EFC-3F45-4011-97FB-A809436C67AD}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS3\Services\Tcpip\..\{555D7EFC-3F45-4011-97FB-A809436C67AD}: NameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8448C906-80B3-4E50-B5E8-B49C011802B1}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8448C906-80B3-4E50-B5E8-B49C011802B1}: NameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8FEDED2D-763C-44CB-AEAA-5C9D637C4DDB}: DhcpNameServer=85.255.115.3,85.255.112.11
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=208.67.220.220,208.67.222.222
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin