Impossible d'installer un anti-virus

Résolu/Fermé
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 - 16 févr. 2008 à 12:43
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 - 20 août 2008 à 13:26
Bonjour,
J'ai depuis quelques temps un drôle de problème avec mon ordinateur: je ne peux absolument pas installer un anti-virus, peu importe lequel. Le pare feu windows et son anti virus, intégré à windows XP ont été désactivé...peut-être même désinstallé... et il est impossible de les réactiver.
Toues mes tentatives d'installation d'autres anti-virus, tels que Avast, AVG, même le WinCare Live... se sont soldées par un message d'erreur.
J'ai eu beau faire des nettoyages avec CClean régulièrement, même une analyse et nettoyage en ligne proposé gratuitement par Windows Live, ca ne change strictement rien.

est-ce que quelqu'un a déjà eu un problème dans le genre (quoique...j'ai tendance à faire dans l'original en ce qui concerne l'ordinateur)? Comment le régler?

Merci d'avance.
Poube!

PS : je ne travaille pas sur l'ordinateur en question en ce moment. (j'ai Window XP, j'utilise depuis le début IE7 ou sinon Fire fox, anti virus [quand je pouvais encore en avoir un] celui de Windows intégré, et Avast)

24 réponses

FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
16 févr. 2008 à 12:50
Salut,

N'aurais-tu pas téléchargé un crack récemment ?
* Télécharge Elibagla en bas de cette page sur ton Bureau. Pour cela, clique sur "Descargar Elibagla" : http://www.zonavirus.com/datos/descargas/95/elibagla.asp
* Lance-le de préférence en mode sans échec, ou en mode normal si le mode sans échec ne fonctionne pas.
* Bagle peut bloquer le mode sans échec, donc il ne faut absolument pas forcer le mode sans échec en passant par MSconfig. Cela peut provoquer un redémarrage en boucles du PC.
* Patiente pendant la durée du Scan.
* Copie-colle le contenu du rapport qui doit se trouver ici : C:\Infosat.txt
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
16 févr. 2008 à 12:54
Merci de répondre si vite... mais avant :
Deux petites questions...
Qu'est-ce que tu appelles par un crack (...oui je sais... pas douée!)
Comment lancer le mode sans échec (je vois ce que c'est...mais je ne l'ai jamais fait par moi même!)
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
16 févr. 2008 à 12:55
Re,

Un crack est un keygen ou une clé illégale permettant d'activer un logiciel payant. Beaucoup d'infections de type Bagle sont véhiculées par les cracks.

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
16 févr. 2008 à 13:00
Non, je n'ai pas utilisé de clef illégale! J'avoue avoir utilisé E-mule... est-ce que ça peut venir de là? ! J'ai souvent entendu qu'on pouvait se choper plein de virus de là?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
16 févr. 2008 à 13:03
Très certainement...
Peux-tu utiliser elibagla ?

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
24 févr. 2008 à 22:44
Me re-voilà!!

Je suis enfin en face de mon ordinateur et je viens de lancer Elibagla, en mode normal par contre. Voici le rapport:


Sun Feb 24 22:31:15 2008
EliBagle v11.04 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Eliminado Bagle
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\POUBE\APPLICATION DATA\HIDIRES\HIDR.EXE --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\POUBE\APPLICATION DATA\HIDIRES\M_HOOK.SYS --> Eliminado Bagle (rootkit)
Por favor, envienos una muestra del fichero
C:\Muestras\HIDR.EXE.Muestra EliBagle v11.04
a "virus@satinfo.es". Gracias.
C:\WINDOWS\SYSTEM32\DRIVERS\HIDR.EXE --> Eliminado Bagle
Por favor, envienos una muestra del fichero
C:\Muestras\SROSA.SYS.Muestra EliBagle v11.04
a "virus@satinfo.es". Gracias.
C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Eliminado Bagle
C:\WINDOWS\SYSTEM32\HLDRRR.EXE --> Eliminado Bagle.dldr
C:\DOCUMENTS AND SETTINGS\POUBE\APPLICATION DATA\M\FLEC006.EXE --> Eliminado Bagle.dldr
C:\DOCUMENTS AND SETTINGS\POUBE\APPLICATION DATA\M\LIST.OCT --> Eliminado Bagle
Eliminada Carpeta "%WinDir%\exefld"
Restaurada Clave: "SafeBoot\Minimal y Network"

Sun Feb 24 22:32:54 2008
EliBagle v11.04 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\

Nº Total de Directorios: 613
Nº Total de Ficheros: 2092
Nº de Ficheros Analizados: 9
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Exploración Detenida por el Usuario.

Sun Feb 24 22:33:30 2008
EliBagle v11.04 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\

Nº Total de Directorios: 5057
Nº Total de Ficheros: 75363
Nº de Ficheros Analizados: 8893
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
16 févr. 2008 à 14:02
PAs aujourd'hui, car je ne travaille pas sur l'ordi en question avant la semaine prochaine... (il y a 65km qui nous sépare!)!! mais j'essayerais dès que j'y retourne et je poste le rapport, comme tu me l'as demandé.
Je te tiens au courant!

Encore merci de répondre si rapidement!! C'est gentil ^^
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
24 févr. 2008 à 22:52
Salut,

C'est une version infectieuse plus ancienne et moins accrocheuse que celles qui circulent actuellement.

1/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download

Ouvre Ccleaner, clique sur "lancer le nettoyage".

2/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
Tu l'installes.
Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.

Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

3/ * Fais un scan en ligne en cliquant ici : http://assiste.com.free.fr/...
* Choisis Kaspersky.
* Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
* Réalise un scan complet du système.
* Sauvegarde le rapport en mode texte à l'issue du scan.

4/ Peux-tu éditer également un rapport Hijackthis ?
http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exe
Démo en image
http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm


Fais un scan et poste l'analyse.

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
24 févr. 2008 à 23:27
Le problème c'est que je bloque dès l'installation d'AVG, avec un message d'erreur:

capture d'écran : https://i27.servimg.com/u/f27/09/03/63/59/erreur10.jpg

c'est le même qui revient à chaque fois que je veux installer un anti virus ou autre dans le genre! Je choisis en général, l'option 'abandonner'... ne sachant pas ce que les deux autres feront!

Autre petite question : est-ce que le fait qu'aucune mise à jour ne me soit proposée, a aussi un lien avec ça? car j'ai normalement la mise à jour automatique, et ca fait un moment que je n'ai rien eu. De plus, la mise à jour de Windows Media Player m'a été refusée tout à l'heure!!!

Pfiou... ca en fait des problèmes!!!
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
26 févr. 2008 à 11:43
Bonjour!

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 25, 2008 8:26:59 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/02/2008
Kaspersky Anti-Virus database records: 580051
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 70859
Number of viruses found: 10
Number of infected objects: 1790
Number of suspicious objects: 0
Duration of the scan process: 01:23:23

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\(infantes)VERDIALES.SAN.CAYETANO.05.1º.PREMIO.PANDA.PTO..TORRE..50PTOS.zip/(infantes)VERDIALES.SAN.CAYETANO.05.1-¦.PREMIO.PANDA.PTO..TORRE..50PTOS.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\(infantes)VERDIALES.SAN.CAYETANO.05.1º.PREMIO.PANDA.PTO..TORRE..50PTOS.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\123 Click'n'Submit Softwares 1.2.zip/123 Click'n'Submit Softwares 1.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\123 Click'n'Submit Softwares 1.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Mail Sender 2.61.zip/1st Mail Sender 2.61.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Mail Sender 2.61.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Security Agent 6.5.zip/1st Security Agent 6.5.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Security Agent 6.5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Subscription Manager 2.2.zip/1st Subscription Manager 2.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Subscription Manager 2.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2.Avp.Kaspersky.Antivirus.4.5.Kav.Keyfiles.(26-10-2007).zip/2.Avp.Kaspersky.Antivirus.4.5.Kav.Keyfiles.(26-10-2007).exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2.Avp.Kaspersky.Antivirus.4.5.Kav.Keyfiles.(26-10-2007).zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_(Full.Version).Symantec.Livestate.Recovery.Advanced.Server.Suite.6.0.zip/2_(Full.Version).Symantec.Livestate.Recovery.Advanced.Server.Suite.6.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_(Full.Version).Symantec.Livestate.Recovery.Advanced.Server.Suite.6.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_antivirus.kaspersky.avp.personal.pro.v4.5.0.58.spanish.+.key.hasta.2007.by.cajai.zip/2_antivirus.kaspersky.avp.personal.pro.v4.5.0.58.spanish.+.key.hasta.2007.by.cajai.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_antivirus.kaspersky.avp.personal.pro.v4.5.0.58.spanish.+.key.hasta.2007.by.cajai.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_F-Prot.AntiVirus.v3.16d.Retail-ZWT.zip/2_F-Prot.AntiVirus.v3.16d.Retail-ZWT.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_F-Prot.AntiVirus.v3.16d.Retail-ZWT.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Atlantis, the Lost Continent Screensaver 2.0.zip/3D Atlantis, the Lost Continent Screensaver 2.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Atlantis, the Lost Continent Screensaver 2.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Cupid 3.0.zip/3D Dancing Cupid 3.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Cupid 3.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Ground Hog 1.0.zip/3D Dancing Ground Hog 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Ground Hog 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 1.0.zip/3D Fireworks by the Bay 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 2.1.zip/3D Fireworks by the Bay 2.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 2.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Magic Christmas Toy Shop 2.zip/3D Magic Christmas Toy Shop 2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Magic Christmas Toy Shop 2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Rocky Reef 3.0.zip/3D Rocky Reef 3.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Rocky Reef 3.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DMark 3.4.zip/3DMark 3.4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DMark 3.4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DWorlds 3.6 Build 557.zip/3DWorlds 3.6 Build 557.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DWorlds 3.6 Build 557.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4800bps speech codec SDK 1.0.zip/4800bps speech codec SDK 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4800bps speech codec SDK 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4WomenOnly 5.2.zip/4WomenOnly 5.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4WomenOnly 5.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4x4 Evolution patch (build 56 to build 57).zip/4x4 Evolution patch (build 56 to build 57).exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4x4 Evolution patch (build 56 to build 57).zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A Legal Good Time 1.0.1.zip/A Legal Good Time 1.0.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A Legal Good Time 1.0.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A&G Grapher 5.51.zip/A&G Grapher 5.51.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A&G Grapher 5.51.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A3D Viewer 1.0.zip/A3D Viewer 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A3D Viewer 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A7 Active Protection 3.20.zip/A7 Active Protection 3.20.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A7 Active Protection 3.20.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A9Converter Pro 1.0.4.zip/A9Converter Pro 1.0.4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A9Converter Pro 1.0.4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aardvark Desktop Creator 1.zip/Aardvark Desktop Creator 1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aardvark Desktop Creator 1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Abilities Builder Divide Whole Numbers 6.1.zip/Abilities Builder Divide Whole Numbers 6.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Abilities Builder Divide Whole Numbers 6.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ABViewer 5.2.5.125.zip/ABViewer 5.2.5.125.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ABViewer 5.2.5.125.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accio German-English Dictionary (Win) 1.0.3.zip/Accio German-English Dictionary (Win) 1.0.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accio German-English Dictionary (Win) 1.0.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accurate Network Monitor 1.31.zip/Accurate Network Monitor 1.31.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accurate Network Monitor 1.31.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACDSee 1.6.zip/ACDSee 1.6.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACDSee 1.6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Explorer 2.zip/Ace Explorer 2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Explorer 2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Password Guard 3.61a.zip/Ace Password Guard 3.61a.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Password Guard 3.61a.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AceReader Pro Deluxe 4.5.zip/AceReader Pro Deluxe 4.5.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AceReader Pro Deluxe 4.5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Action Is.zip/Action Is.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Action Is.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActivatorDesk (Blogger-Dot-Kids) 6.0.0.16.zip/ActivatorDesk (Blogger-Dot-Kids) 6.0.0.16.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActivatorDesk (Blogger-Dot-Kids) 6.0.0.16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active SMART 2.42 build 4.zip/Active SMART 2.42 build 4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active SMART 2.42 build 4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active Uneraser 3.zip/Active Uneraser 3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active Uneraser 3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActiveID 1.2.zip/ActiveID 1.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActiveID 1.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACTUALIZACION.22-02-05.PANDA.PLATINUM.INTERNET.SECURITY.05.(PAV.SIG).EN.LANZAMIENTO!!!.zip/ACTUALIZACION.22-02-05.PANDA.PLATINUM.INTERNET.SECURITY.05.(PAV.SIG).EN.LANZAMIENTO!!!.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACTUALIZACION.22-02-05.PANDA.PLATINUM.INTERNET.SECURITY.05.(PAV.SIG).EN.LANZAMIENTO!!!.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Address Harvester 1.1.0.131.zip/Address Harvester 1.1.0.131.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Address Harvester 1.1.0.131.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Acrobat 5.0.5 Update 1.0.zip/Adobe Acrobat 5.0.5 Update 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Acrobat 5.0.5 Update 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe After Effects 7.zip/Adobe After Effects 7.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe After Effects 7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Illustrator Update 9.0.2.zip/Adobe Illustrator Update 9.0.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Illustrator Update 9.0.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Advanced Virtual COM Port 2.3.zip/Advanced Virtual COM Port 2.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Advanced Virtual COM Port 2.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AdvaPlay 2.0.zip/AdvaPlay 2.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AdvaPlay 2.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AgataSoft KilX 1.4.zip/AgataSoft KilX 1.4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AgataSoft KilX 1.4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AGDL 5 Bhoomika Chawla Wallpapers 1.zip/AGDL 5 Bhoomika Chawla Wallpapers 1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AGDL 5 Bhoomika Chawla Wallpapers 1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Do You Like Hide and Seek map.zip/Age of Mythology - Do You Like Hide and Seek map.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Do You Like Hide and Seek map.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Team Arena map.zip/Age of Mythology - Team Arena map.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Team Arena map.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - The Battle for Middle Earth scenario.zip/Age of Mythology - The Battle for Middle Earth scenario.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - The Battle for Middle Earth scenario.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology retail patch 1.06.zip/Age of Mythology retail patch 1.06.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology retail patch 1.06.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology The Titans Ra's Citadel map.zip/Age of Mythology The Titans Ra's Citadel map.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology The Titans Ra's Citadel map.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AhsayOBS (Mac platform) 5.1.08.zip/AhsayOBS (Mac platform) 5.1.08.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AhsayOBS (Mac platform) 5.1.08.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AILoader 7.zip/AILoader 7.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AILoader 7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AjmZip Manager 1.7.zip/AjmZip Manager 1.7.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AjmZip Manager 1.7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Alarm Clock Pro 7.8.6.zip/Alarm Clock Pro 7.8.6.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Alarm Clock Pro 7.8.6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Algebra Cheat 2 - Solving Equations 1.0.1.zip/Algebra Cheat 2 - Solving Equations 1.0.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Algebra Cheat 2 - Solving Equations 1.0.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AlgoLab Raster to Vector Conversion SDK 2.55.zip/AlgoLab Raster to Vector Conversion SDK 2.55.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AlgoLab Raster to Vector Conversion SDK 2.55.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\All-in-One Media Player 2.3.7.zip/All-in-One Media Player 2.3.7.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\All-in-One Media Player 2.3.7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AllChars 3.6.2.zip/AllChars 3.6.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AllChars 3.6.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Allgood Solitaire 3.2.zip/Allgood Solitaire 3.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Allgood Solitaire 3.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AllToTray 4.6.3.zip/AllToTray 4.6.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AllToTray 4.6.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ALO RM to MP3 Converter 3.3.zip/ALO RM to MP3 Converter 3.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ALO RM to MP3 Converter 3.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Alpha Blast 1.0.zip/Alpha Blast 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Alpha Blast 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AlphaPlugins FirTree for After Effects 1.01.zip/AlphaPlugins FirTree for After Effects 1.01.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AlphaPlugins FirTree for After Effects 1.01.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amazing Mahjongg CE 1.3.zip/Amazing Mahjongg CE 1.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amazing Mahjongg CE 1.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amazon PriceWatcher 2.zip/Amazon PriceWatcher 2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amazon PriceWatcher 2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AMCap 9.08 build 74.3.zip/AMCap 9.08 build 74.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AMCap 9.08 build 74.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\America's Army Operations 1.2 to 1.21 patch.zip/America's Army Operations 1.2 to 1.21 patch.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\America's Army Operations 1.2 to 1.21 patch.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amiglobe 2005 1.1.zip/Amiglobe 2005 1.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amiglobe 2005 1.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amoebic 1.0.zip/Amoebic 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amoebic 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AmphiSoft Plug-ins 1.2.zip/AmphiSoft Plug-ins 1.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AmphiSoft Plug-ins 1.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amplitube Live 1.0.3.zip/Amplitube Live 1.0.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Amplitube Live 1.0.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Antechinus PHP Editor 2.2 build 5.zip/Antechinus PHP Editor 2.2 build 5.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Antechinus PHP Editor 2.2 build 5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Antivirus.Mcafee.Viruscan.8.0i.Enterprise.Fr.Complet.zip/Antivirus.Mcafee.Viruscan.8.0i.Enterprise.Fr.Complet.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Antivirus.Mcafee.Viruscan.8.0i.Enterprise.Fr.Complet.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Antivirus.Norman.Internet.Control.v5.70.r1.zip/Antivirus.Norman.Internet.Control.v5.70.r1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Antivirus.Norman.Internet.Control.v5.70.r1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\antivirus.Panda.Titanium.2006.Antivirus.+.Antispy.updated-fixed.Release.12-2006.zip/antivirus.Panda.Titanium.2006.Antivirus.+.Antispy.updated-fixed.Release.12-2006.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\antivirus.Panda.Titanium.2006.Antivirus.+.Antispy.updated-fixed.Release.12-2006.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Apex PowerPoint Screensaver Maker Professional Plus 2.0.2.zip/Apex PowerPoint Screensaver Maker Professional Plus 2.0.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Apex PowerPoint Screensaver Maker Professional Plus 2.0.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Apple Mac OS ROM Update 1.0.zip/Apple Mac OS ROM Update 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Apple Mac OS ROM Update 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Apple Mac OS Update 8.1.zip/Apple Mac OS Update 8.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Apple Mac OS Update 8.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AppPanel Enterprise Edition 2.2.zip/AppPanel Enterprise Edition 2.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AppPanel Enterprise Edition 2.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AquaCrypt 1.0b.zip/AquaCrypt 1.0b.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AquaCrypt 1.0b.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aquanox 112 to 114 English patch.zip/Aquanox 112 to 114 English patch.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aquanox 112 to 114 English patch.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ares Galaxy Turbo Booster 4.7.1.zip/Ares Galaxy Turbo Booster 4.7.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ares Galaxy Turbo Booster 4.7.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Arial Audio Converter 2.3.36.zip/Arial Audio Converter 2.3.36.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Arial Audio Converter 2.3.36.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aros Magic Go-Moku 1.zip/Aros Magic Go-Moku 1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aros Magic Go-Moku 1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Art Revolution 9 Sea Sunset Screensaver 4.03.zip/Art Revolution 9 Sea Sunset Screensaver 4.03.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Art Revolution 9 Sea Sunset Screensaver 4.03.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ashampoo Utilities 1.03.zip/Ashampoo Utilities 1.03.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ashampoo Utilities 1.03.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Asset Tracking System 4.0.zip/Asset Tracking System 4.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Asset Tracking System 4.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AssetWorX 2.1.zip/AssetWorX 2.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AssetWorX 2.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Astaro Security Linux 5.01.zip/Astaro Security Linux 5.01.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Astaro Security Linux 5.01.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Astral Arrows 1.1.zip/Astral Arrows 1.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Astral Arrows 1.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ATITool 0.24.zip/ATITool 0.24.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ATITool 0.24.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Atomic Time Zone - Server Edition 5.1.1.zip/Atomic Time Zone - Server Edition 5.1.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Atomic Time Zone - Server Edition 5.1.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Attribute Manager 2.35.zip/Attribute Manager 2.35.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Attribute Manager 2.35.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Audiolib MP3 CD Burner 1.0.zip/Audiolib MP3 CD Burner 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Audiolib MP3 CD Burner 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AutoDWG DWG to PDF Converter 3.110.zip/AutoDWG DWG to PDF Converter 3.110.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AutoDWG DWG to PDF Converter 3.110.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Autorun Creator 1.zip/Autorun Creator 1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Autorun Creator 1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AutoSave 2.2.zip/AutoSave 2.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AutoSave 2.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\avast!.virus.cleaner.v.1.0.209.ssepe.zip/avast!.virus.cleaner.v.1.0.209.ssepe.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\avast!.virus.cleaner.v.1.0.209.ssepe.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\avast!4HomeEditionPL[4.7.892](Vega)[oslozone.be].zip/avast!4HomeEditionPL[4.7.892](Vega)[oslozone.be].exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\avast!4HomeEditionPL[4.7.892](Vega)[oslozone.be].zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Avast.2006.Antivirus.Freeware.Italiano.zip/Avast.2006.Antivirus.Freeware.Italiano.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Avast.2006.Antivirus.Freeware.Italiano.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Avast.antivirus.(free).zip/Avast.antivirus.(free).exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Avast.antivirus.(free).zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Avast.Antivirus.Pro.4.
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
26 févr. 2008 à 11:44
Bonjour!

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, February 25, 2008 8:26:59 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 25/02/2008
Kaspersky Anti-Virus database records: 580051
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 70859
Number of viruses found: 10
Number of infected objects: 1790
Number of suspicious objects: 0
Duration of the scan process: 01:23:23

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\(infantes)VERDIALES.SAN.CAYETANO.05.1º.PREMIO.PANDA.PTO..TORRE..50PTOS.zip/(infantes)VERDIALES.SAN.CAYETANO.05.1-¦.PREMIO.PANDA.PTO..TORRE..50PTOS.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\(infantes)VERDIALES.SAN.CAYETANO.05.1º.PREMIO.PANDA.PTO..TORRE..50PTOS.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\123 Click'n'Submit Softwares 1.2.zip/123 Click'n'Submit Softwares 1.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\123 Click'n'Submit Softwares 1.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Mail Sender 2.61.zip/1st Mail Sender 2.61.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Mail Sender 2.61.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Security Agent 6.5.zip/1st Security Agent 6.5.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Security Agent 6.5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Subscription Manager 2.2.zip/1st Subscription Manager 2.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\1st Subscription Manager 2.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2.Avp.Kaspersky.Antivirus.4.5.Kav.Keyfiles.(26-10-2007).zip/2.Avp.Kaspersky.Antivirus.4.5.Kav.Keyfiles.(26-10-2007).exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2.Avp.Kaspersky.Antivirus.4.5.Kav.Keyfiles.(26-10-2007).zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_(Full.Version).Symantec.Livestate.Recovery.Advanced.Server.Suite.6.0.zip/2_(Full.Version).Symantec.Livestate.Recovery.Advanced.Server.Suite.6.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_(Full.Version).Symantec.Livestate.Recovery.Advanced.Server.Suite.6.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_antivirus.kaspersky.avp.personal.pro.v4.5.0.58.spanish.+.key.hasta.2007.by.cajai.zip/2_antivirus.kaspersky.avp.personal.pro.v4.5.0.58.spanish.+.key.hasta.2007.by.cajai.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_antivirus.kaspersky.avp.personal.pro.v4.5.0.58.spanish.+.key.hasta.2007.by.cajai.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_F-Prot.AntiVirus.v3.16d.Retail-ZWT.zip/2_F-Prot.AntiVirus.v3.16d.Retail-ZWT.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\2_F-Prot.AntiVirus.v3.16d.Retail-ZWT.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Atlantis, the Lost Continent Screensaver 2.0.zip/3D Atlantis, the Lost Continent Screensaver 2.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Atlantis, the Lost Continent Screensaver 2.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Cupid 3.0.zip/3D Dancing Cupid 3.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Cupid 3.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Ground Hog 1.0.zip/3D Dancing Ground Hog 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Dancing Ground Hog 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 1.0.zip/3D Fireworks by the Bay 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 2.1.zip/3D Fireworks by the Bay 2.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Fireworks by the Bay 2.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Magic Christmas Toy Shop 2.zip/3D Magic Christmas Toy Shop 2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Magic Christmas Toy Shop 2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Rocky Reef 3.0.zip/3D Rocky Reef 3.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3D Rocky Reef 3.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DMark 3.4.zip/3DMark 3.4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DMark 3.4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DWorlds 3.6 Build 557.zip/3DWorlds 3.6 Build 557.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\3DWorlds 3.6 Build 557.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4800bps speech codec SDK 1.0.zip/4800bps speech codec SDK 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4800bps speech codec SDK 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4WomenOnly 5.2.zip/4WomenOnly 5.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4WomenOnly 5.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4x4 Evolution patch (build 56 to build 57).zip/4x4 Evolution patch (build 56 to build 57).exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\4x4 Evolution patch (build 56 to build 57).zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A Legal Good Time 1.0.1.zip/A Legal Good Time 1.0.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A Legal Good Time 1.0.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A&G Grapher 5.51.zip/A&G Grapher 5.51.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A&G Grapher 5.51.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A3D Viewer 1.0.zip/A3D Viewer 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A3D Viewer 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A7 Active Protection 3.20.zip/A7 Active Protection 3.20.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A7 Active Protection 3.20.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A9Converter Pro 1.0.4.zip/A9Converter Pro 1.0.4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\A9Converter Pro 1.0.4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aardvark Desktop Creator 1.zip/Aardvark Desktop Creator 1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Aardvark Desktop Creator 1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Abilities Builder Divide Whole Numbers 6.1.zip/Abilities Builder Divide Whole Numbers 6.1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Abilities Builder Divide Whole Numbers 6.1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ABViewer 5.2.5.125.zip/ABViewer 5.2.5.125.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ABViewer 5.2.5.125.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accio German-English Dictionary (Win) 1.0.3.zip/Accio German-English Dictionary (Win) 1.0.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accio German-English Dictionary (Win) 1.0.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accurate Network Monitor 1.31.zip/Accurate Network Monitor 1.31.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Accurate Network Monitor 1.31.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACDSee 1.6.zip/ACDSee 1.6.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACDSee 1.6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Explorer 2.zip/Ace Explorer 2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Explorer 2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Password Guard 3.61a.zip/Ace Password Guard 3.61a.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Ace Password Guard 3.61a.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AceReader Pro Deluxe 4.5.zip/AceReader Pro Deluxe 4.5.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AceReader Pro Deluxe 4.5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Action Is.zip/Action Is.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Action Is.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActivatorDesk (Blogger-Dot-Kids) 6.0.0.16.zip/ActivatorDesk (Blogger-Dot-Kids) 6.0.0.16.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActivatorDesk (Blogger-Dot-Kids) 6.0.0.16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active SMART 2.42 build 4.zip/Active SMART 2.42 build 4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active SMART 2.42 build 4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active Uneraser 3.zip/Active Uneraser 3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Active Uneraser 3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActiveID 1.2.zip/ActiveID 1.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ActiveID 1.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACTUALIZACION.22-02-05.PANDA.PLATINUM.INTERNET.SECURITY.05.(PAV.SIG).EN.LANZAMIENTO!!!.zip/ACTUALIZACION.22-02-05.PANDA.PLATINUM.INTERNET.SECURITY.05.(PAV.SIG).EN.LANZAMIENTO!!!.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\ACTUALIZACION.22-02-05.PANDA.PLATINUM.INTERNET.SECURITY.05.(PAV.SIG).EN.LANZAMIENTO!!!.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Address Harvester 1.1.0.131.zip/Address Harvester 1.1.0.131.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Address Harvester 1.1.0.131.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Acrobat 5.0.5 Update 1.0.zip/Adobe Acrobat 5.0.5 Update 1.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Acrobat 5.0.5 Update 1.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe After Effects 7.zip/Adobe After Effects 7.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe After Effects 7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Illustrator Update 9.0.2.zip/Adobe Illustrator Update 9.0.2.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Adobe Illustrator Update 9.0.2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Advanced Virtual COM Port 2.3.zip/Advanced Virtual COM Port 2.3.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Advanced Virtual COM Port 2.3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AdvaPlay 2.0.zip/AdvaPlay 2.0.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AdvaPlay 2.0.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AgataSoft KilX 1.4.zip/AgataSoft KilX 1.4.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AgataSoft KilX 1.4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AGDL 5 Bhoomika Chawla Wallpapers 1.zip/AGDL 5 Bhoomika Chawla Wallpapers 1.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\AGDL 5 Bhoomika Chawla Wallpapers 1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Do You Like Hide and Seek map.zip/Age of Mythology - Do You Like Hide and Seek map.exe Infected: Trojan-Downloader.Win32.Bagle.cr skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Do You Like Hide and Seek map.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Perrine Henninger\Application Data\m\shared\Age of Mythology - Team Arena map.zip/Age of Mythology - Team Arena map.exe
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
25 févr. 2008 à 08:56
Bonjour,

1/
* Télécharge combofix.exe (par sUBs) sur ton Bureau : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Renomme-le à l'enregistrement en machin.exe
* Double clique machin.exe et suis les invites.
* Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

2/ * Télécharge PCA (d'Evosla) : http://ww25.evosla.com/pca_cpt.php?agr=pca_securite
* Dézippe-le dans un répertoire dédié comme c:\PCA au moyen d'un clic droit (Extraire...),
* Clique sur l'onglet "diagnostic du PC" puis "analyser".
* Laisse l'analyse se dérouler. Cela ne prend que quelques secondes.
* Clique sur "enregistrer le rapport" en bas à droite et sauvegarde-le sur le bureau.
* Edite le contenu de ce rapport dans ta prochaine réponse. Il se nomme PCA_LOG.txt

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
25 févr. 2008 à 10:48
Salut,

Il n'y a rien qui se passe, lorsque je lance Combofix (ou si gentillement appelé machin.exe !!! ;p) Il se contente de m'afficher une fenêtre toute bleue sans rien faire de plus!!
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
25 févr. 2008 à 10:54
Salut,

1/ * Télécharge DiagHelp.zip sur ton bureau(Merci Malekal) : http://www.malekal.com/download/DiagHelp.zip
Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
* Ne double-clique pas dessus !! Fais un clic droit sur le fichier et extraire tout.
* Un nouveau dossier chercher va être créé.
* Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
* Une fenêtre va s'ouvrir, choisis l'option 1
* L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.
* Pendant l'analyse après le rapport CATCHME sur l'écran rouge, tu dois appuyer sue entrée pour que l'outil continue ses recherches. Suis les consignes écrites.
* Une fenêtre avec le rapport s'ouvre alors. Copie/colle son contenu. (Il se trouve aussi ici : c:\resultat.txt)
* Double-clique sur ce fichier, Fais CTRL+A puis CTRL+C.
* Dans ta prochaine réponse, colle le rapport en faisant CTRL+V.

2/ # Télécharge SREng (de Smallfrogs) : http://www.kztechs.com/eng/download.html
# Dézippe tout son contenu sur ton bureau (clic droit >Extraire ici).
# Ouvre le dossier SReng2 et double-clique sur SREngPS.exe.
# Clique sur "smart scan".
# Clique sur le bouton "scan".
# Quand l'analyse est terminée, clique sur le bouton "save reports".
# Sauvegarde alors le rapport sur ton bureau.
# Copie/colle le contenu du rapport SREnglLOG.log dans ta prochaine réponse.

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
25 févr. 2008 à 12:54
C'est quand même dingue de voir quelqu'un qui peut avoir une réponse à tout!! encore merci!

Bon, je n'en suis pour l'instant qu'au point 1... le rapport CATCHME sur écran rouge c'est effectué rapidement, sans qu'on ne me demande rien du tout : redémarrage de l'ordinateur tout seul, sans qu'on m'avertisse !! J'ai quand même cherché et copié le rapport, le voici :

DiagHelp version v1.4 - http://www.malekal.com
excute le 25/02/2008 à 12:35:57,82


Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->25/02/2008 12:35:29
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->25/02/2008 12:35:20
C:\WINDOWS\prefetch\VERCLSID.EXE-3667BD89.pf -->25/02/2008 12:33:24
C:\WINDOWS\prefetch\IZARC.EXE-2B73BBEB.pf -->25/02/2008 12:32:57
C:\WINDOWS\prefetch\RPHELPERAPP.EXE-33CB172B.pf -->25/02/2008 12:29:55
C:\WINDOWS\prefetch\MSNTBUP.EXE-0D913FB9.pf -->25/02/2008 12:25:04
C:\WINDOWS\prefetch\WLMAIL.EXE-16F261CF.pf -->25/02/2008 12:13:23
C:\WINDOWS\prefetch\WLLOGINPROXY.EXE-2D4B6027.pf -->25/02/2008 11:36:32
C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->25/02/2008 11:35:24
C:\WINDOWS\prefetch\REALONEMESSAGECENTER.EXE-1B5B11B5.pf -->25/02/2008 11:20:45

C:\WINDOWS\System32\drivers\aswmon.sys -->06/09/2007 11:05:25
C:\WINDOWS\System32\drivers\aswmon2.sys -->06/09/2007 11:05:10
C:\WINDOWS\System32\drivers\aswRdr.sys -->06/09/2007 11:03:02
C:\WINDOWS\System32\drivers\aswTdi.sys -->06/09/2007 11:02:20
C:\WINDOWS\System32\drivers\aavmker4.sys -->06/09/2007 11:00:53
C:\WINDOWS\System32\drivers\PxHelp20.sys -->27/07/2007 00:06:18
C:\WINDOWS\System32\drivers\cdralw2k.sys -->27/03/2007 08:55:32

C:\WINDOWS\System32\wpa.dbl -->24/02/2008 22:18:12
C:\WINDOWS\System32\jupdate-1.6.0_03-b05.log -->15/02/2008 08:25:31
C:\WINDOWS\System32\PerfStringBackup.INI -->04/02/2008 20:13:59
C:\WINDOWS\System32\perfh00C.dat -->04/02/2008 20:13:59
C:\WINDOWS\System32\perfh009.dat -->04/02/2008 20:13:59
C:\WINDOWS\System32\perfc00C.dat -->04/02/2008 20:13:59
C:\WINDOWS\System32\perfc009.dat -->04/02/2008 20:13:59
C:\WINDOWS\System32\FNTCACHE.DAT -->21/01/2008 01:12:33
C:\WINDOWS\System32\dsm_fr.qm -->09/01/2008 12:18:18
C:\WINDOWS\System32\divxsm.tlb -->09/01/2008 12:18:18
C:\WINDOWS\System32\DivXsm.exe -->09/01/2008 12:18:18
C:\WINDOWS\System32\qt-dx331.dll -->09/01/2008 12:18:12
C:\WINDOWS\System32\ssldivx.dll -->09/01/2008 12:18:00
C:\WINDOWS\System32\libdivx.dll -->09/01/2008 12:18:00
C:\WINDOWS\System32\dtu100.dll.manifest -->09/01/2008 12:16:10
C:\WINDOWS\System32\dtu100.dll -->09/01/2008 12:16:10
C:\WINDOWS\System32\dpl100.dll.manifest -->09/01/2008 12:16:10
C:\WINDOWS\System32\dpl100.dll -->09/01/2008 12:16:10
C:\WINDOWS\System32\divx_xx11.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\divx_xx0c.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\divx_xx07.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\DivX.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\divxdec.ax -->09/01/2008 12:15:58
C:\WINDOWS\System32\dpuGUI10.dll -->11/12/2007 20:44:22
C:\WINDOWS\System32\dpv11.dll -->11/12/2007 20:44:20

C:\WINDOWS\WindowsUpdate.log -->25/02/2008 12:25:04
C:\WINDOWS\NeroDigital.ini -->25/02/2008 11:54:15
C:\WINDOWS\wiadebug.log -->25/02/2008 09:00:07
C:\WINDOWS\SchedLgU.Txt -->25/02/2008 00:25:03
C:\WINDOWS\wiaservc.log -->24/02/2008 19:35:04
C:\WINDOWS\bootstat.dat -->24/02/2008 19:34:51
C:\WINDOWS\QTFont.qfn -->28/01/2008 13:33:22
C:\WINDOWS\QTFont.for -->28/01/2008 13:33:22
C:\WINDOWS\RRR2_Screensaver.ini -->10/12/2007 16:15:59
C:\WINDOWS\_delis32.ini -->18/10/2007 18:19:58
C:\WINDOWS\RRR2_Screensaver.scr -->11/10/2007 17:15:06
C:\WINDOWS\bubbloids.scr -->10/10/2007 14:48:57
C:\WINDOWS\brassi.dat -->10/10/2007 14:48:57
C:\WINDOWS\comet.scr -->10/10/2007 14:46:52
C:\WINDOWS\cdplayer.ini -->02/10/2007 18:15:11

winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed


ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com

------------------------------------------------------------------------------
explorer.exe pid: 1484
Command line: C:\WINDOWS\Explorer.EXE

Base Size Version Path
0x44080000 0xcf000 7.00.6000.16441 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x43e00000 0x45000 7.00.6000.16441 C:\WINDOWS\system32\iertutil.dll
0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x10000000 0x64000 1.00.0000.0004 C:\Program Files\SmartFTP Client\sfShellTools.dll
0x13420000 0x1a000 11.00.5721.5145 C:\PROGRA~1\WINDOW~2\wmpband.dll
0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
0x44360000 0x5ca000 7.00.6000.16441 C:\WINDOWS\system32\ieframe.dll
0x44160000 0x124000 7.00.6000.16441 C:\WINDOWS\system32\urlmon.dll
0x01820000 0x2c6000 3.01.4000.2435 C:\WINDOWS\system32\msi.dll
0x442b0000 0x3c000 7.00.6000.16441 C:\WINDOWS\system32\webcheck.dll
0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
0x029b0000 0x26000 1.00.0002.0002 C:\Program Files\SmartFTP Client\smarthook.dll
0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x036a0000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x03b50000 0x4c000 8.00.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
0x15110000 0x25a000 11.00.5721.5145 C:\WINDOWS\system32\wmvcore.dll
0x11c70000 0x39000 11.00.5721.5145 C:\WINDOWS\system32\WMASF.DLL
0x78130000 0x9b000 8.00.50727.0163 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.163_x-ww_681e29fb\MSVCR80.dll
0x04020000 0x5b000 8.01.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
0x05b80000 0x220000 1.02.0002.2288 C:\Program Files\Fichiers communs\Ahead\Lib\AdvrCntr.dll
0x04440000 0x3c000 3.04.0000.0000 C:\WINDOWS\system32\l3codecp.acm
0x1ff00000 0x7e000 6.04.0009.1133 C:\WINDOWS\system32\dxmasf.dll
0x042a0000 0x4f000 9.00.0000.3250 C:\WINDOWS\system32\DRMClien.DLL
0x047e0000 0x9d000 C:\PROGRA~1\IZArc\IZArcCM.dll
0x64f00000 0x12000 4.07.1043.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
0x015f0000 0x10000 8.00.0000.0456 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
0x037c0000 0x5b000 1.01.0000.0000 C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com

------------------------------------------------------------------------------
winlogon.exe pid: 612
Command line: winlogon.exe

Base Size Version Path
0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe
0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x011d0000 0x3b000 1.07.0018.0005 C:\WINDOWS\system32\WgaLogon.dll
0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL


Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 7484-AC27

Répertoire de C:\WINDOWS\system32

19/08/2004 16:09 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 67 009 019 904 octets libres

Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 7484-AC27

Répertoire de C:\WINDOWS\Downloaded Program Files

28/01/2008 11:51 <REP> .
28/01/2008 11:51 <REP> ..
14/02/2007 18:55 65 desktop.ini
25/07/2002 17:13 24 576 dwusplay.dll
25/07/2002 17:13 196 608 dwusplay.exe
24/11/2007 21:24 378 ImageUploader4.inf
24/11/2007 21:24 2 684 432 ImageUploader4.ocx
11/04/2006 12:06 322 IPSUploader.inf
21/06/2006 10:32 1 939 056 IPSUploader.ocx
25/07/2002 17:05 172 032 isusweb.dll
14/03/2007 03:02 1 055 jinstall-6u1.inf
22/02/2007 23:41 304 544 MessengerStatsPAClient.dll
02/08/2007 11:31 360 320 MsnPUpld.dll
02/08/2007 15:47 569 MSNPUpld.inf
25/03/2003 11:09 1 558 msrdp.inf
24/03/2003 22:03 683 008 msrdp.ocx
02/08/2007 11:31 67 456 PURen-us.dll
06/08/2007 12:10 68 992 PURfr-fr.dll
04/12/2006 14:16 144 QTPlugin.inf
09/11/2006 14:36 5 019 swflash.inf
21/09/2007 09:37 465 472 wlscBase.dll
21/09/2007 09:40 320 wlscBase.inf
20 fichier(s) 6 975 926 octets

Total des fichiers listés :
20 fichier(s) 6 975 926 octets
2 Rép(s) 67 009 015 808 octets libres

Recherche de rootkit! (Merci S!Ri)

Recherche d'infections connues

Export des clefs sensibles..


Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\adslTV\\adsltv.exe"="C:\\Program Files\\adslTV\\adsltv.exe:*:Enabled:adsltv"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"



exports des policies
REGEDIT4

[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001



Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...



Bon c'est un peu du étape par étape chez moi...mais, étant donné qu'il y a eu redémarrage en plein milieu, je dois recommencer ou je peux passer à l'étape 2
(je suis d'une lenteur affollante!!)

PS : chose étonnante après redémarrage, mes mises à jours ont démarré!!! J'aime bien !! :p
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
25 févr. 2008 à 13:41
Re,

Le rapport Diaghelp n'est pas entier. Peux-tu recommencer ? Edite ensuite le rapport SREng.

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
25 févr. 2008 à 13:54
Idem : l'ordinateur redémarre avant la fin!
le rapport s'arrete au même endroit que le dernier : le voici

DiagHelp version v1.4 - http://www.malekal.com
excute le 25/02/2008 à 13:42:30,57


Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->25/02/2008 13:42:28
C:\WINDOWS\prefetch\VERCLSID.EXE-3667BD89.pf -->25/02/2008 13:42:21
C:\WINDOWS\prefetch\RPHELPERAPP.EXE-33CB172B.pf -->25/02/2008 13:40:01
C:\WINDOWS\prefetch\REALONEMESSAGECENTER.EXE-1B5B11B5.pf -->25/02/2008 13:32:43
C:\WINDOWS\prefetch\REALPLAY.EXE-1BF219BD.pf -->25/02/2008 13:32:22
C:\WINDOWS\prefetch\WLLOGINPROXY.EXE-2D4B6027.pf -->25/02/2008 13:31:04
C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->25/02/2008 13:30:54
C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->25/02/2008 13:25:59
C:\WINDOWS\prefetch\MSNTBUP.EXE-0D913FB9.pf -->25/02/2008 13:25:03
C:\WINDOWS\prefetch\WUAUCLT.EXE-399A8E72.pf -->25/02/2008 13:20:21

C:\WINDOWS\System32\drivers\mrxdav.sys -->18/12/2007 10:51:35
C:\WINDOWS\System32\drivers\secdrv.sys -->13/11/2007 11:25:54
C:\WINDOWS\System32\drivers\tcpip.sys -->30/10/2007 18:20:55
C:\WINDOWS\System32\drivers\aswmon.sys -->06/09/2007 11:05:25
C:\WINDOWS\System32\drivers\aswmon2.sys -->06/09/2007 11:05:10
C:\WINDOWS\System32\drivers\aswRdr.sys -->06/09/2007 11:03:02
C:\WINDOWS\System32\drivers\aswTdi.sys -->06/09/2007 11:02:20

C:\WINDOWS\System32\wpa.dbl -->25/02/2008 13:19:13
C:\WINDOWS\System32\perfh00C.dat -->25/02/2008 13:06:02
C:\WINDOWS\System32\perfh009.dat -->25/02/2008 13:06:02
C:\WINDOWS\System32\perfc00C.dat -->25/02/2008 13:06:02
C:\WINDOWS\System32\perfc009.dat -->25/02/2008 13:06:02
C:\WINDOWS\System32\PerfStringBackup.INI -->25/02/2008 13:06:01
C:\WINDOWS\System32\TZLog.log -->25/02/2008 13:00:44
C:\WINDOWS\System32\jupdate-1.6.0_03-b05.log -->15/02/2008 08:25:31
C:\WINDOWS\System32\MRT.exe -->04/02/2008 15:09:48
C:\WINDOWS\System32\FNTCACHE.DAT -->21/01/2008 01:12:33
C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 06:36:55
C:\WINDOWS\System32\dsm_fr.qm -->09/01/2008 12:18:18
C:\WINDOWS\System32\divxsm.tlb -->09/01/2008 12:18:18
C:\WINDOWS\System32\DivXsm.exe -->09/01/2008 12:18:18
C:\WINDOWS\System32\qt-dx331.dll -->09/01/2008 12:18:12
C:\WINDOWS\System32\ssldivx.dll -->09/01/2008 12:18:00
C:\WINDOWS\System32\libdivx.dll -->09/01/2008 12:18:00
C:\WINDOWS\System32\dtu100.dll.manifest -->09/01/2008 12:16:10
C:\WINDOWS\System32\dtu100.dll -->09/01/2008 12:16:10
C:\WINDOWS\System32\dpl100.dll.manifest -->09/01/2008 12:16:10
C:\WINDOWS\System32\dpl100.dll -->09/01/2008 12:16:10
C:\WINDOWS\System32\divx_xx11.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\divx_xx0c.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\divx_xx07.dll -->09/01/2008 12:16:02
C:\WINDOWS\System32\DivX.dll -->09/01/2008 12:16:02

C:\WINDOWS\0.log -->25/02/2008 13:18:59
C:\WINDOWS\WindowsUpdate.log -->25/02/2008 13:18:56
C:\WINDOWS\wiaservc.log -->25/02/2008 13:18:54
C:\WINDOWS\wiadebug.log -->25/02/2008 13:18:54
C:\WINDOWS\spupdsvc.log -->25/02/2008 13:18:53
C:\WINDOWS\bootstat.dat -->25/02/2008 13:18:39
C:\WINDOWS\SchedLgU.Txt -->25/02/2008 13:18:03
C:\WINDOWS\tsoc.log -->25/02/2008 13:16:12
C:\WINDOWS\setupapi.log -->25/02/2008 13:16:12
C:\WINDOWS\ocmsn.log -->25/02/2008 13:16:12
C:\WINDOWS\ocgen.log -->25/02/2008 13:16:12
C:\WINDOWS\ntdtcsetup.log -->25/02/2008 13:16:12
C:\WINDOWS\msgsocm.log -->25/02/2008 13:16:12
C:\WINDOWS\KB943460.log -->25/02/2008 13:16:12
C:\WINDOWS\imsins.log -->25/02/2008 13:16:12

winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed


ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com

------------------------------------------------------------------------------
explorer.exe pid: 1552
Command line: C:\WINDOWS\Explorer.EXE

Base Size Version Path
0x44080000 0xcf000 7.00.6000.16608 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x43e00000 0x45000 7.00.6000.16608 C:\WINDOWS\system32\iertutil.dll
0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x10000000 0x64000 1.00.0000.0004 C:\Program Files\SmartFTP Client\sfShellTools.dll
0x13420000 0x1a000 11.00.5721.5145 C:\PROGRA~1\WINDOW~2\wmpband.dll
0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
0x44360000 0x5cd000 7.00.6000.16608 C:\WINDOWS\system32\ieframe.dll
0x7d200000 0x2be000 3.01.4000.4039 C:\WINDOWS\system32\msi.dll
0x44160000 0x127000 7.00.6000.16608 C:\WINDOWS\system32\urlmon.dll
0x442b0000 0x3c000 7.00.6000.16608 C:\WINDOWS\system32\webcheck.dll
0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
0x01cd0000 0x26000 1.00.0002.0002 C:\Program Files\SmartFTP Client\smarthook.dll
0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
0x01fb0000 0x5b000 8.01.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
0x78130000 0x9b000 8.00.50727.1433 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
0x02010000 0x4c000 8.00.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
0x15110000 0x25a000 11.00.5721.5145 C:\WINDOWS\system32\wmvcore.dll
0x11c70000 0x3a000 11.00.5721.5238 C:\WINDOWS\system32\WMASF.DLL
0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x02a50000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x01500000 0x10000 8.00.0000.0456 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
0x02480000 0x5b000 1.01.0000.0000 C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
0x41f00000 0x7000 1.01.0000.3917 C:\WINDOWS\system32\asfsipc.dll
0x60980000 0x7000 3.01.4000.1823 C:\WINDOWS\system32\MSISIP.DLL
0x74e10000 0x10000 5.06.0000.8820 C:\WINDOWS\system32\wshext.dll
0x73d20000 0xfe000 6.02.4131.0000 C:\WINDOWS\system32\MFC42.DLL
0x61d70000 0xe000 6.00.8665.0000 C:\WINDOWS\system32\MFC42LOC.DLL
0x59000000 0xe000 5.06.0000.6626 C:\WINDOWS\system32\wshFR.DLL

ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com

------------------------------------------------------------------------------
winlogon.exe pid: 612
Command line: winlogon.exe

Base Size Version Path
0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe
0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x011d0000 0x3b000 1.07.0018.0005 C:\WINDOWS\system32\WgaLogon.dll
0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL


Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 7484-AC27

Répertoire de C:\WINDOWS\system32

19/08/2004 16:09 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 66 494 533 632 octets libres

Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 7484-AC27

Répertoire de C:\WINDOWS\Downloaded Program Files

28/01/2008 11:51 <REP> .
28/01/2008 11:51 <REP> ..
14/02/2007 18:55 65 desktop.ini
25/07/2002 17:13 24 576 dwusplay.dll
25/07/2002 17:13 196 608 dwusplay.exe
24/11/2007 21:24 378 ImageUploader4.inf
24/11/2007 21:24 2 684 432 ImageUploader4.ocx
11/04/2006 12:06 322 IPSUploader.inf
21/06/2006 10:32 1 939 056 IPSUploader.ocx
25/07/2002 17:05 172 032 isusweb.dll
14/03/2007 03:02 1 055 jinstall-6u1.inf
22/02/2007 23:41 304 544 MessengerStatsPAClient.dll
02/08/2007 11:31 360 320 MsnPUpld.dll
02/08/2007 15:47 569 MSNPUpld.inf
25/03/2003 11:09 1 558 msrdp.inf
24/03/2003 22:03 683 008 msrdp.ocx
02/08/2007 11:31 67 456 PURen-us.dll
06/08/2007 12:10 68 992 PURfr-fr.dll
04/12/2006 14:16 144 QTPlugin.inf
09/11/2006 14:36 5 019 swflash.inf
21/09/2007 09:37 465 472 wlscBase.dll
21/09/2007 09:40 320 wlscBase.inf
20 fichier(s) 6 975 926 octets

Total des fichiers listés :
20 fichier(s) 6 975 926 octets
2 Rép(s) 66 494 529 536 octets libres

Recherche de rootkit! (Merci S!Ri)

Recherche d'infections connues

Export des clefs sensibles..


Liste des fichiers en exception sur le pare-feu XP SP2

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\adslTV\\adsltv.exe"="C:\\Program Files\\adslTV\\adsltv.exe:*:Enabled:adsltv"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"="C:\\Program Files\\SmartFTP Client\\SmartFTP.exe:*:Enabled:SmartFTP Client 2.5"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Export de la clef SharedTaskScheduler

[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"



exports des policies
REGEDIT4

[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001



Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...



je tente tout de même SREng!

[CODE]

2008-02-25,13:53:29

System Repair Engineer 2.5.16.900
Smallfrogs (http://www.KZTechs.com)

Windows XP Home Edition Service Pack 2 (Build 2600) - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
All Boot Items (Including Registry, Startup Folders, Services and so on)
Browser Add-ons
Runing Processes (Including process model information)
File Associations
Winsock Provider
Autorun.Inf
HOSTS File
Process Privileges Scan


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
<CTFMON.EXE><C:\WINDOWS\system32\ctfmon.exe> [(Verified)Microsoft Windows Publisher]
<MsnMsgr><"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background> [(Verified)Microsoft Corporation]
<swg><C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe> [(Verified)Google Inc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
<Smapp><C:\Program Files\Analog Devices\SoundMAX\SMTray.exe> [Analog Devices, Inc.]
<VTTimer><VTTimer.exe> [(Verified)Microsoft Windows Publisher]
<EPSON Stylus DX3800 Series><C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"> [(Verified)Microsoft Windows Hardware Compatibility Publisher]
<NeroFilterCheck><C:\WINDOWS\system32\NeroCheck.exe> [Ahead Software Gmbh]
<TkBellExe><"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot> [(Verified)"RealNetworks, Inc."]
<Adobe Photo Downloader><"C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"> [Adobe Systems Incorporated]
<SunJavaUpdateSched><"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"> [(Verified)"Sun Microsystems, Inc."]
<QuickTime Task><"C:\Program Files\QuickTime\qttask.exe" -atboottime> [Apple Computer, Inc.]
<Adobe Reader Speed Launcher><"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"> [(Verified)"Adobe Systems, Incorporated"]
<LogitechVideoRepair><C:\Program Files\Logitech\Video\ISStart.exe> [Labtec Inc.]
<LogitechVideoTray><C:\Program Files\Logitech\Video\LogiTray.exe> [Labtec Inc.]
<KernelFaultCheck><%systemroot%\system32\dumprep 0 -k> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<shell><Explorer.exe> [(Verified)Microsoft Windows Component Publisher]
<Userinit><C:\WINDOWS\system32\userinit.exe,> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
<AppInit_DLLs><> [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
<UIHost><logonui.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
<WPDShServiceObj><C:\WINDOWS\system32\WPDShServiceObj.dll> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
<WinlogonNotify: WgaLogon><WgaLogon.dll> [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
<IE7 Uninstall Stub><C:\WINDOWS\system32\ieudinit.exe> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
<Outlook Express><%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
<Themes Setup><%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
<Microsoft Outlook Express 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
<NetMeeting 3.01><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
<Windows Messenger 4.7><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
<Microsoft Windows Media Player><rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub> [(Verified)Microsoft Windows Publisher]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
<Carnet d'adresses 6><"%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install> [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
<N/A><c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install> [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Control Panel\Desktop]
<SCRNSAVE.EXE><C:\WINDOWS\RRR2_S~1.SCR> []

==================================
Startup Folders
[Adobe Gamma Loader]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk --> C:\PROGRA~1\FICHIE~1\Adobe\CALIBR~1\ADOBEG~1.EXE [Adobe Systems, Inc.]><N>
[Microsoft Office]
<C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk --> C:\PROGRA~1\MICROS~2\Office\OSA9.EXE [Microsoft Corporation]><N>

==================================
Services
[Gestion d'applications / AppMgmt][Stopped/Manual Start]
<C:\WINDOWS\system32\svchost.exe -k netsvcs-->%SystemRoot%\System32\appmgmts.dll><N/A>
[avast! iAVS4 Control Service / aswUpdSv][Stopped/Disabled]
<"C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"><N/A>
[avast! Antivirus / avast! Antivirus][Stopped/Disabled]
<"C:\Program Files\Alwil Software\Avast4\ashServ.exe"><N/A>
[avast! Mail Scanner / avast! Mail Scanner][Stopped/Disabled]
<"C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service><N/A>
[avast! Web Scanner / avast! Web Scanner][Stopped/Disabled]
<"C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service><N/A>
[Google Updater Service / gusvc][Stopped/Manual Start]
<"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"><Google>
[Service de l'iPod / iPod Service][Stopped/Manual Start]
<"C:\Program Files\iPod\bin\iPodService.exe"><N/A>
[SoundMAX Agent Service / SoundMAX Agent Service (default)][Running/Auto Start]
<C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe><Analog Devices, Inc.>
[Windows Live Setup Service / WLSetupSvc][Stopped/Manual Start]
<"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"><>

==================================
Drivers
[aeaudio / aeaudio][Running/Manual Start]
<system32\drivers\aeaudio.sys><Andrea Electronics Corporation>
[Pilote NT de carte VIA PCI 10/100Mo Fast Ethernet / FETNDIS][Stopped/Manual Start]
<system32\DRIVERS\fetnd5.sys><VIA Technologies, Inc.>
[VIA Rhine Family Fast Ethernet Adapter Driver Service / FETNDISB][Running/Manual Start]
<system32\DRIVERS\fetnd5b.sys><VIA Technologies, Inc.>
[NTSIM / NTSIM][Stopped/Manual Start]
<\??\C:\WINDOWS\system32\ntsim.sys><VIA Networking Technologies, Inc.>
[Volume Adapter / pepifilter][Stopped/Manual Start]
<system32\DRIVERS\lv302af.sys><Labtec Inc.>
[Labtec WebCam Pro(PID_08A0) / PID_08A0][Stopped/Manual Start]
<system32\DRIVERS\LV302AV.SYS><N/A>
[Pilote de liaison parallèle directe / Ptilink][Running/Manual Start]
<system32\DRIVERS\ptilink.sys><Parallel Technologies, Inc.>
[PxHelp20 / PxHelp20][Running/Boot Start]
<\SystemRoot\System32\Drivers\PxHelp20.sys><Sonic Solutions>
[Secdrv / Secdrv][Stopped/Manual Start]
<system32\DRIVERS\secdrv.sys><Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.>
[SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC) / SMCWGU(SMC)][Stopped/Manual Start]
<system32\DRIVERS\SMCWGU.sys><N/A>
[smwdm / smwdm][Running/Manual Start]
<system32\drivers\smwdm.sys><Analog Devices, Inc.>
[VIA AGP Filter / viaagp1][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaagp1.sys><VIA Technologies, Inc.>
[viagfx / viagfx][Running/Manual Start]
<system32\DRIVERS\vtmini.sys><Copyright (C) VIA/S3 Graphics, Inc.>
[ViaIde / ViaIde][Running/Boot Start]
<\SystemRoot\system32\DRIVERS\viaide.sys><Microsoft Corporation>
[Codec Teletext standard / WSTCODEC][Stopped/Manual Start]
<system32\DRIVERS\WSTCODEC.SYS><Microsoft Corporation>
[ZDPSp50 NDIS Protocol Driver / ZDPSp50][Stopped/Manual Start]
<System32\Drivers\ZDPSp50.sys><N/A>

==================================
Browser Add-ons
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[Aide pour le lien d'Adobe PDF Reader]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[SWEETIE Class]
{1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} <C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll, Macrogaming>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Programme d'aide de l'Assistant de connexion Windows Live]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4d91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Google Toolbar Notifier BHO]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[EpsonToolBandKicker Class]
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[Java Plug-in 1.6.0_03]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[BlogThisToolbarButton Class]
{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} <C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll, Microsoft Corporation>
[]
{e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
{FB5F1910-F110-11d2-BB9E-00C04F795683} <C:\Program Files\Messenger\msmsgs.exe, Microsoft Corporation>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[EPSON Web-To-Page]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[Yahoo! Toolbar avec bloqueur de fenêtres pop-up]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[&Google]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[SweetIM For Internet Explorer]
{BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} <C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll, Macrogaming>
[QuickTime Object]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[YInstStarter Class]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} <C:\PROGRA~1\Yahoo!\Common\yinsthelper.dll, Yahoo! Inc.>
[Windows Live Safety Center Base Module]
{5ED80217-570B-4DA9-BF44-BE107C0EC166} <C:\WINDOWS\Downloaded Program Files\wlscBase.dll, Microsoft Corporation>
[Image Uploader Control]
{6E5E167B-1566-4316-B27F-0DDAB3484CF7} <C:\WINDOWS\Downloaded Program Files\ImageUploader4.ocx, Aurigma, Inc.>
[Microsoft RDP Client Control (redist)]
{7584C670-2274-4EFB-B00B-D6AABA6D3850} <C:\WINDOWS\Downloaded Program Files\msrdp.ocx, Microsoft Corporation>
[Windows Live Photo Upload Control]
{7FC1B346-83E6-4774-8D20-1A6B09B0E737} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft® Corporation>
[Java Plug-in 1.6.0_03]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[MessengerStatsClient Class]
{C3F79A2B-B9B4-4A66-B012-3EE46475B072} <C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll, Microsoft Corporation>
[Java Plug-in 1.6.0_01]
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_03]
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Java Plug-in 1.6.0_03]
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} <C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll, Sun Microsystems, Inc.>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[IPSUploader Control]
{DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} <C:\WINDOWS\Downloaded Program Files\IPSUploader.ocx, IP Labs GmbH - Germany.>
[Google Script Object]
{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Yahoo! Toolbar Helper]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[QuickTime Object]
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[Aide pour le lien d'Adobe PDF Reader]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} <C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll, Adobe Systems Incorporated>
[Windows Genuine Advantage Validation Tool]
{17492023-C23A-453E-A040-C7C580BBF700} <C:\WINDOWS\system32\legitcheckcontrol.dll, Microsoft Corporation>
[InformationCardSigninHelper Class]
{19916E01-B44E-4E31-94A4-4696DF46157B} <C:\WINDOWS\system32\icardie.dll, Microsoft Corporation>
[SWEETIE Class]
{1A0AADCD-3A72-4B5F-900F-E3BB5A838E2A} <C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll, Macrogaming>
[Windows Media Player]
{22D6F312-B0F6-11D0-94AB-0080C74C7E95} <C:\WINDOWS\system32\wmpdxm.dll, Microsoft Corporation>
[&Google]
{2318C2B1-4965-11D4-9B18-009027A5CD4F} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[HTML Document]
{25336920-03F9-11CF-8FD0-00AA00686F13} <C:\WINDOWS\system32\mshtml.dll, Microsoft Corporation>
[XML DOM Document]
{2933BF90-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XSL Template]
{2933BF94-7B36-11D2-B20E-00C04F983E60} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[DHTML Edit Control Safe for Scripting for IE5]
{2D360201-FFF5-11D1-8D03-00A0C959BC0A} <C:\Program Files\Fichiers communs\Microsoft Shared\Triedit\dhtmled.ocx, Microsoft Corporation>
[HtmlDlgSafeHelper Class]
{3050F819-98B5-11CF-BB82-00AA00BDCE0B} <C:\WINDOWS\system32\mshtmled.dll, Microsoft Corporation>
[Tabular Data Control]
{333C7BC4-460F-11D0-BC04-0080C7055A83} <C:\WINDOWS\system32\tdc.ocx, Microsoft Corporation>
[QuickTime Object]
{4063BE15-3B08-470D-A0D5-B37161CFFD69} <C:\Program Files\QuickTime\QTPlugin.ocx, Apple Computer, Inc.>
[XML Document]
{48123BC4-99D9-11D1-A6B3-00C04FD91555} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[Shell Name Space]
{55136805-B2DE-11D1-B9F2-00A0C98BC547} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[isInstalled Class]
{5852F5ED-8BF4-11D4-A245-0080C6F74284} <C:\Program Files\Java\jre1.6.0_03\bin\wsdetect.dll, Sun Microsystems, Inc.>
[Windows Live Safety Center Base Module]
{5ED80217-570B-4DA9-BF44-BE107C0EC166} <C:\WINDOWS\Downloaded Program Files\wlscBase.dll, Microsoft Corporation>
[Microsoft Shell UI Helper]
{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[DivXBrowserPlugin Object]
{67DABFBF-D0AB-41FA-9C46-CC0F21721616} <C:\Program Files\DivX\DivX Web Player\npdivx32.dll, DivX,Inc.>
[Windows Media Player]
{6BF52A52-394A-11D3-B153-00C04F79FAA6} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[Image Uploader Control]
{6E5E167B-1566-4316-B27F-0DDAB3484CF7} <C:\WINDOWS\Downloaded Program Files\ImageUploader4.ocx, Aurigma, Inc.>
[Active Desktop Mover]
{72267F6A-A6F9-11D0-BC94-00C04FB67863} <%SystemRoot%\system32\SHELL32.dll, N/A>
[Microsoft RDP Client Control (redist)]
{7584C670-2274-4EFB-B00B-D6AABA6D3850} <C:\WINDOWS\Downloaded Program Files\msrdp.ocx, Microsoft Corporation>
[SSVHelper Class]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Windows Live Photo Upload Control]
{7FC1B346-83E6-4774-8D20-1A6B09B0E737} <C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll, Microsoft® Corporation>
[Microsoft Web Browser]
{8856F961-340A-11D0-A96B-00C04FD705A2} <C:\WINDOWS\system32\ieframe.dll, Microsoft Corporation>
[XML DOM Document 4.0]
{88D969C0-F192-11D4-A65F-0040963251E5} <c:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[Free Threaded XML DOM Document 4.0]
{88D969C1-F192-11D4-A65F-0040963251E5} <c:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XSL Template 4.0]
{88D969C3-F192-11D4-A65F-0040963251E5} <c:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[XML HTTP 4.0]
{88D969C5-F192-11D4-A65F-0040963251E5} <c:\WINDOWS\system32\msxml4.dll, Microsoft Corporation>
[Java Plug-in 1.6.0_03]
{8AD9C840-044E-11D1-B3E9-00805F499D93} <C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll, Sun Microsystems, Inc.>
[Windows Live Safety Center Control Module]
{8E5C8BEE-1887-414C-8AC9-7C3951F28476} <C:\Program Files\Windows Live Safety Center\wlscCtrl.dll, Microsoft Corporation>
[Programme d'aide de l'Assistant de connexion Windows Live]
{9030D464-4C02-4ABF-8ECC-5164760863C6} <C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[RMGetLicense Class]
{A9FC132B-096D-460B-B7D5-1DB0FAE0C062} <C:\WINDOWS\system32\msnetobj.dll, Microsoft Corporation>
[Google Toolbar Helper]
{AA58ED58-01DD-4D91-8333-CF10577473F7} <c:\program files\google\googletoolbar2.dll, Google Inc.>
[Google Toolbar Notifier BHO]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} <C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll, Google Inc.>
[SweetIM For Internet Explorer]
{BC4FFE41-DE9F-46FA-B455-AAD49B9F9938} <C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll, Macrogaming>
[Windows Live Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Windows Live Toolbar Helper]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} <C:\Program Files\Windows Live Toolbar\msntb.dll, Microsoft Corporation>
[Adobe PDF Reader]
{CA8A9780-280D-11CF-A24D-444553540000} <C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroPDF.dll, Adobe Systems, Inc.>
[VIDEO__X_MS_ASF Moniker Class]
{CD3AFA8F-B84F-48F0-9393-7EDC34128127} <C:\WINDOWS\system32\wmp.dll, Microsoft Corporation>
[IPSUploader Thumbnail Control]
{CF7C5669-669A-487D-BC73-24196E611A4B} <C:\WINDOWS\Downloaded Program Files\IPSUploader.ocx, IP Labs GmbH - Germany.>
[RealPlayer G2 Control]
{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA} <C:\WINDOWS\system32\rmoc3260.dll, RealNetworks, Inc.>
[Contrôle de l'Assistant de connexion Windows Live]
{D2517915-48CE-4286-970F-921E881B8C5C} <C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll, Microsoft Corporation>
[Shockwave Flash Object]
{D27CDB6E-AE6D-11CF-96B8-444553540000} <C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx, Adobe Systems, Inc.>
[OfficeObj Class]
{D2BD7935-05FC-11D2-9059-00C04FD7A1BD} <, N/A>
[Microsoft Agent Control 2.0]
{D45FD31B-5C6E-11D1-9EC1-00C04FD7081F} <C:\WINDOWS\msagent\agentctl.dll, Microsoft Corporation>
[GetInfo Class]
{D5184A39-CBDF-4A4F-AC1A-7A45A852C883} <C:\Program Files\Yahoo!\Common\yverinfo.dll, Yahoo! Inc.>
[QuickTimeCheck Class]
{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21} <C:\Program Files\QuickTime\QTSystem\QuickTimeCheck.ocx, Apple Computer, Inc.>
[IPSUploader Control]
{DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} <C:\WINDOWS\Downloaded Program Files\IPSUploader.ocx, IP Labs GmbH - Germany.>
[]
{E1771B7F-98BE-407F-BA67-AA16ADA5D0C5} <C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGSC8~1.DLL, Microsoft Corporation>
[EpsonToolBandKicker Class]
{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[XML HTTP Request]
{ED8C108E-4349-11D2-91A4-00C04F7969E8} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[EPSON Web-To-Page]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} <C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll, SEIKO EPSON CORPORATION>
[Yahoo! Toolbar avec bloqueur de fenêtres pop-up]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} <C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll, Yahoo! Inc.>
[XML DOM Document 3.0]
{F5078F32-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML HTTP 3.0]
{F5078F35-C551-11D3-89B9-0000F81FE221} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[Free Threaded XML DOM Document]
{F6D90F12-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[XML HTTP]
{F6D90F16-9C73-11D3-B32E-00C04F990BB4} <C:\WINDOWS\system32\msxml3.dll, Microsoft Corporation>
[IERPCtl Class]
{FDC7A535-4070-4B92-A0EA-D9994BCC0DC5} <C:\Program Files\Real\RealPlayer\rpplugins\ierpplug.dll, RealNetworks, Inc.>
[&Windows Live Search]
<res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm, N/A>
[Ouvrir dans un nouvel onglet d'arrière-plan]
<res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?48e02811851b4e398e86bdccf2db0d52, N/A>
[Ouvrir dans un nouvel onglet de premier plan]
<res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?48e02811851b4e398e86bdccf2db0d52, N/A>

==================================
Running Processes
[PID: 524 / SYSTEM][\SystemRoot\System32\smss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 588 / SYSTEM][\??\C:\WINDOWS\system32\csrss.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 612 / SYSTEM][\??\C:\WINDOWS\system32\winlogon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\WgaLogon.dll] [Microsoft Corporation, 1.7.0018.5]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 656 / SYSTEM][C:\WINDOWS\system32\services.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\AppPatch\AcAdProc.dll] [Microsoft Corporation, 5.1.2600.3008 (xpsp.061004-0027)]
[PID: 692 / SYSTEM][C:\WINDOWS\system32\lsass.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 828 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 904 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 996 / SYSTEM][C:\WINDOWS\System32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\wups2.dll] [Microsoft Corporation, 7.0.6000.381 (winmain(wmbla).070730-1740)]
[PID: 1040 / SERVICE RÉSEAU][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1108 / SERVICE LOCAL][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[PID: 1308 / SYSTEM][C:\WINDOWS\system32\spoolsv.exe] [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
[C:\WINDOWS\system32\E_FLMACE.DLL] [SEIKO EPSON CORPORATION, 5, 7, 0, 0]
[PID: 1556 / Perrine Henninger][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\Program Files\SmartFTP Client\sfShellTools.dll] [SmartSoft Ltd, 1.0.0.4]
[C:\PROGRA~1\WINDOW~2\wmpband.dll] [Microsoft Corporation, 11.0.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\ieframe.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\WPDShServiceObj.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\Program Files\SmartFTP Client\smarthook.dll] [SmartSoft Ltd., 1.0.2.2]
[C:\WINDOWS\system32\PortableDeviceTypes.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\PortableDeviceApi.dll] [Microsoft Corporation, 5.2.5721.5145 (WMP_11.061018-2006)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll] [Adobe Systems, Inc., 8.1.0.0]
[C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA] [Adobe Systems, Inc., 8.0.0.0]
[C:\PROGRA~1\IZArc\IZArcCM.dll] [N/A, ]
[C:\Program Files\Alwil Software\Avast4\ashShell.dll] [ALWIL Software, 4, 7, 1043, 0]
[C:\WINDOWS\system32\l3codecp.acm] [Fraunhofer Institut Integrierte Schaltungen IIS, 3, 4, 0, 0]
[PID: 1668 / Perrine Henninger][C:\Program Files\Analog Devices\SoundMAX\SMTray.exe] [Analog Devices, Inc., 3, 2, 17, 0]
[PID: 1676 / Perrine Henninger][C:\WINDOWS\system32\VTTimer.exe] [S3 Graphics, Inc., 1.100.2004.0115]
[PID: 1688 / Perrine Henninger][C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE] [SEIKO EPSON CORPORATION, 4.00]
[PID: 1704 / Perrine Henninger][C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe] [RealNetworks, Inc., 0.1.0.3725]
[PID: 1724 / Perrine Henninger][C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe] [Adobe Systems Incorporated, 3.0.0.50878]
[C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdboot.dll] [Adobe Systems Incorporated, 3.0.0.50878]
[C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\MSVCP71.dll] [Microsoft Corporation, 7.10.3077.0]
[C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[PID: 1736 / Perrine Henninger][C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe] [Sun Microsystems, Inc., 6.0.30.5]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[PID: 1744 / Perrine Henninger][C:\Program Files\QuickTime\qttask.exe] [Apple Computer, Inc., 7.1.5]
[PID: 1820 / Perrine Henninger][C:\Program Files\Logitech\Video\LogiTray.exe] [Labtec Inc., 8.1.7.1036]
[C:\Program Files\Logitech\Video\QCUI2.dll] [Labtec Inc., 8.1.7.1036]
[C:\Program Files\Logitech\Video\LTWVC12n.dll] [LEAD Technologies, Inc., 12.1.0.011]
[C:\Program Files\Logitech\Video\LQCUI2.dll] [Labtec Inc., 8.1.7.1036]
[C:\Program Files\Logitech\Video\LLogTray.dll] [Labtec Inc., 8.1.7.1036]
[C:\WINDOWS\Twain_32\QuickCam\HPortal.dll] [Labtec Inc., 8.1.7.1018]
[C:\WINDOWS\Twain_32\QuickCam\LHPortal.dll] [Labtec Inc., 8.1.7.1018]
[C:\WINDOWS\system32\LVComC.dll] [Labtec Inc., 8.1.7.1018]
[PID: 1852 / Perrine Henninger][C:\WINDOWS\system32\ctfmon.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1872 / Perrine Henninger][C:\Program Files\Windows Live\Messenger\msnmsgr.exe] [Microsoft Corporation, 8.5.1288.0816]
[C:\Program Files\Windows Live\Messenger\MSIMG32.dll] [Patchou, 4, 50, 0, 312]
[C:\Program Files\Windows Live\Messenger\MSNCore.dll] [Microsoft Corporation, 8.5.1288.0816]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\Windows Live\Messenger\msidcrl40.dll] [Microsoft Corporation, 4.100.313.1]
[C:\Program Files\Windows Live\Messenger\ContactsUX.dll] [Microsoft Corporation, 8.5.1288.0816]
[C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll] [Patchou, 4, 50, 0, 312]
[C:\Program Files\Messenger Plus! Live\Detoured.dll] [N/A, ]
[C:\Program Files\Windows Live\Messenger\msgslang.8.5.1288.0816.dll] [Microsoft Corporation, 8.5.1288.0816]
[C:\Program Files\Windows Live\Messenger\msgsres.dll] [Microsoft Corporation, 8.5.1288.0816]
[C:\Program Files\Messenger Plus! Live\MsgPlusLiveRes.dll] [Patchou, 4, 50, 0, 312]
[C:\Program Files\Windows Live\Messenger\lcapi.dll] [Microsoft Corporation, 1.7.256.0 (RTC Version 4.3.5371.0) built by: msn8.0(rtbldlab)]
[C:\WINDOWS\system32\msdmo.dll] [, ]
[C:\Program Files\Windows Live\Messenger\lcres.dll] [Microsoft Corp., 1.7.109.0 (RTC Version 4.3.5371.0) built by: msn8.0(rtbldlab)]
[C:\Program Files\Windows Live\Messenger\RTMPLTFM.dll] [Microsoft Corporation, 3.0.5774.0 built by: media_msn80]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[C:\Program Files\Windows Live\Messenger\MSGSWCAM.dll] [Microsoft Corporation, 8.5.1288.0816]
[C:\WINDOWS\system32\sirenacm.dll] [Microsoft Corporation, 8.5.1288.0816]
[PID: 1888 / Perrine Henninger][C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe] [Google Inc., 2, 0, 301, 1654]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\gtn.dll] [Google Inc., 2, 0, 301, 7164]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\res_fr.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
[PID: 1936 / Perrine Henninger][C:\WINDOWS\system32\LVComS.exe] [Labtec Inc., 8.1.7.1018]
[C:\WINDOWS\system32\LVComC.dll] [Labtec Inc., 8.1.7.1018]
[PID: 364 / SYSTEM][C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe] [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)]
[C:\WINDOWS\system32\mscoree.dll] [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)]
[C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvc.dll] [Microsoft Corporation, 2.0.50727.1433 (REDBITS.050727-1400)]
[PID: 472 / SYSTEM][C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe] [Analog Devices, Inc., 3, 2, 6, 0]
[PID: 488 / SYSTEM][C:\WINDOWS\system32\svchost.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 844 / SERVICE LOCAL][C:\WINDOWS\System32\alg.exe] [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1632 / Perrine Henninger][C:\Program Files\Internet Explorer\iexplore.exe] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\IEFRAME.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\IEUI.dll] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
[C:\WINDOWS\system32\xmllite.dll] [Microsoft Corporation, 1.00.1018.0]
[C:\Program Files\SmartFTP Client\sfShellTools.dll] [SmartSoft Ltd, 1.0.0.4]
[C:\Program Files\Internet Explorer\ieproxy.dll] [Microsoft Corporation, 7.00.5730.11 (winmain(wmbla).061017-1135)]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll] [Yahoo! Inc., 2006, 10, 26, 1]
[C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll] [Adobe Systems Incorporated, 8.0.0.2006102200]
[C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll] [Macrogaming, 3, 0, 0, 21]
[C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll] [Sun Microsystems, Inc., 6.0.30.5]
[C:\Program Files\Java\jre1.6.0_03\bin\MSVCR71.dll] [Microsoft Corporation, 7.10.3052.4]
[C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll] [Microsoft Corporation, 4.200.514.2]
[c:\program files\google\googletoolbar2.dll] [Google Inc., 4, 0, 1601, 4978]
[C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\msidcrl40.dll] [Microsoft Corporation, 4.200.514.2]
[C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll] [Google Inc., 2, 0, 301, 7164]
[C:\Program Files\Windows Live Toolbar\msntb.dll] [Microsoft Corporation, 03.01.0000.0130]
[C:\Program Files\Windows Live Toolbar\fr-fr\mtbres.dll.mui] [Microsoft Corporation, 03.00.0001.2012]
[C:\Program Files\Windows Live Toolbar\mtbres.dll] [Microsoft Corporation, 03.01.0000.0130]
[C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll] [SEIKO EPSON CORPORATION, 1, 1, 0, 0]
[C:\WINDOWS\system32\ieapfltr.dll] [Microsoft Corporation, 7.0.6000.16461]
[C:\WINDOWS\system32\msfeeds.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\WINDOWS\system32\msacm32.drv] [Microsoft Corporation, 5.1.2600.0 (xpclient.010817-1148)]
[PID: 1924 / Perrine Henninger][C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe] [Microsoft Corporation, 4.200.514.2]
[C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\msidcrl40.dll] [Microsoft Corporation, 4.200.514.2]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[PID: 3016 / Perrine Henninger][C:\Documents and Settings\Perrine Henninger\Bureau\SREngPS.EXE] [Smallfrogs Studio, 2.5.16.900]
[C:\WINDOWS\system32\Normaliz.dll] [Microsoft Corporation, 6.0.5441.0 (winmain(wmbla).060628-1735)]
[C:\WINDOWS\system32\iertutil.dll] [Microsoft Corporation, 7.00.6000.16608 (vista_gdr.071204-1500)]
[C:\Documents and Settings\Perrine Henninger\Bureau\Upload\3rdUpd.DLL] [Smallfrogs Studio, 2, 1, 0, 15]

==================================
File Associations
.TXT OK. [%SystemRoot%\system32\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["C:\WINDOWS\hh.exe" %1]
.HLP OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
N/A

==================================
Autorun.Inf
N/A

==================================
HOSTS File
127.0.0.1 localhost

==================================
Process Privileges Scan
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1668, C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1724, C:\PROGRAM FILES\ADOBE\PHOTOSHOP ALBUM EDITION DÉCOUVERTE\3.0\APPS\APDPROXY.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1744, C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE]
Special Privilege Enabled: SeLoadDriverPrivilege [PID = 1820, C:\PROGRAM FILES\LOGITECH\VIDEO\LOGITRAY.EXE]

==================================
API HOOK
N/A

==================================
Hidden Process
N/A

==================================


/CODE


0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
25 févr. 2008 à 14:04
Re,

Peux-tu suivre ces consignes : https://forum.pcastuces.com/sujet.asp?f=25&s=37494
Edite ce rapport.


FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
25 févr. 2008 à 16:10
Voilà pour ce rapport:

__________________________________________________
ewido anti-spyware online scanner
https://www.avg.com/en-us/free-antivirus-download
__________________________________________________


Name: TrackingCookie.Adbrite
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@3.adbrite[2].txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@ad.yieldmanager[2].txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@adbrite[2].txt
Risk: Medium

Name: TrackingCookie.Adtech
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@adtech[1].txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@advertising[1].txt
Risk: Medium

Name: TrackingCookie.Advertising
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@advertising[2].txt
Risk: Medium

Name: TrackingCookie.Atdmt
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@atdmt[2].txt
Risk: Medium

Name: TrackingCookie.Atdmt
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@atdmt[3].txt
Risk: Medium

Name: TrackingCookie.Bluestreak
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@bluestreak[1].txt
Risk: Medium

Name: TrackingCookie.Bluestreak
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@bluestreak[2].txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@doubleclick[1].txt
Risk: Medium

Name: TrackingCookie.Doubleclick
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@doubleclick[2].txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@ehg-veohnetworksinc.hitbox[2].txt
Risk: Medium

Name: TrackingCookie.Comclick
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@fl01.ct2.comclick[1].txt
Risk: Medium

Name: TrackingCookie.Real
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@france.real[2].txt
Risk: Medium

Name: TrackingCookie.Real
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@france.real[3].txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@hitbox[1].txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@media.adrevolver[1].txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@mediaplex[1].txt
Risk: Medium

Name: TrackingCookie.Overture
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@overture[1].txt
Risk: Medium

Name: TrackingCookie.Real
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@real[1].txt
Risk: Medium

Name: TrackingCookie.Real
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@real[2].txt
Risk: Medium

Name: TrackingCookie.Netflame
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@ssl-hints.netflame[1].txt
Risk: Medium

Name: TrackingCookie.Weborama
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@weborama[1].txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: C:\Documents and Settings\Perrine Henninger\Cookies\perrine_henninger@zedo[1].txt
Risk: Medium

Name: Worm.Bagle.iu
Path: C:\Muestras\HIDR.EXE.Muestra EliBagle v11.04
Risk: High

Name: Worm.Bagle.jn
Path: C:\Muestras\SROSA.SYS.Muestra EliBagle v11.04
Risk: High

Name: Downloader.Bagle.aj
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031496.exe
Risk: High

Name: Worm.Bagle.hq
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031497.exe
Risk: High

Name: Worm.Bagle.hq
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031498.sys
Risk: High

Name: Worm.Bagle.iu
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031499.exe
Risk: High

Name: Worm.Bagle.jn
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031500.sys
Risk: High

Name: Downloader.Bagle.fp
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031504.exe
Risk: High

Name: Downloader.Bagle.fp
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031505.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031507.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031508.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031509.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031510.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031511.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031512.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031513.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031514.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031515.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031516.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031517.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031518.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031519.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031520.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031521.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031522.exe
Risk: High

Name: Worm.Bagle.iu
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031523.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031524.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031525.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031528.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031529.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031530.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031531.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031532.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031533.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031534.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031535.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031536.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031537.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031538.exe
Risk: High

Name: Worm.Bagle.ik
Path: C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031539.exe
Risk: High
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
25 févr. 2008 à 16:32
Re,

OK. Les fichiers Bagle trouvés sont soit en quarantaine, soit dans la restauration système. on s'en occupera à la fin.
Peux-tu faire un scan avec Kaspersky comme demandé ici : http://www.commentcamarche.net/forum/affich 5051926 impossible d installer un anti virus#8
Edite ce rapport.

FillPCA
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
26 févr. 2008 à 12:26
Bonjour,

A/

* Télécharge OTMoveIt2 (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
* Double-clique sur OTMoveIt.exe pour lancer le programme,
* Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste Standard List of Files/Folders to Move" :

C:\Documents and Settings\Perrine Henninger\Application Data\m


* Clique sur MoveIt! pour lancer la suppression,
* Le résultat appraraîtra dans le cadre Results.
* Clique sur Exit pour fermer le programme.
* Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
* Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

B/ * Lance OTmoveIT.
* Clique sur CleanUp! (le programme va télécharger un fichier texte qui servira a nettoyer les programmes que l'on a téléchargés).

NOTE : Normalement, ton firewall (parefeu) devrait te demander si OTmoveIT peut accéder à internet, Autorise le.

* Une liste apparaît dans la partie gauche d'OTmoveIT.
* Un message apparaît pour confirmer le nettoyage. Confirme.
* Les fichiers infectés qui se trouvent dans les quarantaines seront supprimés aussi.

C/ Vide la corbeille.

D/ Refais un scan complet avec Kaspersky et édite-le. Je reviens demain soir ou jeudi.

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
26 févr. 2008 à 15:11
Re-

nouveau scan kaspersky :

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, February 26, 2008 3:08:50 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/02/2008
Kaspersky Anti-Virus database records: 581816
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 69484
Number of viruses found: 9
Number of infected objects: 44
Number of suspicious objects: 0
Duration of the scan process: 01:22:17

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Historique\History.IE5\MSHist012008022620080227\index.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Temp\~DFF3EB.tmp Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Temp\~DFF3FA.tmp Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Perrine Henninger\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Perrine Henninger\NTUSER.DAT.LOG Object is locked skipped
C:\Muestras\HIDR.EXE.Muestra EliBagle v11.04 Infected: Email-Worm.Win32.Bagle.iu skipped
C:\Muestras\SROSA.SYS.Muestra EliBagle v11.04 Infected: Email-Worm.Win32.Bagle.jn skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031496.exe Infected: Trojan-Downloader.Win32.Bagle.aj skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031497.exe Infected: Email-Worm.Win32.Bagle.hq skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031498.sys Infected: Email-Worm.Win32.Bagle.hq skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031499.exe Infected: Email-Worm.Win32.Bagle.iu skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031500.sys Infected: Email-Worm.Win32.Bagle.jn skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031501.exe Infected: Trojan-Downloader.Win32.Bagle.bu skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031502.exe Infected: Email-Worm.Win32.Bagle.jo skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031503.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031504.exe Infected: Trojan-Downloader.Win32.Bagle.fp skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031505.exe Infected: Trojan-Downloader.Win32.Bagle.fp skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031506.exe Infected: Email-Worm.Win32.Bagle.jo skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031507.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031508.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031509.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031510.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031511.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031512.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031513.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031514.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031515.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031516.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031517.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031518.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031519.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031520.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031521.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031522.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031523.exe Infected: Email-Worm.Win32.Bagle.iu skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031524.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031525.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031528.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031529.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031530.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031531.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031532.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031533.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031534.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031535.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031536.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031537.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031538.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP189\A0031539.exe Infected: Email-Worm.Win32.Bagle.ik skipped
C:\System Volume Information\_restore{AEDA2FBF-C34D-4C7F-8A0D-221AEC83150D}\RP194\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{96CD07AC-7030-4EF8-8E33-A09274784557}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


A demain ou plus tard!!!
Poube!!
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
27 févr. 2008 à 20:54
Salut,

OK.

* Télécharge Toolscleaner de A.Rothstein sur ton Bureau : http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
* Double-clique sur ToolsCleaner2.exe>Recherche puis Suppression,
* Ton Bureau va disparaître. Ceci est normal.
* S'il ne réapparait pas, fais ceci : CTRL+ALT+SUP pour faire apparaître le gestionnaire de tâches.
Rends-toi à l'onglet Processus, clique en haut à gauche sur "Fichiers" et choisis "Exécuter". Tape "explorer" et valide. Cela te fera ré-apparaître ton Bureau.

1/ Il est fortement recommandé d'avoir tous ses logiciels de sécurité à jour, afin d'éviter les failles par lesquelles s'engouffrent les infections.
2/ Tu peux supprimer tous les logiciels que nous avons utilisés (Type: SmitFraufix, Blacklight, SDFix, lopxpMH, ect.....) qui traitent des infections spécifiques et qui sont mis à jour régulièrement. Il est inutile de les garder sur ton PC.
Tu peux par contre, garder AVG Antispyware et CCleaner.
3/ /!\ Maintenant que ton PC n'est plus infecté, désactive puis réactive ta "Restauration du système" afin de créer un point de restauration sain.
Pour désactiver ou activer la Restauration du système, tu dois ouvrir une session Administrateur sous Windows XP.
Désactivation:
Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
> Appliquer et Ok.
Activation:
Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
> Appliquer et Ok. Redémarrer l'ordinateur.
Comment faire pour...(lettre A): https://forum.pcastuces.com/sujet.asp?f=25&s=3902
4/ Pour améliorer la sécurité de ton PC prend quelques instants pour lire:
Sécuriser son PC +WIFI (versions "hot" & "light"): https://forum.pcastuces.com/default.asp
5/ Dénonce ton infection pour faire condamner les auteurs.

Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection :
- Voir les règles du forum : https://malwarecomplaints.info/
- Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

Tu as alors, sous forme de liste, un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).

*** Ton infection : Bagle ***
>> https://malwarecomplaints.info/
Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections, conforme au règle du forum (âge, ville, département etc..)
Indique aussi le nom du Forum qui t'a aidé : CCM
6/ Tu peux marquer ton sujet comme résolu en cliquant sur le bouton.
7/ Je te conseille enfin de défragmenter ton PC : http://www.coupdepoucepc.com/modules/news/article.php?storyid=218

Bon surf !

FillPCA
0
Poube Messages postés 89 Date d'inscription samedi 16 février 2008 Statut Membre Dernière intervention 27 décembre 2012 4
29 févr. 2008 à 16:19
Salut!!

Je prends note de toutes ces dernières consignes que j'appliquerais dès dimanche soir à mon retour. Je te remercie encore mille fois pour ton aide et ta patience!!

Bonne Continuation!
Poube !!
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
1 mars 2008 à 17:41
OK.

Bon surf !

FillPCA
0
je vous conseil de fair une mise a niveu de votre system puis l'instalation d'un enti-virus en occurence Avar entivi
0
FillPCA Messages postés 2242 Date d'inscription samedi 21 avril 2007 Statut Non membre Dernière intervention 18 février 2023 123
21 mars 2008 à 17:35
Salut,

Je pense que le sujet est maintenant réglé, depuis 20 jours.

FillPCA
0