rapport combofix:
ComboFix 08-04-18.3 - Nico 2008-04-20 18:38:53.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.533 [GMT 2:00]
Endroit: C:\Documents and Settings\Nico\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\dedgjjlm.ini
C:\WINDOWS\system32\dedgjjlm.ini2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-20 to 2008-04-20 ))))))))))))))))))))))))))))))))))))
.
2008-04-20 17:08 . 2008-04-20 17:08 <REP> d-------- C:\Program Files\Avira
2008-04-20 17:08 . 2008-04-20 17:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-20 16:54 . 2008-04-20 18:38 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\NtUser.dat.LOG
2008-04-20 16:47 . 2008-04-20 16:47 <REP> d--h----- C:\WINDOWS\msdownld.tmp
2008-04-20 16:41 . 2008-04-20 16:44 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-04-20 16:19 . 2008-03-01 14:58 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-20 16:19 . 2007-07-01 05:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-20 16:19 . 2007-07-01 05:36 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-20 16:19 . 2008-03-01 14:58 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-20 16:19 . 2008-03-01 14:58 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-20 16:19 . 2008-03-01 14:58 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-20 16:19 . 2008-03-01 14:58 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-20 16:19 . 2008-03-01 14:58 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-20 16:19 . 2006-10-27 15:09 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-04-20 16:19 . 2008-02-22 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 16:07 . 2008-04-20 16:07 <REP> d-------- C:\Documents and Settings\NetworkService\Menu D‚marrer
2008-04-20 15:51 . 2008-04-20 16:09 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-04-20 15:44 . 2004-08-19 16:09 259,072 --a--c--- C:\WINDOWS\system32\dllcache\snmpcl.dll
2008-04-20 15:44 . 2004-08-19 16:10 32,768 --a------ C:\WINDOWS\system32\snmp.exe
2008-04-20 15:44 . 2004-08-19 16:10 32,768 --a--c--- C:\WINDOWS\system32\dllcache\snmp.exe
2008-04-20 15:42 . 2008-04-20 15:42 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-04-20 15:42 . 2004-08-19 16:09 40,448 --a--c--- C:\WINDOWS\system32\dllcache\snmpthrd.dll
2008-04-20 15:26 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]0
/u02423_.tmp
2008-04-20 15:17 . 2008-04-20 15:48 <REP> d-------- C:\WINDOWS\EHome
2008-04-20 15:08 . 2008-04-20 15:08 <REP> d-------- C:\Documents and Settings\LocalService\Bureau
2008-04-20 12:04 . 2008-04-20 12:04 <REP> d-------- C:\Documents and Settings\Nico\Application Data\Malwarebytes
2008-04-20 12:03 . 2008-04-20 13:09 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-20 12:03 . 2008-04-20 12:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-20 12:03 . 2008-04-20 12:03 74,752 --a------ C:\scxxsjah.exe
2008-04-20 10:28 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-04-20 09:49 . 2008-04-20 13:11 1,541,089 ---hs---- C:\WINDOWS\system32\bbhwrqwh.ini
2008-04-20 09:46 . 2008-04-20 09:46 118 --a------ C:\WINDOWS\system32\ymgokcbp.bat
2008-04-20 09:06 . 2008-04-20 09:47 1,540,677 ---hs---- C:\WINDOWS\system32\hcqbtvso.ini
2008-04-20 08:51 . 2004-08-03 23:04 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winzm.ime
2008-04-20 08:51 . 2004-08-03 23:04 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winsp.ime
2008-04-20 08:51 . 2004-08-03 23:04 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winpy.ime
2008-04-20 08:51 . 2004-08-03 23:04 79,360 --a--c--- C:\WINDOWS\system32\dllcache\winar30.ime
2008-04-20 08:51 . 2003-04-24 14:00 69,120 --a--c--- C:\WINDOWS\system32\dllcache\wingb.ime
2008-04-20 08:51 . 2004-08-03 23:04 65,536 --a--c--- C:\WINDOWS\system32\dllcache\winime.ime
2008-04-20 08:51 . 2003-04-24 14:00 41,600 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.dll
2008-04-20 08:51 . 2003-04-24 14:00 31,360 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.sys
2008-04-20 08:49 . 2003-04-24 14:00 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-04-20 08:48 . 2003-04-24 14:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-04-20 08:47 . 2003-04-24 14:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-04-20 08:42 . 2008-04-20 08:42 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-04-20 08:42 . 2008-04-20 08:42 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-04-20 08:42 . 2008-04-20 08:42 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-04-20 08:42 . 2008-04-20 08:42 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-04-20 08:42 . 2008-04-20 08:42 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-04-20 08:42 . 2008-04-20 08:42 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-04-20 08:41 . 2004-08-19 16:09 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2008-04-20 08:41 . 2003-04-24 14:00 73,728 --a--c--- C:\WINDOWS\system32\dllcache\icwtutor.exe
2008-04-20 08:41 . 2003-04-24 14:00 65,536 --a--c--- C:\WINDOWS\system32\dllcache\icwres.dll
2008-04-20 08:41 . 2003-04-24 14:00 40,960 --a--c--- C:\WINDOWS\system32\dllcache\trialoc.dll
2008-04-20 08:25 . 2003-04-24 14:00 1,086,182 -ra------ C:\WINDOWS\SET22.tmp
2008-04-19 18:41 . 2008-04-19 18:41 <REP> d-------- C:\Program Files\Google
2008-04-19 14:53 . 2008-04-19 16:26 4 --a------ C:\WINDOWS\scanreg.ini
2008-04-19 14:49 . 2005-02-01 14:49 12 --a------ C:\WINDOWS\system32\wsxttime.sys
2008-04-19 14:37 . 2008-04-20 16:57 <REP> d-------- C:\Program Files\Systerac XP Tools 3
2008-04-19 14:36 . 2008-04-19 14:36 <REP> d-------- C:\WINDOWS\Downloaded Installations
2008-04-19 14:23 . 2008-04-20 16:55 <REP> d-------- C:\Program Files\SpyErazer
2008-04-19 14:23 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-19 14:23 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-19 14:23 . 2008-04-19 14:23 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-19 14:23 . 2008-04-19 14:23 3,120 --a------ C:\WINDOWS\118294.78
2008-04-19 14:23 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-19 11:30 . 2008-04-20 16:46 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-04-19 11:30 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-04-19 11:27 . 2008-04-19 11:27 <REP> d-------- C:\WINDOWS\system32\bits
2008-04-19 11:26 . 2004-08-19 16:09 351,232 --a------ C:\WINDOWS\system32\winhttp.dll
2008-04-19 11:26 . 2004-08-19 16:09 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2008-04-19 11:26 . 2004-08-19 16:09 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2008-04-19 11:26 . 2004-08-19 16:09 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2008-04-19 11:20 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-19 11:20 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-19 11:18 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-04-19 11:18 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-04-19 11:18 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-04-19 11:18 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-04-19 11:18 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-04-19 11:18 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-04-19 11:18 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-04-19 11:18 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-04-19 10:59 . 2008-04-20 12:05 2 --a------ C:\1756552116
2008-04-19 09:19 . 2007-01-25 16:37 4,027,456 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-04-19 09:18 . 2008-04-19 09:18 <REP> d-------- C:\Program Files\Realtek AC97
2008-04-19 09:18 . 2006-12-08 15:20 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe
2008-04-19 09:18 . 2002-02-05 13:54 141,016 --a------ C:\WINDOWS\system32\alsndmgr.wav
2008-04-19 09:17 . 2006-11-17 05:40 18,804,736 --a------ C:\WINDOWS\system32\alsndmgr.cpl
2008-04-19 09:01 . 2008-04-19 09:01 <REP> d---s---- C:\Documents and Settings\Nico\UserData
2008-04-19 07:22 . 2001-03-08 18:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-04-19 07:19 . 2008-04-20 11:38 109,756 --a------ C:\WINDOWS\BM6b81e887.xml
2008-04-19 06:43 . 2003-04-24 14:00 1,086,182 -ra------ C:\WINDOWS\SET1B.tmp
2008-04-19 06:43 . 2003-04-24 14:00 13,923 -ra------ C:\WINDOWS\SET27.tmp
2008-04-18 00:44 . 2008-04-18 00:44 116 --a------ C:\WINDOWS\system32\nbsven.bat
2008-04-17 18:07 . 2008-04-19 19:26 425,459 --a------ C:\Documents and Settings\Nico\scan.dat
2008-04-17 18:06 . 2008-04-17 18:06 114 --a------ C:\WINDOWS\system32\hjkh.bat
2008-04-17 18:03 . 2008-04-17 18:03 123 --a------ C:\WINDOWS\system32\ikye.bat
2008-04-17 17:59 . 2008-04-17 17:59 0 -ra------ C:\WINDOWS\system32\TFTP672
2008-04-17 17:50 . 2008-04-17 17:50 <REP> d-------- C:\Documents and Settings\Nico\Application Data\libresystem
2008-04-17 17:45 . 2008-04-17 17:45 <REP> dr------- C:\Documents and Settings\All Users\Application Data\libresystem
2008-04-17 17:44 . 2004-10-07 13:39 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-04-17 17:23 . 2008-04-17 17:23 121 --a------ C:\WINDOWS\system32\unnpqyed.bat
2008-04-16 21:38 . 2003-04-24 14:00 28,160 --a--c--- C:\WINDOWS\system32\dllcache\msoobe.exe
2008-04-16 21:33 . 2004-08-19 15:52 411,648 --a------ C:\WINDOWS\system32\mstsc.exe
2008-04-16 21:22 . 2003-04-24 14:00 1,086,182 -ra------ C:\WINDOWS\SET19.tmp
2008-04-16 21:22 . 2003-04-24 14:00 13,923 -ra------ C:\WINDOWS\SET25.tmp
2008-04-16 19:30 . 2008-04-16 19:30 <REP> d-------- C:\Documents and Settings\Daphn‚
2008-04-16 19:19 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-04-16 19:19 . 2003-03-18 20:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-04-16 19:19 . 2003-02-21 04:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-04-16 19:18 . 2008-04-16 19:18 <REP> d-------- C:\Program Files\Alwil Software
2008-04-16 18:58 . 2008-04-16 18:58 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-04-16 18:54 . 2008-04-16 18:54 0 -ra------ C:\WINDOWS\system32\TFTP5412
2008-04-16 18:40 . 2008-04-16 18:40 13,736 --a------ C:\WINDOWS\system32\wpa.bak
2008-04-16 18:39 . 2008-04-16 18:39 0 -ra------ C:\WINDOWS\system32\TFTP3304
2008-04-16 18:24 . 2008-04-16 18:24 <REP> d-------- C:\Program Files\Rockstar Games
2008-04-08 19:32 . 2008-04-08 19:32 <REP> d-------- C:\WINDOWS\system32\URTTemp
2008-04-08 19:28 . 2008-04-08 19:28 0 --a------ C:\WINDOWS\frontpg.ini
2008-04-08 19:27 . 2008-04-08 19:27 <REP> d-------- C:\WINDOWS\IIS Temporary Compressed Files
2008-04-08 19:25 . 2008-04-08 19:26 <REP> d-------- C:\WINDOWS\system32\msmq
2008-04-07 05:12 . 2008-04-19 19:20 <REP> d-------- C:\Documents and Settings\Nico\Application Data\MSN6
2008-04-07 05:12 . 2008-04-07 05:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-04-07 05:05 . 2008-04-07 05:05 <REP> d---s---- C:\WINDOWS\system32\Microsoft
2008-04-07 05:05 . 2006-08-01 15:02 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 05:54 --------- d-----w C:\Program Files\Services en ligne
2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1bd9becd-055a-4dba-9041-1c0a24c4026d}]
C:\WINDOWS\System32\npaoxjra.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-19 16:10 1667584]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-19 18:41 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-10-22 12:22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"Microsoft Anivirus Monitor Process"="antiv.exe" []
"Microsft Security Monitor Process"="mssmpp.exe" []
"cookw"="C:\PROGRA~1\FICHIE~1\LIBRES~1\cookw.exe" [ ]
"SBI"="C:\Documents and Settings\Nico\Bureau\install_sbd_fr.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\SOUNDMAN.EXE]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2006-10-22 12:22 86016]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft Anivirus Monitor Process"="antiv.exe" []
"Microsft Security Monitor Process"="mssmpp.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 Machnm32;Machnm32 Driver;C:\WINDOWS\System32\Machnm32.sys [2003-08-13 00:27]
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\System32\inetsrv\inetinfo.exe [2004-08-19 16:09]
S2 Distributed Allocated Memory Unit;Distributed Allocated Memory Unit;"C:\WINDOWS\system32\dllcache\mravsc32.exe" []
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-20 18:43:46
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-04-20 18:46:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-20 16:46:49
Pre-Run: 32,560,791,552 octets libres
Post-Run: 32,595,222,528 octets libres
219
Version de la base de données: 660
Type de recherche: Examen complet (C:\|)
Eléments examinés: 43113
Temps écoulé: 1 hour(s), 0 minute(s), 40 second(s)
Processus mémoire infecté(s): 1
Module(s) mémoire infecté(s): 4
Clé(s) du Registre infectée(s): 25
Valeur(s) du Registre infectée(s): 7
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 50
Processus mémoire infecté(s):
C:\WINDOWS\system32\algs.exe (Backdoor.Bot) -> No action taken.
Module(s) mémoire infecté(s):
c:\WINDOWS\system32\rqRiJyvu.dll (Trojan.Vundo) -> No action taken.
c:\WINDOWS\system32\qoMffCvS.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hwqrwhbb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mljjgded.dll (Trojan.Vundo) -> No action taken.
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rqrijyvu (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a1d3ce66-721f-4a88-b58e-c532286c347b} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a1d3ce66-721f-4a88-b58e-c532286c347b} (Trojan.Vundo) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1a26f07f-0d60-4835-91cf-1e1766a0ec56} (Trojan.Agent) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{7543fbd5-2279-4d03-8f29-eb21531fa2fe} (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Purchased Products (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> No action taken.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM6b81e887 (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows update loader (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ctfmona (Trojan.Downloader) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ADP (Rogue.Multiple) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Application Layer Gateway Service (Backdoor.Bot) -> No action taken.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\mljjgded -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\mljjgded -> No action taken.
Dossier(s) infecté(s):
C:\Program Files\MalwareAlarm (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\Helper (Adware.BHO) -> No action taken.
Fichier(s) infecté(s):
c:\WINDOWS\system32\rqRiJyvu.dll (Trojan.Vundo) -> No action taken.
c:\WINDOWS\system32\qoMffCvS.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\cbdfngim.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mignfdbc.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hwqrwhbb.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\bbhwrqwh.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\mljjgded.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\dedgjjlm.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\dedgjjlm.ini2 (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pxdagjqv.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\vqjgadxp.ini (Trojan.Vundo) -> No action taken.
C:\WINDOWS\Downloaded Program Files\webinst.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\45U789MB\ddos1[1].htm (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\45U789MB\sdferw[1].htm (Trojan.Agent) -> No action taken.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\I49VGGX3\ddos1[1].htm (Trojan.Vundo) -> No action taken.
C:\Program Files\MalwareAlarm\MalwareAlarm3.dll (Rogue.Multiple) -> No action taken.
C:\Program Files\Systerac XP Tools 3\iea.exe (Rogue.PornCleanser) -> No action taken.
C:\System Volume Information\_restore{57A83DB2-1707-42B2-BC86-B9A7E80285B2}\RP5\A0001162.dll (Rogue.Multiple) -> No action taken.
C:\WINDOWS\system32\blackster.scr (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\ctfmonb.bmp (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\ljJCtqQJ.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\pmnOEWPJ.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\rmyvdgca.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\Temp\7CF28762C38CA0D4.tmp (Trojan.Dropper) -> No action taken.
C:\WINDOWS\Temp\AE8AB41F91F72503.tmp (Malware.Trace) -> No action taken.
C:\Program Files\MalwareAlarm\MalwareAlarm.lic (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\MalwareAlarm0.ma (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\MalwareAlarm1.ma (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\mfc71.dll (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\msvcp71.dll (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\msvcr71.dll (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\pv.exe (Rogue.Malware.Alarm) -> No action taken.
C:\Program Files\MalwareAlarm\Uninstall.exe (Rogue.Malware.Alarm) -> No action taken.
C:\WINDOWS\System32\xxywwwxw.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\oqqqiekb.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\xpupdate.exe (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\ctfmona.exe (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\algs.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\winIogon.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\Temp\.tt1.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt2.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt3.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt4.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt5.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt6.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt7.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt8.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.tt9.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.ttA.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\.ttB.tmp (Trojan.Downloader) -> No action taken.