Nouveau virus?? OBFUSTAT?? plus erreur

Fermé
wilhat - 1 oct. 2007 à 20:44
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 - 2 oct. 2007 à 20:38
Bonjour à tous, j'ai un problème évidement ..... si je viens ici.... bon j'ai un virus qui s'appelle OBFUSTAT, en plus de ça chaque fois que j'allume mon pc j'ai une 20aine de fenetre d'erreur qui apparaissent... ensuite mon spybot ne fonctionne plus il y a aussi une erreur RUN32.DLL????
QUE DOIS JE FAIRE???? je sais que c'est ce fichier qui est nfecté mais je ne sais pas comment faire pour le virer C:\WINDOWS\SYSTEM32\nnnlmno.dll

merci de m'aider

j'ai un rapport high jack this apres avoir scanné mon ordi par bit defender (rien trouvé)
j'ai aussi fait CCLEANER, CLEANZIP, AVGanti spyware, AVAST, et je ne me rappelles plus trop tellement j'en ai fait!!!!

rapport higjackthis
---------------------------------------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 20:42:34, on 01/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\osfvvffrp.exe
C:\WINDOWS\system\NOTEPAD.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\LGV\Bureau\virus\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.cri.univ-nantes.fr/cache.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4B7551B3-D45D-41C5-929E-6221272591F5} - C:\WINDOWS\system32\wvwxw.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\smpvtlca.dll",sitypnow
O4 - HKLM\..\RunServices: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - https://onlinelibrary.wiley.com/action/cookieAbsent
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://fwdservice.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://happywash.dnsalias.com:81/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://nomade.univ-nantes.fr/dana-cached/setup/JuniperSetup.cab
O20 - Winlogon Notify: nnnlmno - C:\WINDOWS\SYSTEM32\nnnlmno.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Print Spooler Service (isoaci6fayceqeg) - Unknown owner - C:\WINDOWS\system32\osfvvffrp.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NOTEPAD - Unknown owner - C:\WINDOWS\system\NOTEPAD.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
A voir également:

19 réponses

did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 20:59
Bonsoir,

* Télécharge VundoFix.exe (par Atribune) sur ton Bureau:

http://www.atribune.org/public-beta/VundoFix.exe

* Double-clique VundoFix.exe afin de le lancer
* Clique sur le bouton Scan for Vundo
* Lorsque le scan est complété, clique sur le bouton Remove Vundo
* Une invite te demandera si tu veux supprimer les fichiers, clique YES
* Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
* Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
* Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

a+
0
voilà mon rapport vundofix :
--------------------------------------------------------------------------------------------------------------
VundoFix V6.5.9

Checking Java version...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 21:05:27 01/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\acltvpms.ini
C:\WINDOWS\system32\smpvtlca.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\acltvpms.ini
C:\WINDOWS\system32\acltvpms.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\smpvtlca.dll
C:\WINDOWS\system32\smpvtlca.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\smpvtlca.dll
C:\WINDOWS\system32\smpvtlca.dll Has been deleted!

Performing Repairs to the registry.
Done!
---------------------------------------------------------------------------------------------------------------------------
et puis mon nouveau high jack....

__________________________________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 21:36:49, on 01/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\osfvvffrp.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system\NOTEPAD.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\LGV\Bureau\virus\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.cri.univ-nantes.fr/cache.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A0AE282-BFDC-43DD-AF6C-B9A479FE79E0} - C:\WINDOWS\system32\wvwxw.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {ABD20031-4F10-4201-B553-37AF8DA43940} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKLM\..\RunServices: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - https://onlinelibrary.wiley.com/action/cookieAbsent
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://fwdservice.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://happywash.dnsalias.com:81/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://nomade.univ-nantes.fr/dana-cached/setup/JuniperSetup.cab
O20 - Winlogon Notify: mljggfd - C:\WINDOWS\SYSTEM32\mljggfd.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Print Spooler Service (isoaci6fayceqeg) - Unknown owner - C:\WINDOWS\system32\osfvvffrp.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NOTEPAD - Unknown owner - C:\WINDOWS\system\NOTEPAD.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
0
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 21:41
re,

* Relance Vundofix
* Ne clique pas sur "Scan for a vundo"
* Clique droit au milieu de la fenêtre
* Clique sur Add more files ?
* Copie/colle les fichiers ci-dessous ( un par case) :

C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\SYSTEM32\mljggfd.dll

* Clique sur Add files
* Ensuite clique sur Close Windows
* Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
* Si l'outils demande un redémarrage, accepte
* Poste le rapport Vundofix, ainsi qu'un nouveau log hijackthis

a+
0
bon bon, voilà le rapport...

-----------------------------------------------------------------------------------------------------------------------
undoFix V6.5.9

Checking Java version...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Java version is 1.5.0.11

Scan started at 21:05:27 01/10/2007

Listing files found while scanning....

C:\WINDOWS\system32\acltvpms.ini
C:\WINDOWS\system32\smpvtlca.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\acltvpms.ini
C:\WINDOWS\system32\acltvpms.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\smpvtlca.dll
C:\WINDOWS\system32\smpvtlca.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\smpvtlca.dll
C:\WINDOWS\system32\smpvtlca.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\SYSTEM32\mljggfd.dll
C:\WINDOWS\SYSTEM32\mljggfd.dll Could not be deleted.

Attempting to delete C:\WINDOWS\SYSTEM32\mljggfd.dll
C:\WINDOWS\SYSTEM32\mljggfd.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\system32\wvwxw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\system32\wvwxw.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...
-----------------------------------------------------------------------------------------------------------------------------

et le nouveau rapport highjack


____________________________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:02:45, on 01/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system\NOTEPAD.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\osfvvffrp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\LGV\Bureau\virus\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.cri.univ-nantes.fr/cache.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {490E6574-52D6-49A9-9F78-AD2BC9814315} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {ABD20031-4F10-4201-B553-37AF8DA43940} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {B89201BB-FE41-43ED-87D2-2EE01E7F0A4E} - C:\WINDOWS\system32\wvwxw.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKLM\..\RunServices: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - https://onlinelibrary.wiley.com/action/cookieAbsent
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://fwdservice.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://happywash.dnsalias.com:81/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://nomade.univ-nantes.fr/dana-cached/setup/JuniperSetup.cab
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Print Spooler Service (isoaci6fayceqeg) - Unknown owner - C:\WINDOWS\system32\osfvvffrp.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NOTEPAD - Unknown owner - C:\WINDOWS\system\NOTEPAD.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 22:10
re,

Télécharge OTMoveIt (de Old_Timer) sur ton Bureau:

http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en gars ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.


C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\SYSTEM32\mljggfd.dll
C:\WINDOWS\system32\osfvvffrp.exe


clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre Results.
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

il te sera peut-être demander de redémarrer le pc pour achever la suppression.
si c'est le cas accepte par Yes.


poste un nouvel hijackhis aussi!

a+
0
re voilà mon rapport OTMoveIt :


---------------------------------------------------------------------------------------------------


LoadLibrary failed for C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\system32\wvwxw.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\wvwxw.dll scheduled to be moved on reboot.
LoadLibrary failed for C:\WINDOWS\SYSTEM32\mljggfd.dll
C:\WINDOWS\SYSTEM32\mljggfd.dll NOT unregistered.
C:\WINDOWS\SYSTEM32\mljggfd.dll moved successfully.
C:\WINDOWS\system32\osfvvffrp.exe moved successfully.

Created on 10/01/2007 22:15:46
_________________________________________________________________

et mon dernier highjackthis

_________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:27:14, on 01/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system\NOTEPAD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\LGV\Bureau\virus\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.cri.univ-nantes.fr/cache.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {CA5F1987-51FF-4935-B662-C5CC2D6F30D0} - C:\WINDOWS\system32\wvwxw.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKLM\..\RunServices: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - https://onlinelibrary.wiley.com/action/cookieAbsent
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://fwdservice.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://happywash.dnsalias.com:81/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://nomade.univ-nantes.fr/dana-cached/setup/JuniperSetup.cab
O20 - Winlogon Notify: byxvssp - C:\WINDOWS\SYSTEM32\byxvssp.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Print Spooler Service (isoaci6fayceqeg) - Unknown owner - C:\WINDOWS\system32\osfvvffrp.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NOTEPAD - Unknown owner - C:\WINDOWS\system\NOTEPAD.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
0
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 22:31
re,

redémarre ton pc et poste un nouvel hijackthis, OtMoveIt demande le redémarrage!

a+
0
mais j'ai déja fait... bon ...je vais le refaire

merci de t'occuper de moi.... au fait ca sert a quoi la fonction cleanup??
0
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 22:39
re,

ça sert à virer les outils utiliser pour désinfecter le pc!

a+
0
ok, c'est sympa aussi e comprendre ce qu'on fait...;-)

mon nouveau highjack :

il y a toujours le fichier ...et pus deux autre en ligne 020..... ca erait pas vundo encore??? au fait AVG m'avait trouvé virtumonde...

----------------------------------------------------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 22:41:55, on 01/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system\NOTEPAD.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\LGV\Bureau\virus\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.cri.univ-nantes.fr/cache.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: (no name) - {D5BA6524-4FFB-40C2-AB6A-9C7A0A8FA4B0} - C:\WINDOWS\system32\wvwxw.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKLM\..\RunServices: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - https://onlinelibrary.wiley.com/action/cookieAbsent
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://fwdservice.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://happywash.dnsalias.com:81/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://nomade.univ-nantes.fr/dana-cached/setup/JuniperSetup.cab
O20 - Winlogon Notify: byxvssp - C:\WINDOWS\SYSTEM32\byxvssp.dll
O20 - Winlogon Notify: qomklli - C:\WINDOWS\SYSTEM32\qomklli.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Print Spooler Service (isoaci6fayceqeg) - Unknown owner - C:\WINDOWS\system32\osfvvffrp.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NOTEPAD - Unknown owner - C:\WINDOWS\system\NOTEPAD.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
0
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 22:52
re,

oui, c'est du vundo réclcitrant!

on va le virer!

Télécharge ComboFix (par sUBs) d'un de ces liens sur ton bureau:

http://www.techsupportforum.com/sectools/combofix.exe

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Double clique combofix.exe et suis les invites

Poste le rapport

a+
0
vola le rapport j'ai aussi une erreur rundll quand mn ordi demarre c'est lier???

-----------------------------------------------------------------------------------------------------------
ComboFix 07-10-02.2 - LGV 2007-10-01 23:02:46.2 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.177 [GMT 2:00]
Running from: C:\Documents and Settings\LGV\Bureau\virus\combofix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\check_LSA7.txt
C:\WINDOWS\system32\iqkcejdx.exe
C:\WINDOWS\system32\wvwxw.dll
C:\WINDOWS\system32\wxwvw.bak1
C:\WINDOWS\system32\wxwvw.bak2
C:\WINDOWS\system32\wxwvw.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((((((( Fichiers créés 2007-09-02 to 2007-10-02 ))))))))))))))))))))))))))))))))))))
.

2007-10-01 22:38 35,328 --a------ C:\WINDOWS\system32\qomklli.dll
2007-10-01 22:19 35,328 --a------ C:\WINDOWS\system32\byxvssp.dll
2007-10-01 21:05 <REP> d-------- C:\VundoFix Backups
2007-10-01 20:02 35,328 --a------ C:\WINDOWS\system32\nnnlmno.dll
2007-10-01 19:18 35,328 --a------ C:\WINDOWS\system32\ddcbxwu.dll
2007-10-01 18:41 35,328 --a------ C:\WINDOWS\system32\pmnkjkh.dll
2007-10-01 17:14 35,328 --a------ C:\WINDOWS\system32\urqoopn.dll
2007-10-01 15:52 35,328 --a------ C:\WINDOWS\system32\iifefge.dll
2007-10-01 15:14 35,328 --a------ C:\WINDOWS\system32\jkkhede.dll
2007-10-01 10:56 35,328 --a------ C:\WINDOWS\system32\ddcdeca.dll
2007-10-01 09:57 35,328 --a------ C:\WINDOWS\system32\ddccdcb.dll
2007-10-01 09:50 <REP> d-------- C:\Program Files\MSXML 6.0
2007-10-01 08:50 35,328 --a------ C:\WINDOWS\system32\qomjjjj.dll
2007-09-30 12:33 <REP> d-------- C:\Program Files\MSBuild
2007-09-30 12:28 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2007-09-30 12:26 <REP> d-------- C:\Program Files\Reference Assemblies
2007-09-30 12:24 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-09-30 12:24 <REP> d-------- C:\beefaff2caa54e614d46ab00895944
2007-09-29 19:55 35,328 --a------ C:\WINDOWS\system32\vturonl.dll
2007-09-28 17:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Advanced Chemistry Development
2007-09-22 17:12 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-22 16:10 <REP> d-------- C:\Documents and Settings\LGV\.housecall6.6
2007-09-21 16:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-21 16:03 <REP> d-------- C:\WINDOWS\ERUNT
2007-09-20 23:12 3,620 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-20 23:11 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-09-20 23:11 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-20 23:11 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-09-20 23:08 <REP> d-------- C:\Program Files\RogueRemover FREE
2007-09-20 15:10 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-20 12:09 <REP> d-------- C:\Program Files\Panda Security
2007-09-19 22:50 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-09-19 21:23 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-09-19 06:16 38,649 -rahs---- C:\WINDOWS\system\NOTEPAD.exe
2007-09-07 12:28 <REP> d-------- C:\Documents and Settings\LGV\Application Data\Mestrelab Research S.L
2007-09-07 12:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Mestrelab Research S.L
2007-09-07 12:27 <REP> d-------- C:\Program Files\Mestrelab Research S.L

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-01 18:33 --------- d-------- C:\Program Files\CCleaner
2007-10-01 08:55 --------- d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-09-27 20:48 --------- d-------- C:\Program Files\eMule
2007-09-27 18:50 --------- d-------- C:\Documents and Settings\LGV\Application Data\Juniper Networks
2007-09-24 14:05 --------- d-------- C:\Program Files\Google
2007-09-21 09:56 1037312 --a------ C:\WINDOWS\explorer.exe
2007-09-06 12:05 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 12:05 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 12:03 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 12:02 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 12:00 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-16 22:58 --------- d-------- C:\Documents and Settings\LGV\Application Data\DivX
2007-08-16 17:55 --------- d-------- C:\Program Files\DivX
2007-08-11 12:38 --------- d-------- C:\Documents and Settings\All Users\Application Data\Skyline
2007-08-09 20:58 --------- d-------- C:\Documents and Settings\LGV\Application Data\Skyline
2007-08-09 17:59 --------- d-------- C:\Program Files\WinLemm
2007-08-07 01:33 --------- d-------- C:\Program Files\ReflexiveArcade
2006-12-31 13:33 15001752 --a------ C:\Program Files\GoogleEarthWin.exe
C:\Program Files\vlc-0.8.5-win32 lecteur vidéo.exe
.

((((((((((((((((((((((((((((( snapshot_2007-09-20_152124.50 )))))))))))))))))))))))))))))))))))))))))
.
----a-w 135,168 2007-09-28 07:06:08 C:\WINDOWS\catchme.exe
----a-w 15,072 2005-10-12 23:15:25 C:\WINDOWS\$hf_mig$\KB920342\spmsg.dll
----a-w 216,800 2005-10-12 23:15:26 C:\WINDOWS\$hf_mig$\KB920342\spuninst.exe
----a-w 153,088 2006-10-11 16:37:30 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\p2p.dll
----a-w 104,960 2006-10-11 16:37:30 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\p2pgasvc.dll
----a-w 313,344 2006-10-11 16:37:30 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\p2pgraph.dll
----a-w 115,712 2006-10-11 16:37:30 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\p2pnetsh.dll
----a-w 553,984 2006-10-11 16:37:30 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\p2psvc.dll
----a-w 58,880 2006-10-11 16:37:30 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\pnrpnsp.dll
----a-w 228,352 2006-09-26 09:14:52 C:\WINDOWS\$hf_mig$\KB920342\SP2QFE\spru040c.dll
----a-w 22,752 2005-10-12 23:15:25 C:\WINDOWS\$hf_mig$\KB920342\update\spcustom.dll
----a-w 727,776 2005-10-12 23:15:28 C:\WINDOWS\$hf_mig$\KB920342\update\update.exe
----a-w 394,976 2005-10-12 23:15:45 C:\WINDOWS\$hf_mig$\KB920342\update\updspapi.dll
----a-w 15,072 2005-10-12 23:18:45 C:\WINDOWS\$hf_mig$\KB925720\spmsg.dll
----a-w 216,800 2005-10-12 23:18:45 C:\WINDOWS\$hf_mig$\KB925720\spuninst.exe
----a-w 73,216 2006-10-04 14:04:06 C:\WINDOWS\$hf_mig$\KB925720\SP2QFE\magnify.exe
----a-w 55,296 2006-10-04 14:04:05 C:\WINDOWS\$hf_mig$\KB925720\SP2QFE\narrator.exe
----a-w 216,576 2006-10-04 14:04:06 C:\WINDOWS\$hf_mig$\KB925720\SP2QFE\osk.exe
----a-w 36,864 2006-10-04 14:05:36 C:\WINDOWS\$hf_mig$\KB925720\SP2QFE\umandlg.dll
----a-w 50,176 2006-10-04 14:04:05 C:\WINDOWS\$hf_mig$\KB925720\SP2QFE\utilman.exe
----a-w 22,752 2005-10-12 23:18:45 C:\WINDOWS\$hf_mig$\KB925720\update\spcustom.dll
----a-w 727,776 2005-10-12 23:18:46 C:\WINDOWS\$hf_mig$\KB925720\update\update.exe
----a-w 394,976 2005-10-12 23:18:49 C:\WINDOWS\$hf_mig$\KB925720\update\updspapi.dll
----a-w 15,072 2005-10-12 23:18:45 C:\WINDOWS\$hf_mig$\KB925876\spmsg.dll
----a-w 216,800 2005-10-12 23:18:45 C:\WINDOWS\$hf_mig$\KB925876\spuninst.exe
----a-w 116,736 2006-12-11 14:13:35 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\aaclient.dll
----a-w 600,576 2006-11-07 08:10:30 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\lhmstsc.exe
----a-w 1,866,240 2006-12-11 14:13:35 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\lhmstscx.dll
----a-w 288,768 2006-12-11 14:13:35 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\rhttpaa.dll
----a-w 16,832 2006-11-07 08:10:30 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\tscinst.vbs
----a-w 12,451 2006-11-07 08:10:30 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\tscuinst.vbs
----a-w 36,352 2006-12-11 14:13:35 C:\WINDOWS\$hf_mig$\KB925876\SP2QFE\tsgqec.dll
----a-w 22,752 2005-10-12 23:18:45 C:\WINDOWS\$hf_mig$\KB925876\update\spcustom.dll
----a-w 38,400 2006-12-11 13:44:01 C:\WINDOWS\$hf_mig$\KB925876\update\tscupdatecustom.dll
----a-w 727,776 2005-10-12 23:18:46 C:\WINDOWS\$hf_mig$\KB925876\update\update.exe
----a-w 394,976 2005-10-12 23:18:49 C:\WINDOWS\$hf_mig$\KB925876\update\updspapi.dll
-c----w 221,488 2006-10-16 14:10:58 C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe
-c----w 379,184 2006-10-16 14:10:58 C:\WINDOWS\$NtUninstallWIC$\spuninst\updspapi.dll
----a-w 151,552 2007-09-30 10:26:12 C:\WINDOWS\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
----a-w 3,915,776 2007-09-30 10:28:05 C:\WINDOWS\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
----a-w 344,064 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
----a-w 352,256 2007-09-30 10:26:12 C:\WINDOWS\assembly\GAC_MSIL\Microsoft.Transactions.Bridge\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.dll
----a-w 593,920 2007-09-30 10:28:04 C:\WINDOWS\assembly\GAC_MSIL\PresentationBuildTasks\3.0.0.0__31bf3856ad364e35\PresentationBuildTasks.dll
----a-w 32,768 2007-09-30 10:28:05 C:\WINDOWS\assembly\GAC_MSIL\PresentationCFFRasterizer\3.0.0.0__31bf3856ad364e35\PresentationCFFRasterizer.dll
----a-w 4,972,544 2007-09-30 10:28:06 C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
----a-w 184,320 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
----a-w 126,976 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Classic\3.0.0.0__31bf3856ad364e35\PresentationFramework.Classic.dll
----a-w 376,832 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Luna\3.0.0.0__31bf3856ad364e35\PresentationFramework.Luna.dll
----a-w 151,552 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\PresentationFramework.Royale\3.0.0.0__31bf3856ad364e35\PresentationFramework.Royale.dll
----a-w 897,024 2007-09-30 10:28:08 C:\WINDOWS\assembly\GAC_MSIL\PresentationUI\3.0.0.0__31bf3856ad364e35\PresentationUI.dll
----a-w 528,384 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\ReachFramework\3.0.0.0__31bf3856ad364e35\ReachFramework.dll
----a-w 94,208 2007-09-30 10:26:13 C:\WINDOWS\assembly\GAC_MSIL\SMDiagnostics\3.0.0.0__b77a5c561934e089\SMdiagnostics.dll
----a-w 401,408 2007-09-30 10:26:14 C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel\3.0.0.0__b77a5c561934e089\System.IdentityModel.dll
----a-w 126,976 2007-09-30 10:26:14 C:\WINDOWS\assembly\GAC_MSIL\System.IdentityModel.Selectors\3.0.0.0__b77a5c561934e089\System.IdentityModel.Selectors.dll
----a-w 131,072 2007-09-30 10:26:15 C:\WINDOWS\assembly\GAC_MSIL\System.IO.Log\3.0.0.0__b03f5f7f11d50a3a\System.IO.Log.dll
----a-w 884,736 2007-09-30 10:26:15 C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Serialization\3.0.0.0__b77a5c561934e089\System.Runtime.Serialization.dll
----a-w 5,623,808 2007-09-30 10:26:16 C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
----a-w 159,744 2007-09-30 10:26:20 C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.Install\3.0.0.0__b77a5c561934e089\System.ServiceModel.Install.dll
----a-w 16,384 2007-09-30 10:26:20 C:\WINDOWS\assembly\GAC_MSIL\System.ServiceModel.WasHosting\3.0.0.0__b77a5c561934e089\System.ServiceModel.WasHosting.dll
----a-w 688,128 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\System.Speech\3.0.0.0__31bf3856ad364e35\System.Speech.dll
----a-w 1,108,784 2007-09-30 10:33:29 C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
----a-w 1,641,272 2007-09-30 10:33:31 C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
----a-w 588,592 2007-09-30 10:33:30 C:\WINDOWS\assembly\GAC_MSIL\System.Workflow.Runtime\3.0.0.0__31bf3856ad364e35\System.Workflow.Runtime.dll
----a-w 163,840 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClient\3.0.0.0__31bf3856ad364e35\UIAutomationClient.dll
----a-w 372,736 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\UIAutomationClientsideProviders\3.0.0.0__31bf3856ad364e35\UIAutomationClientsideProviders.dll
----a-w 32,768 2007-09-30 10:28:09 C:\WINDOWS\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
----a-w 86,016 2007-09-30 10:28:08 C:\WINDOWS\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
----a-w 1,167,360 2007-09-30 10:28:03 C:\WINDOWS\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
----a-w 81,920 2007-09-30 10:28:10 C:\WINDOWS\assembly\GAC_MSIL\WindowsFormsIntegration\3.0.0.0__31bf3856ad364e35\WindowsFormsIntegration.dll
----a-w 499,712 2007-10-01 10:13:25 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\7e12b5d20c1f916e1e9cd09984fd2ce7\ComSvcConfig.ni.exe
----a-w 1,118,208 2007-10-01 10:13:32 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\34bb5f48543da64eb27bb33cf67bef80\Microsoft.Transactions.Bridge.ni.dll
----a-w 405,504 2007-10-01 10:13:36 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\67866b3c1ff291be35afd8ecb2c62e49\Microsoft.Transactions.Bridge.Dtc.ni.dll
----a-w 17,920 2007-09-30 10:29:19 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualC\99b84ab573bab171f6e6848998b44a92\Microsoft.VisualC.ni.dll
----a-w 1,568,768 2007-10-01 10:37:32 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\4876c8b358483ce23a2782f9d197b612\PresentationBuildTasks.ni.dll
----a-w 40,448 2007-09-30 10:30:33 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCFFRast#\159e424b3000e4f64874b911d7bb944e\PresentationCFFRasterizer.ni.dll
----a-w 11,984,896 2007-09-30 10:30:28 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationCore\e9a2cdc0bdee39803796536171f04f89\PresentationCore.ni.dll
----a-w 48,640 2007-09-30 10:33:08 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\e0ec8286791e8c5015df1b70e4643989\PresentationFontCache.ni.exe
----a-w 241,664 2007-09-30 10:32:46 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2bdb5ae985227f890900186a24e774b5\PresentationFramework.Classic.ni.dll
----a-w 14,680,064 2007-09-30 10:32:03 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\6850bca726ac35d859bd4bb07035802a\PresentationFramework.ni.dll
----a-w 270,336 2007-09-30 10:32:54 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9932341a96e9da69dd8891d3d5442c2d\PresentationFramework.Royale.ni.dll
----a-w 548,864 2007-09-30 10:32:49 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a30b140d481a1d20ea2fcfee30131216\PresentationFramework.Luna.ni.dll
----a-w 393,216 2007-09-30 10:33:00 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b58063000ef2a5bf18727dddbed97116\PresentationFramework.Aero.ni.dll
----a-w 1,982,464 2007-09-30 10:32:14 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationUI\46ce824bd8f28a6eb83f0feed8f63580\PresentationUI.ni.dll
----a-w 2,396,160 2007-09-30 10:32:25 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ReachFramework\cb3f7ee9f048f06f7aee49596b968f84\ReachFramework.ni.dll
----a-w 135,168 2007-10-01 10:13:40 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\2f67dbea37503724b2d987585e7a6776\ServiceModelReg.ni.exe
----a-w 286,720 2007-10-01 10:13:42 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\54f8c4141aef39b39b34e9a5f50f3ed3\SMDiagnostics.ni.dll
----a-w 323,584 2007-10-01 10:13:45 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMSvcHost\14aef755acc1aa535b8c1b527f48cbdb\SMSvcHost.ni.exe
----a-w 262,144 2007-10-01 10:37:54 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\sysglobl\4e4f4c072b9e3667765226bb6f55c0d6\sysglobl.ni.dll
----a-w 163,840 2007-09-30 10:29:36 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\2d189491f549da7b47e8fa17e11a7ebd\System.Configuration.Install.ni.dll
----a-w 1,179,648 2007-09-30 10:29:31 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\16fce99803b40a5c83bc90bb2286f714\System.Data.OracleClient.ni.dll
----a-w 2,695,168 2007-09-30 10:29:17 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\629ec1f67f5d7fc0e51974dfca58f955\System.Data.SqlXml.ni.dll
----a-w 241,664 2007-10-01 10:12:30 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\2b063381aee32c42c20f08a692646d22\System.IdentityModel.Selectors.ni.dll
----a-w 987,136 2007-10-01 10:12:26 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\cf62fae3c4a2995798178032d19389fc\System.IdentityModel.ni.dll
----a-w 421,888 2007-10-01 10:12:33 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IO.Log\738fd27b301b7de9117f0352d5e0e4c0\System.IO.Log.ni.dll
----a-w 655,360 2007-10-01 10:39:12 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Messaging\3594a9faba22c0675a6bf13d208004a5\System.Messaging.ni.dll
----a-w 1,118,208 2007-09-30 10:32:30 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Printing\e6d9829ef18eb4a067315d72db218e7b\System.Printing.ni.dll
----a-w 815,104 2007-09-30 10:29:23 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\26c1570fe809abff4561a43620a7b7e8\System.Runtime.Remoting.ni.dll
----a-w 2,363,392 2007-10-01 10:12:39 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\0345a4656b71d4e598fabe9567aeaf57\System.Runtime.Serialization.ni.dll
----a-w 339,968 2007-09-30 10:29:27 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\f705c0f476bbc5b6a3d99cddaf3ee220\System.Runtime.Serialization.Formatters.Soap.ni.dll
----a-w 17,534,976 2007-10-01 10:13:18 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\0db6cfbfed9e275dded9d6ed40a08b30\System.ServiceModel.ni.dll
----a-w 229,376 2007-09-30 10:29:34 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\e97fc85299404bfee69e3e3f174b87cc\System.ServiceProcess.ni.dll
----a-w 2,031,616 2007-10-01 10:37:48 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Speech\4c33f84403a9f4da09cb774cf3170875\System.Speech.ni.dll
----a-w 2,994,176 2007-09-30 10:34:01 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\aed7d4ed1d0e6faf4a81d823dc11388e\System.Workflow.Activities.ni.dll
----a-w 4,587,520 2007-10-01 10:38:36 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\84273b9e3067853107810062ec596675\System.Workflow.ComponentModel.ni.dll
----a-w 2,101,248 2007-10-01 10:39:06 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\faab60f220e8156cec9c528e44189db8\System.Workflow.Runtime.ni.dll
----a-w 483,328 2007-10-01 10:49:58 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\b38accaf98f64874b677dd28a97fbb77\UIAutomationClient.ni.dll
----a-w 1,118,208 2007-10-01 10:50:18 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\b586df6e718c560b9a359c0abac6f910\UIAutomationClientsideProviders.ni.dll
----a-w 50,688 2007-09-30 10:30:30 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\223c2311022a3c926b5cd66fe3fea055\UIAutomationProvider.ni.dll
----a-w 196,608 2007-09-30 10:30:31 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationTypes\994856a96d73485db9d141fbfd19e546\UIAutomationTypes.ni.dll
----a-w 3,272,704 2007-09-30 10:29:10 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\61cf534c75f1b13194cabda37d0de492\WindowsBase.ni.dll
----a-w 274,432 2007-10-01 10:50:38 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\f11dcf0473914677e4bf9a201bc58716\WindowsFormsIntegration.ni.dll
----a-w 380,928 2007-10-01 10:13:47 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WsatConfig\72664d5c089f175daf74a4b0dc05d3ac\WsatConfig.ni.exe
----a-w 181,760 2007-10-01 10:29:19 C:\WINDOWS\BDOSCAN8\bdcore.dll
----a-w 385,536 2007-09-21 13:53:44 C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll
----a-w 163,328 2007-09-19 21:46:25 C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
----a-w 6,651,904 2007-09-21 14:04:14 C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
----a-w 114,688 2007-09-21 14:04:15 C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
----a-w 163,328 2007-09-19 21:46:25 C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
----a-w 6,651,904 2007-09-21 14:03:56 C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
----a-w 114,688 2007-09-21 14:03:57 C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
------w 16,832 2006-11-07 08:06:47 C:\WINDOWS\Installer\tsclientmsitrans\tscinst.vbs
------w 12,451 2006-11-07 08:06:47 C:\WINDOWS\Installer\tsclientmsitrans\tscuinst.vbs
----a-r 26,694 2007-09-24 12:05:42 C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\ARPPRODUCTICON.exe
----a-r 26,694 2007-09-24 12:05:42 C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
----a-r 26,694 2007-09-24 12:05:42 C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\googleearth.exe_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
----a-r 65,536 2007-09-24 12:05:42 C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut1_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
----a-r 65,536 2007-09-24 12:05:42 C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\NewShortcut2_407B9B5CDAC54F44A756B57CAB4E6A8B.exe
----a-r 26,694 2007-09-24 12:05:42 C:\WINDOWS\Installer\{1E04F83B-2AB9-4301-9EF7-E86307F79C72}\UNINST_Uninstall_G_3DE5E7D47B88403CA3FD2017A8240C5B.exe
----a-w 74,012 2006-10-30 02:06:24 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\baseline.dat
----a-w 99,600 2006-10-30 01:25:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\DeleteTemp.exe
----a-w 220,672 2006-10-29 21:15:06 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\dlmgr.dll
----a-w 1,054,720 2006-10-29 21:17:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\gencomp.dll
----a-w 163,328 2006-10-29 21:14:26 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\HtmlLite.dll
----a-w 194,320 2006-10-30 01:25:54 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\RebootStub.exe
----a-w 167,176 2006-10-30 01:25:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\runmsi.exe
----a-w 365,320 2006-10-30 01:25:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
----a-w 80,384 2006-10-30 01:17:12 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1025.dll
----a-w 80,384 2006-10-30 01:17:30 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1028.dll
----a-w 86,016 2006-10-30 01:17:36 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1029.dll
----a-w 87,040 2006-10-30 01:17:44 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1030.dll
----a-w 89,600 2006-10-30 01:17:50 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1031.dll
----a-w 94,208 2006-10-30 01:17:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1032.dll
----a-w 82,944 2006-10-30 01:18:10 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1035.dll
----a-w 91,648 2006-10-30 01:18:16 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1036.dll
----a-w 80,384 2006-10-30 01:18:22 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1037.dll
----a-w 89,600 2006-10-30 01:18:30 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1038.dll
----a-w 88,064 2006-10-30 01:18:36 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1040.dll
----a-w 80,384 2006-10-30 01:18:42 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1041.dll
----a-w 80,384 2006-10-30 01:18:48 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1042.dll
----a-w 87,040 2006-10-30 01:18:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1043.dll
----a-w 83,968 2006-10-30 01:19:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1044.dll
----a-w 86,528 2006-10-30 01:19:08 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1045.dll
----a-w 84,480 2006-10-30 01:19:14 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1046.dll
----a-w 82,944 2006-10-30 01:19:28 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1049.dll
----a-w 83,968 2006-10-30 01:19:34 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1053.dll
----a-w 82,432 2006-10-30 01:19:42 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.1055.dll
----a-w 80,384 2006-10-30 01:17:24 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.2052.dll
----a-w 90,624 2006-10-30 01:19:22 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.2070.dll
----a-w 90,112 2006-10-30 01:18:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.3082.dll
----a-w 80,384 2006-10-29 21:15:20 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setupres.dll
----a-w 1,621,504 2006-10-29 21:15:22 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\SITSetup.dll
----a-w 590,848 2006-10-29 21:18:26 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\vs70uimgr.dll
----a-w 541,184 2006-10-29 21:20:20 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\vsbasereqs.dll
----a-w 816,128 2006-10-29 21:18:12 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\vsscenario.dll
----a-w 1,139,712 2006-10-29 21:16:52 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\vs_setup.dll
----a-w 98,816 2006-10-30 01:17:14 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1025.dll
----a-w 98,816 2006-10-30 01:17:30 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1028.dll
----a-w 99,840 2006-10-30 01:17:38 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1029.dll
----a-w 99,840 2006-10-30 01:17:44 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1030.dll
----a-w 102,400 2006-10-30 01:17:50 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1031.dll
----a-w 104,448 2006-10-30 01:17:58 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1032.dll
----a-w 98,816 2006-10-30 01:18:10 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1035.dll
----a-w 103,424 2006-10-30 01:18:16 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1036.dll
----a-w 98,816 2006-10-30 01:18:24 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1037.dll
----a-w 102,400 2006-10-30 01:18:30 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1038.dll
----a-w 101,376 2006-10-30 01:18:36 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1040.dll
----a-w 98,816 2006-10-30 01:18:42 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1041.dll
----a-w 98,816 2006-10-30 01:18:50 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1042.dll
----a-w 99,840 2006-10-30 01:18:56 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1043.dll
----a-w 98,816 2006-10-30 01:19:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1044.dll
----a-w 99,840 2006-10-30 01:19:08 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1045.dll
----a-w 99,328 2006-10-30 01:19:16 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1046.dll
----a-w 98,816 2006-10-30 01:19:28 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1049.dll
----a-w 98,816 2006-10-30 01:19:36 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1053.dll
----a-w 98,816 2006-10-30 01:19:42 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.1055.dll
----a-w 98,816 2006-10-30 01:17:24 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.2052.dll
----a-w 101,376 2006-10-30 01:19:22 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.2070.dll
----a-w 102,400 2006-10-30 01:18:04 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.3082.dll
----a-w 98,816 2006-10-29 21:18:36 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapRes.dll
----a-w 1,103,872 2006-10-29 21:19:30 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\WapUI.dll
----a-w 159,744 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ComSvcConfig.exe
----a-w 741,376 2006-10-30 01:33:58 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
----a-w 626,440 2007-09-30 10:26:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\install.exe
----a-w 80,896 2007-09-30 10:26:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\install.res.1033.dll
----a-w 352,256 2006-10-30 01:34:00 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.dll
----a-w 151,552 2006-10-30 01:34:00 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\Microsoft.Transactions.Bridge.Dtc.dll
----a-w 61,440 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelReg.exe
----a-w 11,264 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceMonikerSupport.dll
----a-w 94,208 2006-10-30 01:34:00 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMDiagnostics.dll
----a-w 122,880 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
----a-w 884,736 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.Runtime.Serialization.dll
----a-w 5,623,808 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
----a-w 159,744 2006-10-30 01:34:00 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.Install.dll
----a-w 16,384 2006-10-30 01:34:00 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.WasHosting.dll
----a-w 143,360 2006-10-30 01:34:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\WsatConfig.exe
----a-w 14,648 2006-07-25 19:32:00 C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Workflow Foundation\PerformanceCounterInstaller.exe
----a-w 797,696 2006-10-20 14:08:52 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\NaturalLanguage6.dll
----a-w 4,874,240 2006-10-20 14:09:02 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\NlsData0009.dll
----a-w 2,628,608 2006-10-20 12:03:40 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\NlsLexicons0009.dll
----a-w 72,992 2006-10-20 19:29:46 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PenIMC.dll
----a-w 32,768 2006-10-20 19:21:24 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationCFFRasterizer.dll
----a-w 36,864 2006-10-20 19:21:24 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
----a-w 106,272 2006-10-20 19:29:52 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationHostDLL.dll
----a-w 897,024 2006-10-20 19:21:26 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationUI.dll
----a-w 14,848 2006-10-20 19:21:26 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\XamlViewer\XamlViewer_v0300.exe
----a-w 27,648 2006-10-14 14:43:18 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\filterpipelineprintproc.dll
----a-w 751,104 2006-10-14 14:43:18 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\mxdwdrv.dll
----a-w 131,584 2006-10-14 14:42:40 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\mxdwdui.dll
----a-w 671,744 2006-10-14 14:44:44 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\printfilterpipelinesvc.exe
----a-w 124,416 2006-10-14 14:43:38 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\prntvpt.dll
----a-w 14,048 2006-06-29 11:07:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\spmsg2.dll
----a-w 213,216 2006-06-29 11:07:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\spuninst.exe
----a-w 22,752 2006-06-29 11:07:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\spupdsvc.exe
----a-w 376,320 2006-10-14 14:42:18 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\unidrv.dll
----a-w 510,464 2006-10-14 14:42:28 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\unidrvui.dll
----a-w 619,008 2006-10-14 14:40:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\unires.dll
----a-w 580,352 2006-10-14 18:21:58 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\xpsshhdr.dll
----a-w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\xpssvcs.dll
----a-w 34,304 2006-10-14 15:13:02 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\amd64\filterpipelineprintproc.dll
----a-w 737,792 2006-10-14 15:12:14 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\amd64\mxdwdrv.dll
----a-w 2,946,304 2006-10-14 18:09:04 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\amd64\xpssvcs.dll
----a-w 27,648 2006-10-14 14:43:18 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\i386\filterpipelineprintproc.dll
----a-w 751,104 2006-10-14 14:43:18 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\i386\mxdwdrv.dll
----a-w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\i386\xpssvcs.dll
----a-w 22,752 2006-06-29 11:07:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\update\spcustom.dll
----a-w 716,000 2006-06-29 11:07:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\update\update.exe
----a-w 371,424 2006-06-29 11:07:36 C:\WINDOWS\SoftwareDistribution\Download\4a70c28cb8115cefc13bb853867e3a00\update\updspapi.dll
----a-w 15,072 2005-10-12 23:18:45 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\spmsg.dll
----a-w 216,800 2005-10-12 23:18:45 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\spuninst.exe
----a-w 73,216 2006-10-04 13:32:58 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2gdr\magnify.exe
----a-w 55,296 2006-10-04 13:32:55 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2gdr\narrator.exe
----a-w 216,576 2006-10-04 13:32:58 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2gdr\osk.exe
----a-w 36,864 2006-10-04 13:38:06 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2gdr\umandlg.dll
----a-w 50,176 2006-10-04 13:32:57 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2gdr\utilman.exe
----a-w 73,216 2006-10-04 14:04:06 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2qfe\magnify.exe
----a-w 55,296 2006-10-04 14:04:05 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2qfe\narrator.exe
----a-w 216,576 2006-10-04 14:04:06 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2qfe\osk.exe
----a-w 36,864 2006-10-04 14:05:36 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2qfe\umandlg.dll
----a-w 50,176 2006-10-04 14:04:05 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\sp2qfe\utilman.exe
----a-w 22,752 2005-10-12 23:18:45 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\update\spcustom.dll
----a-w 727,776 2005-10-12 23:18:46 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\update\update.exe
----a-w 394,976 2005-10-12 23:18:49 C:\WINDOWS\SoftwareDistribution\Download\56002837f7a4e94042661b5a6da2fe88\update\updspapi.dll
----a-w 412,160 2006-10-24 10:30:20 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\photometadatahandler.dll
----a-w 14,640 2006-10-16 14:10:58 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\spmsg.dll
----a-w 221,488 2006-10-16 14:10:58 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\spuninst.exe
----a-w 23,856 2006-10-16 14:10:58 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\spupdsvc.exe
----a-w 716,288 2006-10-24 10:30:06 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\windowscodecs.dll
----a-w 352,256 2006-10-24 10:29:50 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\windowscodecsext.dll
----a-w 276,992 2006-10-24 10:30:00 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\wmphoto.dll
----a-w 23,856 2006-10-16 14:10:56 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\update\spcustom.dll
----a-w 742,192 2006-10-16 14:10:58 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\update\update.exe
----a-w 379,184 2006-10-16 14:10:58 C:\WINDOWS\SoftwareDistribution\Download\75dbb8bbff547dc1bae58bc8980482d5\update\updspapi.dll
----a-w 15,072 2005-10-12 23:15:25 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\spmsg.dll
----a-w 216,800 2005-10-12 23:15:26 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\spuninst.exe
----a-w 153,088 2006-10-11 16:24:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2gdr\p2p.dll
----a-w 104,960 2006-10-11 16:24:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2gdr\p2pgasvc.dll
----a-w 313,344 2006-10-11 16:24:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2gdr\p2pgraph.dll
----a-w 116,224 2006-10-11 16:24:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2gdr\p2pnetsh.dll
----a-w 553,984 2006-10-11 16:24:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2gdr\p2psvc.dll
----a-w 58,880 2006-10-11 16:24:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2gdr\pnrpnsp.dll
----a-w 153,088 2006-10-11 16:37:30 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\p2p.dll
----a-w 104,960 2006-10-11 16:37:30 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\p2pgasvc.dll
----a-w 313,344 2006-10-11 16:37:30 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\p2pgraph.dll
----a-w 115,712 2006-10-11 16:37:30 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\p2pnetsh.dll
----a-w 553,984 2006-10-11 16:37:30 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\p2psvc.dll
----a-w 58,880 2006-10-11 16:37:30 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\pnrpnsp.dll
----a-w 228,352 2006-09-26 09:14:52 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\sp2qfe\spru040c.dll
----a-w 22,752 2005-10-12 23:15:25 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\update\spcustom.dll
----a-w 727,776 2005-10-12 23:15:28 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\update\update.exe
----a-w 394,976 2005-10-12 23:15:45 C:\WINDOWS\SoftwareDistribution\Download\98b54ccb3140e178c9593938729d0006\update\updspapi.dll
----a-w 1,485,696 2007-04-24 09:32:06 C:\WINDOWS\SoftwareDistribution\Download\d219c5aa727ee8fc0f9eb775006e580a\legitcheckcontrol.dll
----a-w 14,640 2006-11-17 14:14:30 C:\WINDOWS\SoftwareDistribution\Download\d219c5aa727ee8fc0f9eb775006e580a\spmsg.dll
----a-w 742,192 2006-11-17 14:14:30 C:\WINDOWS\SoftwareDistribution\Download\d219c5aa727ee8fc0f9eb775006e580a\update\update.exe
----a-w 379,184 2006-11-17 14:14:30 C:\WINDOWS\SoftwareDistribution\Download\d219c5aa727ee8fc0f9eb775006e580a\update\updspapi.dll
----a-w 70,528 2007-04-24 09:30:24 C:\WINDOWS\SoftwareDistribution\Download\d219c5aa727ee8fc0f9eb775006e580a\update\wgacustom.dll
----a-w 15,072 2005-10-12 23:18:45 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\spmsg.dll
----a-w 216,800 2005-10-12 23:18:45 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\spuninst.exe
----a-w 116,736 2006-12-11 13:44:01 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\aaclient.dll
----a-w 600,576 2006-11-07 08:06:47 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\lhmstsc.exe
----a-w 1,866,240 2006-12-11 13:44:01 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\lhmstscx.dll
----a-w 288,768 2006-12-11 13:44:01 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\rhttpaa.dll
----a-w 16,832 2006-11-07 08:06:47 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\tscinst.vbs
----a-w 12,451 2006-11-07 08:06:47 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\tscuinst.vbs
----a-w 36,352 2006-12-11 13:44:01 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2gdr\tsgqec.dll
----a-w 116,736 2006-12-11 14:13:35 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\aaclient.dll
----a-w 600,576 2006-11-07 08:10:30 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\lhmstsc.exe
----a-w 1,866,240 2006-12-11 14:13:35 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\lhmstscx.dll
----a-w 288,768 2006-12-11 14:13:35 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\rhttpaa.dll
----a-w 16,832 2006-11-07 08:10:30 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\tscinst.vbs
----a-w 12,451 2006-11-07 08:10:30 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\tscuinst.vbs
----a-w 36,352 2006-12-11 14:13:35 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\sp2qfe\tsgqec.dll
----a-w 22,752 2005-10-12 23:18:45 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\update\spcustom.dll
----a-w 38,400 2006-12-11 13:44:01 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\update\tscupdatecustom.dll
----a-w 727,776 2005-10-12 23:18:46 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\update\update.exe
----a-w 394,976 2005-10-12 23:18:49 C:\WINDOWS\SoftwareDistribution\Download\ee445c4a35b1ba9cf93491ecb4e95f39\update\updspapi.dll
------w 116,736 2006-12-11 13:44:01 C:\WINDOWS\system32\aaclient.dll
----a-w 69,408 2006-10-20 19:29:46 C:\WINDOWS\system32\dxva2.dll
----a-w 478,496 2006-10-20 19:30:00 C:\WINDOWS\system32\evr.dll
----a-w 161,936 2007-10-01 06:46:46 C:\WINDOWS\system32\FNTCACHE.DAT
----a-w 35,328 2007-10-02 21:14:58 C:\WINDOWS\system32\hggecca.dll
----a-w 556,296 2006-10-30 01:33:58 C:\WINDOWS\system32\icardagt.exe
----a-w 9,480 2006-10-30 01:33:58 C:\WINDOWS\system32\icardres.dll
----a-w 83,968 2006-10-30 01:33:58 C:\WINDOWS\system32\infocardapi.dll
----a-w 1,485,696 2007-04-24 09:32:06 C:\WINDOWS\system32\LegitCheckControl.dll
----a-w 73,216 2006-10-04 13:32:58 C:\WINDOWS\system32\magnify.exe
----a-w 1,980,704 2006-10-20 19:30:06 C:\WINDOWS\system32\milcore.dll
----a-w 600,576 2006-11-07 08:06:47 C:\WINDOWS\system32\mstsc.exe
----a-w 1,866,240 2006-12-11 13:44:01 C:\WINDOWS\system32\mstscax.dll
----a-w 1,320,800 2007-05-15 13:43:10 C:\WINDOWS\system32\msxml6.dll
----a-w 86,728 2006-10-19 11:33:20 C:\WINDOWS\system32\msxml6r.dll
----a-w 55,296 2006-10-04 13:32:55 C:\WINDOWS\system32\narrator.exe
----a-w 216,576 2006-10-04 13:32:58 C:\WINDOWS\system32\osk.exe
----a-w 153,088 2006-10-11 16:24:45 C:\WINDOWS\system32\p2p.dll
----a-w 104,960 2006-10-11 16:24:45 C:\WINDOWS\system32\p2pgasvc.dll
----a-w 313,344 2006-10-11 16:24:45 C:\WINDOWS\system32\p2pgraph.dll
----a-w 116,224 2006-10-11 16:24:45 C:\WINDOWS\system32\p2pnetsh.dll
----a-w 553,984 2006-10-11 16:24:45 C:\WINDOWS\system32\p2psvc.dll
----a-w 69,314 2007-09-30 10:27:49 C:\WINDOWS\system32\perfc009.dat
----a-w 82,340 2007-09-30 10:27:49 C:\WINDOWS\system32\perfc00C.dat
----a-w 434,716 2007-09-30 10:27:49 C:\WINDOWS\system32\perfh009.dat
----a-w 503,118 2007-09-30 10:27:49 C:\WINDOWS\system32\perfh00C.dat
------w 412,160 2006-10-24 10:30:20 C:\WINDOWS\system32\photometadatahandler.dll
----a-w 58,880 2006-10-11 16:24:45 C:\WINDOWS\system32\pnrpnsp.dll
----a-w 104,224 2006-10-20 19:29:52 C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
----a-w 344,352 2006-10-20 19:29:58 C:\WINDOWS\system32\PresentationHost.exe
----a-w 20,768 2006-10-20 19:29:46 C:\WINDOWS\system32\PresentationHostProxy.dll
----a-w 769,312 2006-10-20 19:30:02 C:\WINDOWS\system32\PresentationNative_v0300.dll
------w 124,416 2006-10-14 14:43:38 C:\WINDOWS\system32\prntvpt.dll
----a-w 150,808 2006-08-24 14:15:06 C:\WINDOWS\system32\rgb9rast_2.dll
------w 288,768 2006-12-11 13:44:01 C:\WINDOWS\system32\rhttpaa.dll
------w 14,640 2006-10-16 14:10:58 C:\WINDOWS\system32\spmsg.dll
----a-w 23,856 2006-10-16 14:10:58 C:\WINDOWS\system32\spupdsvc.exe
----a-w 844,800 2007-07-22 16:39:27 C:\WINDOWS\system32\swreg.exe
------w 36,352 2006-12-11 13:44:01 C:\WINDOWS\system32\tsgqec.dll
----a-w 159,008 2006-10-20 19:29:54 C:\WINDOWS\system32\UIAutomationCore.dll
----a-w 36,864 2006-10-04 13:38:06 C:\WINDOWS\system32\umandlg.dll
----a-w 50,176 2006-10-04 13:32:57 C:\WINDOWS\system32\utilman.exe
------w 716,288 2006-10-24 10:30:06 C:\WINDOWS\system32\WindowsCodecs.dll
------w 352,256 2006-10-24 10:29:50 C:\WINDOWS\system32\WindowsCodecsExt.dll
------w 276,992 2006-10-24 10:30:00 C:\WINDOWS\system32\WMPhoto.dll
------w 580,352 2006-10-14 18:21:58 C:\WINDOWS\system32\XPSSHHDR.dll
------w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\system32\XpsSvcs.dll
-c--a-w 1,037,312 2007-09-21 07:56:21 C:\WINDOWS\system32\dllcache\explorer.exe
-c----w 27,648 2006-10-14 14:43:18 C:\WINDOWS\system32\dllcache\FilterPipelinePrintProc.dll
-c----w 73,216 2006-10-04 13:32:58 C:\WINDOWS\system32\dllcache\magnify.exe
-c----w 55,296 2006-10-04 13:32:55 C:\WINDOWS\system32\dllcache\narrator.exe
-c----w 216,576 2006-10-04 13:32:58 C:\WINDOWS\system32\dllcache\osk.exe
-c----w 153,088 2006-10-11 16:24:45 C:\WINDOWS\system32\dllcache\p2p.dll
-c----w 104,960 2006-10-11 16:24:45 C:\WINDOWS\system32\dllcache\p2pgasvc.dll
-c----w 313,344 2006-10-11 16:24:45 C:\WINDOWS\system32\dllcache\p2pgraph.dll
-c----w 116,224 2006-10-11 16:24:45 C:\WINDOWS\system32\dllcache\p2pnetsh.dll
-c----w 553,984 2006-10-11 16:24:45 C:\WINDOWS\system32\dllcache\p2psvc.dll
-c----w 58,880 2006-10-11 16:24:45 C:\WINDOWS\system32\dllcache\pnrpnsp.dll
-c----w 671,744 2006-10-14 14:44:44 C:\WINDOWS\system32\dllcache\PrintFilterPipelineSvc.exe
-c----w 36,864 2006-10-04 13:38:06 C:\WINDOWS\system32\dllcache\umandlg.dll
-c----w 50,176 2006-10-04 13:32:57 C:\WINDOWS\system32\dllcache\utilman.exe
-c----w 580,352 2006-10-14 18:21:58 C:\WINDOWS\system32\dllcache\XPSSHHDR.dll
-c----w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\system32\dllcache\XpsSvcs.dll
----a-w 751,104 2006-10-14 14:43:18 C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdrv.dll
----a-w 131,584 2006-10-14 14:42:40 C:\WINDOWS\system32\spool\drivers\w32x86\3\mxdwdui.dll
----a-w 376,320 2006-10-14 14:42:18 C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrv.dll
----a-w 510,464 2006-10-14 14:42:28 C:\WINDOWS\system32\spool\drivers\w32x86\3\unidrvui.dll
----a-w 619,008 2006-10-14 14:40:36 C:\WINDOWS\system32\spool\drivers\w32x86\3\unires.dll
----a-w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\system32\spool\drivers\w32x86\3\XpsSvcs.dll
----a-w 27,648 2006-10-14 14:43:18 C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
------w 671,744 2006-10-14 14:44:44 C:\WINDOWS\system32\spool\prtprocs\w32x86\PrintFilterPipelineSvc.exe
----a-w 34,304 2006-10-14 15:13:02 C:\WINDOWS\system32\spool\prtprocs\x64\filterpipelineprintproc.dll
----a-w 737,792 2006-10-14 15:12:14 C:\WINDOWS\system32\spool\XPSEP\amd64\mxdwdrv.dll
----a-w 2,946,304 2006-10-14 18:09:04 C:\WINDOWS\system32\spool\XPSEP\amd64\xpssvcs.dll
----a-w 737,792 2006-10-14 15:12:14 C:\WINDOWS\system32\spool\XPSEP\amd64\amd64\mxdwdrv.dll
----a-w 2,946,304 2006-10-14 18:09:04 C:\WINDOWS\system32\spool\XPSEP\amd64\amd64\xpssvcs.dll
----a-w 751,104 2006-10-14 14:43:18 C:\WINDOWS\system32\spool\XPSEP\i386\mxdwdrv.dll
----a-w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\system32\spool\XPSEP\i386\xpssvcs.dll
----a-w 751,104 2006-10-14 14:43:18 C:\WINDOWS\system32\spool\XPSEP\i386\i386\mxdwdrv.dll
----a-w 1,698,048 2006-10-14 18:22:00 C:\WINDOWS\system32\spool\XPSEP\i386\i386\xpssvcs.dll
----a-w 304,928 2006-10-20 19:29:54 C:\WINDOWS\system32\XPSViewer\XPSViewer.exe
----atw 16,384 2007-10-02 21:13:39 C:\WINDOWS\Temp\Perflib_Perfdata_188.dat
.
----a-w 109,056 2007-07-19 22:47:22 C:\WINDOWS\catchme.exe
----a-w 181,248 2007-09-19 19:24:13 C:\WINDOWS\BDOSCAN8\bdcore.dll
----a-w 158,752 2007-04-04 18:57:48 C:\WINDOWS\system32\FNTCACHE.DAT
----a-w 1,474,864 2006-12-12 08:45:04 C:\WINDOWS\system32\LegitCheckControl.DLL
----a-w 73,216 2004-08-05 11:00:00 C:\WINDOWS\system32\magnify.exe
----a-w 411,648 2004-08-05 11:00:00 C:\WINDOWS\system32\mstsc.exe
----a-w 655,360 2004-08-05 11:00:00 C:\WINDOWS\system32\mstscax.dll
----a-w 55,296 2004-08-05 11:00:00 C:\WINDOWS\system32\narrator.exe
----a-w 216,576 2004-08-05 11:00:00 C:\WINDOWS\system32\osk.exe
----a-w 116,224 2004-08-05 11:00:00 C:\WINDOWS\system32\p2p.dll
----a-w 86,016 2004-08-05 11:00:00 C:\WINDOWS\system32\p2pgasvc.dll
----a-w 312,320 2004-08-05 11:00:00 C:\WINDOWS\system32\p2pgraph.dll
----a-w 88,064 2004-08-05 11:00:00 C:\WINDOWS\system32\p2pnetsh.dll
----a-w 526,848 2004-08-05 11:00:00 C:\WINDOWS\system32\p2psvc.dll
----a-w 62,678 2007-09-15 12:14:05 C:\WINDOWS\system32\perfc009.dat
----a-w 75,704 2007-09-15 12:14:05 C:\WINDOWS\system32\perfc00C.dat
----a-w 401,398 2007-09-15 12:14:05 C:\WINDOWS\system32\perfh009.dat
----a-w 468,728 2007-09-15 12:14:05 C:\WINDOWS\system32\perfh00C.dat
----a-w 48,640 2004-08-05 11:00:00 C:\WINDOWS\system32\pnrpnsp.dll
------w 14,640 2006-09-25 16:58:48 C:\WINDOWS\system32\spmsg.dll
----a-w 23,856 2006-09-25 16:58:48 C:\WINDOWS\system32\spupdsvc.exe
----a-w 279,552 2007-07-22 16:39:27 C:\WINDOWS\system32\swreg.exe
----a-w 36,864 2004-08-05 11:00:00 C:\WINDOWS\system32\umandlg.dll
----a-w 50,176 2004-08-05 11:00:00 C:\WINDOWS\system32\utilman.exe
-c----w 1,037,312 2007-06-13 13:22:28 C:\WINDOWS\system32\dllcache\explorer.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8CEFE835-8EBF-420F-AFA2-807008E32917}]
2007-10-02 23:14 35328 --a------ C:\WINDOWS\system32\hggecca.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-15 00:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-15 00:26]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2004-11-12 18:57]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2005-01-14 17:45]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-11-17 11:56]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-08-03 02:05]
"TFncKy"="TFncKy.exe" []
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-12-09 15:32]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 17:22]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"TPSMain"="TPSMain.exe" [2005-01-21 11:28 C:\WINDOWS\system32\TPSMain.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 13:48]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 08:27]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2004-12-21 10:48]
"NDSTray.exe"="NDSTray.exe" []
"LogitechVideo[inspector]"="C:\Program Files\Logitech\Video\InstallHelper.exe" [2005-12-07 10:33]
"LogitechCameraAssistant"="C:\Program Files\Logitech\Video\CameraAssistant.exe" [2005-12-07 10:26]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 21:05]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 23:37 C:\WINDOWS\agrsmmsg.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"osfvvffrp"="C:\WINDOWS\system32\osfvvffrp.exe" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"osfvvffrp"=C:\WINDOWS\system32\osfvvffrp.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8CEFE835-8EBF-420F-AFA2-807008E32917}"= C:\WINDOWS\system32\hggecca.dll [2007-10-02 23:14 35328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggecca]
hggecca.dll 2007-10-02 23:14 35328 C:\WINDOWS\system32\hggecca.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qomklli]
qomklli.dll 2007-10-01 22:38 35328 C:\WINDOWS\system32\qomklli.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=C:\WINDOWS\pss\Outil de mise à jour Google.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

R3 dsNcAdpt;Juniper Network Connect Adapter;C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys
R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-10-01 17:07:05 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-10-01 06:50:41 C:\WINDOWS\Tasks\User_Feed_Synchronization-{1D67CFC6-09AB-49AD-A8DE-DBF5CC62B2D6}.job"
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista
0
je t'envoie en plus un highjack.... pour le plaisir il y a encore un fichier en 02 et en 020 un autre et tous les deux sont douteux!!!!


-----------------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 23:48:39, on 02/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system\NOTEPAD.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ElkCtrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\LGV\Bureau\virus\scanner.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.cri.univ-nantes.fr/cache.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5AB80EBE-5268-4D68-B574-5A581D2560BB} - C:\WINDOWS\system32\fccca.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKLM\..\RunServices: [osfvvffrp] C:\WINDOWS\system32\osfvvffrp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - https://onlinelibrary.wiley.com/action/cookieAbsent
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
O16 - DPF: {0585238B-9CA6-4CCB-A9B2-FE4BA495E880} (AXWebMon Control) - http://fwdservice.com
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - http://happywash.dnsalias.com:81/activex/AMC.cab
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - https://nomade.univ-nantes.fr/dana-cached/setup/JuniperSetup.cab
O20 - Winlogon Notify: hggecca - C:\WINDOWS\SYSTEM32\hggecca.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Print Spooler Service (isoaci6fayceqeg) - Unknown owner - C:\WINDOWS\system32\osfvvffrp.exe (file missing)
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NOTEPAD - Unknown owner - C:\WINDOWS\system\NOTEPAD.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
0
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
1 oct. 2007 à 23:51
re,


1. Télécharge The Avenger par Swandog46 sur ton Bureau:

http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/

Click sur Avenger.zip pour ouvrir le fichier
Extraire avenger.exe sur votre bureau

2. Copie tout le texte en gras ci-dessous : mettre en surbrillance et appuyer sur les touches(Ctrl+C):

Files to delete:
C:\WINDOWS\system32\qomklli.dll
C:\WINDOWS\system32\byxvssp.dll
C:\WINDOWS\system32\nnnlmno.dll
C:\WINDOWS\system32\ddcbxwu.dll
C:\WINDOWS\system32\pmnkjkh.dll
C:\WINDOWS\system32\urqoopn.dll
C:\WINDOWS\system32\iifefge.dll
C:\WINDOWS\system32\jkkhede.dll
C:\WINDOWS\system32\ddcdeca.dll
C:\WINDOWS\system32\ddccdcb.dll


3. Maintenant, lance The Avenger en cliquant sur son icône du bureau.
Sous "Script file to execute" choisir "Input Script Manually".
Puis clique sur l'icône en forme de loupe qui va ouvrir une nouvelle fenêtre "View/edit script"
Dans cette fenêtre, colle le texte précedemment copié sur le bureau par les touches (Ctrl+V).
Cliquer Done
ensuite clique sur l'icône en forme de Feu Vert pour démarrer l'exécution du script
Réponds "Yes" deux fois quand demandé.

4. The Avenger va automatiquement faire ce qui suit:
Il va Re-démarrer le système.
Pendant le re-démarrage, il apparaitra brièvement une fenêtre de commande de windows noire sur ton bureau, ceci est NORMAL.
Après le re-démarrage, il crée un fichier log qui s'ouvrira, faisant apparaitre les actions exécutées par The Avenger. Ce fichier log se trouve ici : C:\avenger.txt

5. Pour finir copie/colle le contenu du ficher c:\avenger.txt

a+
0
voila mon rapport.... c'est grave?? je suis encore infecté???

_________________________________________________________________________________

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\clwieidp

*******************

Script file located at: \??\C:\Documents and Settings\ghxqldcq.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\qomklli.dll deleted successfully.
File C:\WINDOWS\system32\byxvssp.dll deleted successfully.
File C:\WINDOWS\system32\nnnlmno.dll deleted successfully.
File C:\WINDOWS\system32\ddcbxwu.dll deleted successfully.
File C:\WINDOWS\system32\pmnkjkh.dll deleted successfully.
File C:\WINDOWS\system32\urqoopn.dll deleted successfully.
File C:\WINDOWS\system32\iifefge.dll deleted successfully.
File C:\WINDOWS\system32\jkkhede.dll deleted successfully.
File C:\WINDOWS\system32\ddcdeca.dll deleted successfully.
File C:\WINDOWS\system32\ddccdcb.dll deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
0
c'est la cata ce matin mon ordi me demande un mot de passe pour ma session (alors que je ne n'en ai jamais créé ) et il refuse de m'ouvrir ma session ????? je pete un cable
0
impossible de démarrer mon ordi il me demande toujours un mot de passe ??? c'est halucinant je vais l'exploser.... please help me
0
Bonjour, je crois que là.... c'est mort pour mon ordi..... je l'ai donné a un informaticien qui essaie de me sauvegarder les données en passant par le reseau de la fac.... sous linux (impossibilité de faire sauter le mot de passe et donc d'utiliser XP) demain il va essayer pour l'instant c'est un peu compliqué m'a t il dit alors j'espere qu'il va me recuoerer mes données...did71 je te remercie pour ton aide si tu veux je te tiens au courant...en tous cas je devais avoir un gros virus : peut etre nouveau???

je resume pour les gens qui lirait ce message : ca a commencer avec des messages d'erreur rundll puis le plantage systématique de spybot.... puis le plantage de windows XP en une journée... sans compter les pages internet qui s'ouvraient mais je pense que ça c'est pas lié voilà.... ma maigre contribution


ton avis ?? did71??? j'avais quoi comme virus<??????
0
did71 Messages postés 2187 Date d'inscription vendredi 24 mars 2006 Statut Contributeur sécurité Dernière intervention 30 janvier 2010 36
2 oct. 2007 à 20:38
Bonsoir,

tu avais vundo résistant mais on aurait pu le nettoyer tout de même!

Si tu avais le CD de XP, on aurait pu tenter une réparation pour supprimer ce mot de passe et ensuite continuer!

En espèrant que tout se passe pour le mieux pour tes données!

Bonne soirée

a+
0