HjackThis ci-joint - Plus de connection Internet....
Forum Sécurité - Virus : HjackThis ci-joint - Plus de connection Internet....
Bonjour. J'écris ceci depuis un vieux portable, mon PC contaminé ne pouvant plus accéder à Internet. Je disposais de BitDefender et A-Squared, que j'ai enlevés pour les remplacer ( après l'infection ) par ces bons ? vieux Avast et ZoneAlarm. J'ai lu et tenté d'appliquer ce que j'ai lu : mode sans échec, patati, patata... Sans succès. Je dispose sur le PC contaminé de Hijackthis, VundoFix, OTOmoveIt, ComboFix... Rien n' y fait. J'espère recevoir le soutien rapide et éclairé d'un aimable connaisseur ? C-joint le HijackThis report, avec entre autres les 2 explorer.exe en route... Merci d'avance, car je suis manifestement au bout du rouleau de mes infimes comptétences....
Logfile of HijackThis v1.99.1
Scan saved at 10:59:15, on 24/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Flash Module - {85911752-BC96-4fff-9121-6EB9D8F438E1} - hyperconn.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: C:\WINDOWS\System32\jkd845jg.dll - {B5AC49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\System32\jkd845jg.dll (file missing)
O2 - BHO: C:\WINDOWS\System32\d4ghggf4g.dll - {B5AF0562-94F3-42BD-F434-2604812C297D} - C:\WINDOWS\System32\d4ghggf4g.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O10 - Broken Internet access because of LSP provider 'rsvp322.dll' missing
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{424990FD-6194-467C-8C7C-3E6A62E975FB}: NameServer = 85.255.116.78,85.255.112.126
O17 - HKLM\System\CCS\Services\Tcpip\..\{500A7054-443F-4997-A078-51BC92DA1369}: NameServer = 85.255.116.78,85.255.112.126
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1082F44-3F0E-4F7A-9083-30B2D0DBCEC9}: NameServer = 85.255.116.78,85.255.112.126
O17 - HKLM\System\CS9\Services\Tcpip\Parameters: NameServer = 85.255.116.78 85.255.112.126
O17 - HKLM\System\CS9\Services\Tcpip\..\{424990FD-6194-467C-8C7C-3E6A62E975FB}: NameServer = 85.255.116.78,85.255.112.126
O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 85.255.116.78 85.255.112.126
O17 - HKLM\System\CS10\Services\Tcpip\..\{424990FD-6194-467C-8C7C-3E6A62E975FB}: NameServer = 85.255.116.78,85.255.112.126
O17 - HKLM\System\CS11\Services\Tcpip\Parameters: NameServer = 85.255.116.78 85.255.112.126
O17 - HKLM\System\CS11\Services\Tcpip\..\{424990FD-6194-467C-8C7C-3E6A62E975FB}: NameServer = 85.255.116.78,85.255.112.126
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.78 85.255.112.126
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Microsoft Inet Service - Unknown owner - C:\WINDOWS\System32\_svchost.exe (file missing)
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Salut,
Télécharge FixWareout (d'Andy Manchesta) sur le Bureau.
>>Deuxième lien<<
Double clique sur FixWareout.exe, : clique sur Next puis Install.
Run fixit doit être coché, enfin clique sur Finish.
Suis les messages à l'écran. Ton ordinateur devra redémarrer, accepte. Le démarrage sera légèrement plus long que d'habitude.
Poste le rapport >C:\fixwareout\report.txt<
Accompagné d'un nouveau log HiJackThis.
Message édité par XmichouX le 24-11-2007 à 12:02:15
Répondre à XmichouX
Merci pour la réponse rapide. Voici les résultats : Username "***" - 24/11/2007 12:52:31 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.78 85.255.112.126" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{424990FD-6194-467C-8C7C-3E6A62E975FB}
"nameserver"="85.255.116.78,85.255.112.126" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{500A7054-443F-4997-A078-51BC92DA1369}
"nameserver"="85.255.116.78,85.255.112.126" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F1082F44-3F0E-4F7A-9083-30B2D0DBCEC9}
"nameserver"="85.255.116.78,85.255.112.126" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{424990FD-6194-467C-8C7C-3E6A62E975FB}
"DhcpNameServer"="85.255.116.78,85.255.112.126" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{500A7054-443F-4997-A078-51BC92DA1369}
"DhcpNameServer"="85.255.116.78,85.255.112.126" <Value cleared.
Cache de résolution DNS vidé.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"DVD43"="C:\\PROGRA~1\\DVDREG~1\\DVDRegionFree.exe /hidden"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"MsmqIntCert"="regsvr32 /s mqrt.dll"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
--------------------
Logfile of HijackThis v1.99.1
Scan saved at 13:05:12, on 24/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Flash Module - {85911752-BC96-4fff-9121-6EB9D8F438E1} - hyperconn.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: C:\WINDOWS\System32\jkd845jg.dll - {B5AC49A2-94F3-42BD-F434-2604812C897D} - C:\WINDOWS\System32\jkd845jg.dll (file missing)
O2 - BHO: C:\WINDOWS\System32\d4ghggf4g.dll - {B5AF0562-94F3-42BD-F434-2604812C297D} - C:\WINDOWS\System32\d4ghggf4g.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O10 - Broken Internet access because of LSP provider 'rsvp322.dll' missing
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 85.255.116.78 85.255.112.126
O17 - HKLM\System\CS10\Services\Tcpip\..\{424990FD-6194-467C-8C7C-3E6A62E975FB}: NameServer = 85.255.116.78,85.255.112.126
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Microsoft Inet Service - Unknown owner - C:\WINDOWS\System32\_svchost.exe (file missing)
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Re,
Télécharge SDFix (d'Andy Manchesta)
Enregistre le sur ton le bureau.
Lance le.
Fais install afin qu'il puisse s'extraire.
Redémarre en mode sans échec
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\
Lance SDFix.
Double clique sur RunThis.bat .
Appuie sur Y pour le lancer.
Il te sera demandé d'appuyer sur une touche pour redemarrer , fais le
Il est probable que le redémarrage soit un peu plus long que d'habitude.
Une fois l'apparition de ton Bureau, il affichera Finished
Appuie sur une touche.
Un rapport est généré , poste le dans ta réponse.
Il se trouve également. dans le dossier SDFix >Report.txt<
Repasse une fois FixWareout, poste le rapport.
Message édité par XmichouX le 24-11-2007 à 13:42:55
Répondre à XmichouX
Re-itou,
Voici les 2 reports : ( sorry pour le délai, mais je dois jongler avec les 2 PC et lecteur usb.. )
SDFix: Version 1.115
Run by *** on 24/11/2007 at 14:10
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
symavc32
Path:
\??\C:\WINDOWS\system32\drivers\symavc32.sys
symavc32 - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\257234~1 - Deleted
C:\WINDOWS\mljul0.exe - Deleted
C:\WINDOWS\system32\cmds.txt - Deleted
C:\WINDOWS\system32\conf.dat - Deleted
C:\WINDOWS\system32\cookie1.dat - Deleted
C:\WINDOWS\system32\cs.dat - Deleted
C:\WINDOWS\system32\drivers\symavc32.sys - Deleted
C:\WINDOWS\system32\hyperconn.dll - Deleted
C:\WINDOWS\system32\kr_done1 - Deleted
C:\WINDOWS\system32\ps1.dat - Deleted
C:\WINDOWS\system32\qtplugin.exe - Deleted
C:\WINDOWS\system32\rc.dat - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll.cla - Deleted
Could Not Remove C:\WINDOWS\system32\wsnpoem\audio.dll
Could Not Remove C:\WINDOWS\system32\wsnpoem\video.dll
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 14:29:45
Windows 5.1.2600 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\SYSTEM32\ntos.exe 196608 bytes
C:\WINDOWS\SYSTEM32\wsnpoem
C:\WINDOWS\SYSTEM32\wsnpoem\audio.dll 49152 bytes
C:\WINDOWS\SYSTEM32\wsnpoem\video.dll 49152 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 4
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
C:\WINDOWS\system32\wsnpoem\audio.dll Found
C:\WINDOWS\system32\wsnpoem\audio.dll.cla Found
C:\WINDOWS\system32\wsnpoem\video.dll Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 21 Jun 2003 377,344 A..H. --- "C:\Program Files\Smart Projects\IsoBuster\Help\AHlp.exe"
Finished!
-------------------
Username "***" - 24/11/2007 14:35:11 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Cache de résolution DNS vidé.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"DVD43"="C:\\PROGRA~1\\DVDREG~1\\DVDRegionFree.exe /hidden"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"MsmqIntCert"="regsvr32 /s mqrt.dll"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
Repasse un coup SDFix, poste le rapport .
Accompagné d'un nouveau Hijackthis
Répondre à XmichouX
Michou, tu dois peut-etre savoir déjà que le message : impossible de charger le service ... accompagne toujours SDFix, à l'aller comme au retour...
Voici ce que dela donne :
SDFix: Version 1.115
Run by *** on 24/11/2007 at 15:19
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\wsnpoem\audio.dll.cla - Deleted
Could Not Remove C:\WINDOWS\system32\wsnpoem\audio.dll
Could Not Remove C:\WINDOWS\system32\wsnpoem\video.dll
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 15:37:49
Windows 5.1.2600 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\SYSTEM32\ntos.exe 196608 bytes
C:\WINDOWS\SYSTEM32\wsnpoem
C:\WINDOWS\SYSTEM32\wsnpoem\audio.dll 16384 bytes
C:\WINDOWS\SYSTEM32\wsnpoem\video.dll 49152 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 4
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
C:\WINDOWS\system32\wsnpoem\audio.dll Found
C:\WINDOWS\system32\wsnpoem\video.dll Found
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 21 Jun 2003 377,344 A..H. --- "C:\Program Files\Smart Projects\IsoBuster\Help\AHlp.exe"
Finished!
--------------
Logfile of HijackThis v1.99.1
Scan saved at 15:42:48, on 24/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O10 - Broken Internet access because of LSP provider 'rsvp322.dll' missing
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 85.255.116.78 85.255.112.126
O17 - HKLM\System\CS10\Services\Tcpip\..\{424990FD-6194-467C-8C7C-3E6A62E975FB}: NameServer = 85.255.116.78,85.255.112.126
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Microsoft Inet Service - Unknown owner - C:\WINDOWS\System32\_svchost.exe (file missing)
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Que des fichiers très résistants à ce que j'ai vu.
On va utiliser puissant, alors sois prudent.
Relance HiJackThis, do a system scan only, coche ces lignes :
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\System32\ntos.exe,
|
Puis Fix Checked !
Sélectionne le contenu du cadre ci-dessous :
Files to delete:
|
Copie-colle le contenu précis de ce cadre dans ton bloc note en l’ouvrant.
Il ne doit manquer aucune ligne !
Enregistre ce fichier sur ton bureau que tu renommeras remove.txt
Télécharge The Avenger (de Swandog46)
Dézippe le sur ton bureau.
Lance le en double cliquant sur l’exe puis fais ok.
Sélectionne Load Script from File et clique sur l'cône en forme de dossier à droite.
Sélectionne ton fichier remove.txt se trouvant sur le bureau.
Clique sur le feu vert puis sur oui.
Le programme va te demander de redémarrer ton pc, accepte.
Poste le rapport qui se trouve ici >>C:\avenger.txt<<
+++++++++++
Télécharge WinsockXPFix.exe
Double clique sur WinsockXPFix.exe.
Tout d'abord, cliquez sur le boutton ReG-Backup. Cela sauvegardera ton registre par précaution.
Clique sur OK, et encore une fois. Tu verras une fenêtre de sauvegarde de ton registre, tu cliqueras une nouvelle fois sur OK.
Retourne à la fenêtre principale. Cliquez sur Fix. Cliquez sur Yes. Il se lancera pendant une minute ou deux et un bip se fera entendre et vous verrez cette fenêtre.
Finalement, cliquez sur OK et laissez votre PC redémarrer.
Répondre à XmichouX
Voilà qui est fait ; Avenger et WinsockXPFix.exe.
L' OS est en train de redémarrer
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\avvicjnf
*******************
Script file located at: \??\C:\WINDOWS\System32\yxyxtgki.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\SYSTEM32\ntos.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\wsnpoem\audio.dll deleted successfully.
File C:\WINDOWS\SYSTEM32\wsnpoem\video.dll deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Bien, je vérifie par précaution.
Repasse SDFix et poste moi le rapport.
De plus :
Aller dans poste de travail>outils>option des dossiers>affichage>afficher les fichiers et dossiers cachés. - - > Appliquer - - > OK
Aller dans poste de travail>outils>option des dossiers>affichage>décocher masquer les fichiers protégés du système d’exploitation. - - > Appliquer - - > OK
(Tu recoches après)
Dis moi le contenu de ce dossier : C:\WINDOWS\SYSTEM32\wsnpoem\
Répondre à XmichouX
OK je vais faire cela d'ici quelques minutes. J'ai essayé de me connecter à Internet : je parviens bien à atteindre mon provider et à refaire ma configuration provider avec succès, mais je n'atteins aucune autre page... A +
Dis moi le contenu de ce dossier : C:\WINDOWS\SYSTEM32\wsnpoem\
= : audio.dll.cla - Fichier CLA -2 ko
Effectivement....
SDFix: Version 1.115
Run by *** on 24/11/2007 at 18:03
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\wsnpoem\audio.dll.cla - Deleted
Folder C:\WINDOWS\system32\wsnpoem - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 18:16:04
Windows 5.1.2600 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Sat 21 Jun 2003 377,344 A..H. --- "C:\Program Files\Smart Projects\IsoBuster\Help\AHlp.exe"
Finished!
Merci pour ton aide précieuse Michou... Je pense qu'au niveau virus, malwares et autres plaisanteries du même goût tu m'as sauvé des eaux... Il me reste désormais à découvrir pourquoi je ne peux nonobstant toujours pas accéder à Internet...
Ceci dit.. Il me reste le gros souci suivant, qui explique probablement le reste : Generic Host proces for win 32 services tente de se connecter à Internet. Je viens de lui barrer la route " définitivement " via ZoneAlarme... Il est donc toujours bel et bien là... et me barre quant à lui la route à Internet
Re,
Reposte un Hijackthis
Répondre à XmichouX
Re-itou,
Je ne sais pas comment, mais j'ai récupéré l'accès à internet. J'avais barré la route à ce Generic dans ZoneAlarme, puis j'ai en désespoir de cause supprimé quelque chose d'un tout autre nom dans ZonAlamrm, et Internet m'est revenu... Pour combien de temps ?
Allez, encore un peu de lecture ? merci Michou
Logfile of HijackThis v1.99.1
Scan saved at 09:29:04, on 25/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1082F44-3F0E-4F7A-9083-30B2D0DBCEC9}: NameServer = 172.19.3.1,172.19.3.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Re,
Tu avais bien coché cette ligne ?
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\System32\ntos.exe, |
++++++++++++++
Télécharge sur ton bureau : Clean (de Malekal)
Dézippe le sur ton bureau. Double-clic sur ce dossier clean.
Double-clic sur clean.cmd. Cela va ouvrir une fenêtre noire.
Un menu va apparaître, choisis l'option 1 puis entrée. Ensuite appuies sur une touche comme il te sera demandé et poste le rapport ici.
Le rapport se trouve ici : C:\rapport_clean.txt
Tuto
Si tu obtiens un fichier C:\upload_moi.zip, merci de faire ceci.
+++++++++++++
Désinstalle avast, redémarre et supprime ~~>C:\Program Files\Alwil Software
Télécharge ccleaner (>>tuto à lire !<<), tu download «the latest version » puis installe le en décochant - Ajouter la Barre d'Outils Yahoo! CCleaner
Puis lance le nettoyage, puis fais chercher des erreurs et sauvegardes si tu le souhaites.
Télécharge et installe Antivir. (tuto)
Pourquoi changer ? Avast vs Antivir
Vérifie qu’il soit bien à jour ! Fais une analyse complète, poste le rapport.
Répondre à XmichouX
Re-itou,
Clean accompli, C:\upload_moi.zip upload accompli
Je vais faire maintenant ce que tu me dis concernant CCCleaner, Alvast / antivir... A +
-------------
25/11/2007 a 11:37:45,17
*** Recherche des fichiers dans C:
*** Recherche des fichiers dans C:\WINDOWS\
C:\WINDOWS\windebug.log FOUND
C:\WINDOWS\windebug.log FOUND
*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\bdod.bin FOUND
C:\WINDOWS\system32\RadLightMPCUninstall.exe FOUND
C:\WINDOWS\system32\SpoonUninstall.exe FOUND
C:\WINDOWS\SYSTEM\MAPI32.DLL FOUND
"C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND
*** Recherche des fichiers dans C:\Program Files
C:\PROGRA~1\PERFEC~1\ FOUND
"C:\Program Files\Multi_Media\" FOUND
Télécharge AVG Anti-Spyware Installes-le.
Lance AVG et fais une mise à jour.
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglet comment réagir, clique sur Actions recommandées. Choisis Quarantaine.
Ne fais pas d’analyse pour le moment.
Redémarre en mode sans échec
/!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\
Relance Avg.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas.
Clique sur "Enregistrer le rapport". Ceci génère un rapport qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
Poste le ici.
&
Toujours en mode sans échec, relance clean et fais l'option 2, poste le rapport.
Répondre à XmichouX
Re-Michou... C'est pas gagné... ( voir ci-dessous... )
Aussi : depuis tout ce temps, je fonctionne en " désactiver la restauration du système " décochée... Une influence ?
Et après le passage du scan AntiVir, je viens de récupérer la liste des programmes installés dans " ajouter / supprimer des programmes installés " dans PDC, laquelle liste était jusqu'alors ... vide !
Pour te répondre au sujet de : Tu avais bien coché cette ligne ?
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\System32\ntos.exe,
j'avaus lu et relu et reparcouru 3 x avant de cliquer sur fix...
-----------
AntiVir PersonalEdition Classic
Report file date: dimanche 25 novembre 2007 12:55
Scanning for 941284 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (plain) [5.1.2600]
Username: SYSTEM
Computer name: ***T
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:30
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:52
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:48
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:22
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 11:53:14
ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 11:53:14
ANTIVIR2.VDF : 7.0.1.0 1393152 Bytes 23/11/2007 11:53:16
ANTIVIR3.VDF : 7.0.1.4 11776 Bytes 23/11/2007 11:53:16
AVEWIN32.DLL : 7.6.0.34 3125760 Bytes 25/11/2007 11:53:20
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:28
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:18
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:02
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:08
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:34
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:20
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:44
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:14
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:38
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:22
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: dimanche 25 novembre 2007 12:55
The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'MQTGSVC.EXE' - '1' Module(s) have been scanned
Scan process 'NLClient.exe' - '1' Module(s) have been scanned
Scan process 'fxssvc.exe' - '1' Module(s) have been scanned
Scan process 'mqsvc.exe' - '1' Module(s) have been scanned
Scan process 'symlcsvc.exe' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'PAStiSvc.exe' - '1' Module(s) have been scanned
Scan process 'snmp.exe' - '1' Module(s) have been scanned
Scan process 'tcpsvcs.exe' - '1' Module(s) have been scanned
Scan process 'NLSVC.EXE' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Module is infected -> 'C:\DOCUME~1\JEAN-M~1\LOCALS~1\Temp\winlogon.exe'
Scan process 'qttask.exe' - '1' Module(s) have been scanned
Scan process 'zlclient.exe' - '0' Module(s) have been scanned
Scan process 'inetinfo.exe' - '1' Module(s) have been scanned
Scan process 'msdtc.exe' - '1' Module(s) have been scanned
Scan process 'EXPLORER.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'VSMON.EXE' - '0' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'SVCHOST.EXE' - '1' Module(s) have been scanned
Scan process 'LSASS.EXE' - '1' Module(s) have been scanned
Scan process 'SERVICES.EXE' - '1' Module(s) have been scanned
Scan process 'WINLOGON.EXE' - '1' Module(s) have been scanned
Scan process 'CSRSS.EXE' - '1' Module(s) have been scanned
Scan process 'SMSS.EXE' - '1' Module(s) have been scanned
Process 'winlogon.exe' has been terminated
C:\DOCUME~1\JEAN-M~1\LOCALS~1\Temp\winlogon.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was deleted!
34 processes with 33 modules were scanned
Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( '25' files ).
Starting the file scan:
Begin scan in 'C:\' <DISQUE>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\upload_moi_LABELIST.tar.gz
[0] Archive type: GZ
--> upload_moi.tar
[1] Archive type: TAR (tape archiver)
--> qoobox/Quarantine/C/Program Files/Fichiers communs/Microsoft Shared/Web Folders/ibm00001.dll.vir
[DETECTION] Is the Trojan horse TR/PSW.Sinowal.EL
--> qoobox/Quarantine/C/WINDOWS/SYSTEM32/xpdx.sys.vir
[DETECTION] Is the Trojan horse TR/Click.Costrat.BZ
--> qoobox/Quarantine/C/WINDOWS/SYSTEM32/kdubs.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was deleted!
C:\WINDOWS\SYSTEM32\tcpconn.exe
[WARNING] The file could not be opened!
C:\WINDOWS\SYSTEM32\rt26.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '477b659e.qua'!
C:\WINDOWS\SYSTEM32\update266.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47ad662d.qua'!
C:\WINDOWS\SYSTEM32\update241.exe
[DETECTION] Contains detection pattern of the worm WORM/Ntech.T
[INFO] The file was moved to '47ad6630.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Bkq57.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ba6639.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Thc22.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ac663e.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Rgj30.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b36640.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Gqyb67.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47c2664d.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Ixkc59.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b46656.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Nvcm54.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ac6657.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Pfu42.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47be6649.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Etr64.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47bb6659.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Oago38.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b06647.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Urva50.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47bf665a.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Ioi46.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b2665a.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Nqno62.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b7665e.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Rwv58.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47bf6667.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Xtd31.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ad6666.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Gti53.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b26669.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Rps48.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47bc6667.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Dukw81.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b4666d.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Nscv60.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ac666d.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Vrd31.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ad666e.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Rfob35.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b86664.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Uju41.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47be666a.qua'!
C:\WINDOWS\SYSTEM32\DRIVERS\Hhp47.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47b9666a.qua'!
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcrst.dll
[WARNING] The file could not be opened!
C:\Program Files\rares\Windows.Media.Player.10+.Bonus-enemy13.par.www.emule-mania.com.RB0
[0] Archive type: ZIP
--> RadLightMPC.exe
[DETECTION] Contains detection pattern of the dropper DR/Zlob.Gen
[INFO] The file was moved to '47b76c51.qua'!
C:\Program Files\rares\Windows.Media.Player.10+.Bonus-enemy13.par.www.emule-mania.com.zip
[0] Archive type: ZIP
--> RadLightMPC.exe
[DETECTION] Contains detection pattern of the dropper DR/Zlob.Gen
[INFO] The file was moved to '47b76c6b.qua'!
C:\Program Files\mp10\RadLightMPC.exe
[DETECTION] Contains detection pattern of the dropper DR/Zlob.Gen
[INFO] The file was moved to '47ad7052.qua'!
C:\QooBox\Quarantine\C\Program Files\Fichiers communs\Microsoft Shared\Web Folders\ibm00001.dll.vir
[DETECTION] Is the Trojan horse TR/PSW.Sinowal.EL
[INFO] The file was moved to '47b6737b.qua'!
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\xpdx.sys.vir
[DETECTION] Is the Trojan horse TR/Click.Costrat.BZ
[INFO] The file was moved to '47ad738d.qua'!
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\kdubs.exe.vir
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47be7383.qua'!
C:\SDFix\backups_old2\backups.zip
[0] Archive type: ZIP
--> backups/mljul0.exe
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> backups/symavc32.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
--> backups/hyperconn.dll
[DETECTION] Is the Trojan horse TR/Spy.Banker.gcf
--> backups/qtplugin.exe
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47ac739f.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000312.EXE
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797605.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000313.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797608.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000314.dll
[DETECTION] Is the Trojan horse TR/Spy.Banker.gcf
[INFO] The file was moved to '4779760a.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000315.EXE
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779760d.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000325.exe
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779760f.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000326.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797612.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000327.dll
[DETECTION] Is the Trojan horse TR/Spy.Banker.gcf
[INFO] The file was moved to '47797615.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000328.exe
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797617.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000968.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47797634.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000970.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[INFO] The file was moved to '47797636.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000971.exe
[DETECTION] Contains detection pattern of the worm WORM/Ntech.T
[INFO] The file was moved to '47797639.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000972.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779763b.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000973.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779763e.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000974.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797640.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000975.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797641.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000976.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797643.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000977.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797645.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000978.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797647.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000979.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797649.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000980.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779764d.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000981.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779764f.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000982.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797652.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000983.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797654.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000984.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797656.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000985.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797657.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000986.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797659.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000987.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779765b.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000988.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779765d.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000989.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '4779765e.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000990.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797660.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000991.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797662.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000992.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797664.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0000993.sys
[DETECTION] Is the Trojan horse TR/Rootkit.Gen
[INFO] The file was moved to '47797666.qua'!
C:\System Volume Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0001003.exe
[DETECTION] Contains detection pattern of the dropper DR/Zlob.Gen
[INFO] The file was moved to '47797668.qua'!
End of the scan: dimanche 25 novembre 2007 14:18
Used time: 1:23:05 min
The scan has been done completely.
5140 Scanning directories
143741 Files were scanned
74 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
2 files were deleted
0 files were repaired
66 files were moved to quarantine
0 files were renamed
3 Files cannot be scanned
143667 Files not concerned
1784 Archives were scanned
3 Warnings
6 Notes
Re,
Le lien vers AVG est mort ( pour moi en tous cas ? ) et j'ai téléchargé AVG 7 ailleurs... le hic est que je ne vois pas, après clic sur analyse de la barre d'outils, de " onglet comment réagir, clique sur Actions recommandées. Choisis Quarantaine. "...
So sorry... Ok j'ai trouvé actions recommandées etc...
Non il ne faut pas avg 7 c'est un antivirus.
Si le lien ne fonctionne pas : >Clique ici<
Message édité par XmichouX le 25-11-2007 à 15:33:31
Répondre à XmichouX
Ok, Michou... mais je lis comme titre du programme téléchargé ( et de son rapport aussi ) : AVG anty-spyware... Voici déjà les rapports obtenus avec cet AVG-là... et Clean.... A +
Tout a fonctionné, sauf la quarantaine pour ledit Generic de m...
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 16:50:17 25/11/2007
+ Résultat de l'analyse:
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Erreur lors du nettoyage.
HKU\S-1-5-21-682003330-842925246-1708537768-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@advertising[2].txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@fastclick[1].txt -> TrackingCookie.Fastclick : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@questionmarket[2].txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Jean-Marc Moeremans\Cookies\jean-marc moeremans@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Nettoyé.
Fin du rapport
------------------
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 25/11/2007 a 17:14:00,74
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
*** Suppression des fichiers dans C:\Program Files
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Re,
Supprime cette valeur manuellement via : (Démarrer/exécuter/regedit/ok)
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} |
Puis reposte un Hijackthis.
Message édité par XmichouX le 25-11-2007 à 20:01:25
Répondre à XmichouX
Re-itou...
J'ai bien trouvé hkEY( et non HKU)\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\ mais pas la suite...
J'y trouve :
AB ( par défaut ) Reg Z ( valeur non définie )
06A18dc1...REG_DWORD
FB5F1910-F110...REG_DWORD
NextId - REG_DWORD
C'est tout...
On vérifie quand même ![]()
Sélectionne l'intégralité du cadre ci-dessous :
REGEDIT4 [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping] |
Copie/colle le dans le Bloc Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Enregistre le sous sur ton bureau sous le nom de Correction.reg
Double-clique dessus, accepte l'inscription des données.
Message édité par XmichouX le 25-11-2007 à 20:04:09
Répondre à XmichouX
Et puis je le vire manuel, c'est ça ?
Tu as fait le reg ?
Sinon au pire repasse avg pour la partie registre pour voir
Reposte un Hijackthis.
Répondre à XmichouX
Oui, j'ai fait Correction.reg. Je vais maintenant dans Regedit pour le supprimer manuellement, voulais-je demander ?
AVG anti-spyware pour le registre dit : rien à signaler. OK.
Et Hijackthis donne ceci :
Logfile of HijackThis v1.99.1
Scan saved at 20:26:21, on 25/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\JEAN-M~1\LOCALS~1\Temp\winlogon.exe
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1082F44-3F0E-4F7A-9083-30B2D0DBCEC9}: NameServer = 172.19.3.1,172.19.3.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Bouhhh ..
Repasse un coup SDFIX
Répondre à XmichouX
Bonsoir Michou,
la routine de la semaine a redémarré, ce qui explique l'heure tardive de ma réponse...
Voici donc le nouvel Sdfix...
Pour info et/ou rappel ( pardon si je te saoule, mais l'intention est bonne..) :
a) F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\System32\ntos.exe, n'était pas résolu malgré que l'aie coché dans fix Hijacthis. Ne devrais-je pas le refaire ?
b) "Désactiver la restauration du système " est toujours décoché
c) Après avoir fait " correction.reg " je ne l'ai pas viré manuellement
d) Si je fais bien Sdfix en mode sans échec, le reboot se fait en mode normal
Le SDFix: Version 1.115
Run by *** on 26/11/2007 at 20:33
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
SysLibrary
Path:
\??\C:\WINDOWS\System32\DefLib.sys
SysLibrary - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-26 20:46:30
Windows 5.1.2600 FAT NTAPI
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
Files with Hidden Attributes:
Sat 21 Jun 2003 377,344 A..H. --- "C:\Program Files\Smart Projects\IsoBuster\Help\AHlp.exe"
Finished!
Normal le reboot ainsi que la restauration système.
Reposte un Hijackthis.
Répondre à XmichouX
Re,
Que voilà :
Logfile of HijackThis v1.99.1
Scan saved at 21:42:45, on 26/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\eMule\eMule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\System32\ntos.exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1082F44-3F0E-4F7A-9083-30B2D0DBCEC9}: NameServer = 172.19.3.1,172.19.3.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Essaie de refixer la ligne F2
Répondre à XmichouX
Salut Michou,
Ligne F2 fixée, et scan hijackthis effectué après reboot...
M'a l'air bien fixée cette fois... ?
+++++
Logfile of HijackThis v1.99.1
Scan saved at 19:25:46, on 27/11/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [DVD43] C:\PROGRA~1\DVDREG~1\DVDRegionFree.exe /hidden
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F1082F44-3F0E-4F7A-9083-30B2D0DBCEC9}: NameServer = 172.19.3.1,172.19.3.2
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
Bien, c'est clean
Une dernière vérif ?
Fais une analyse antivirus en ligne sur Kaspersky avec Internet Explorer. (Tuto)
Autorise les active x.
Clique sur Démarrer Online Scanner.
Sélectionne le poste de travail comme analyse. Enregistres sous le rapport en format .txt.
Colle son rapport ici.
Répondre à XmichouX
Bonsoir Michou,
Voici le rapport Kaspersky.
Tu dois savoir qu'au cours de l'analyse, Antivir m'a suugéré d'interdire l'accès Internet à ( quelque chose comme... ) tpconn.exe, ce que j'ai naturellement appliqué.
KASPERSKY ONLINE SCANNER REPORT
Wednesday, November 28, 2007 9:04:25 AM
Operating System: Microsoft Windows XP Professional, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/11/2007
Kaspersky Anti-Virus database records: 467126
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
Q:\
Scan Statistics
Total number of scanned objects 55164
Number of viruses found 2
Number of infected objects 7
Number of suspicious objects 0
Duration of the scan process 10:04:41
Infected Object Name Virus Name Last Action
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SYSTEM32\tcpconn.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\NetLimit.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\config\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\TEMP\ZLT00f33.TMP Object is locked skipped
C:\WINDOWS\TEMP\ZLT00f36.TMP Object is locked skipped
C:\WINDOWS\TEMP\Perflib_Perfdata_140.dat Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\LABELIST.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\eMule\Temp\002.part Object is locked skipped
C:\Program Files\eMule\Temp\004.part Object is locked skipped
C:\Program Files\eMule\Temp\005.part Object is locked skipped
C:\Program Files\eMule\Temp\006.part Object is locked skipped
C:\avenger\backup.zip/avenger/ntos.exe Infected: Trojan-Spy.Win32.Broker.af skipped
C:\avenger\backup.zip ZIP: infected - 1 skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\eviz.dll.vir Object is locked skipped
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\lznbcoq.dll.vir Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5B4E83A0-13FB-4A2D-A58D-631F23C2CF01.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CD6DF2B8-0005-4F03-9AEF-624D13A93802.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-EE395AC4-2444-48B7-8ABF-B8682280D7E1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0D36203B-9460-4824-B98C-74C9671600DE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-69FCE296-9550-492D-8396-D7DFE15A298A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5DC52C75-8617-4A7D-B4E2-6D2D39A4AC6B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C8CDC013-53C0-4637-A077-984DBD666B6C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-36B24FA5-22EC-419F-AA0F-DCDEF3ED9684.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-08F85C43-C0A1-4ECA-B120-7FD197DFA484.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-12BBD99F-6B2F-44A7-BCC7-E72027915D3D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4F2B5718-BC51-4B6F-B0A1-5C26441AAAA1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5D698AB5-DCAB-48F0-905F-C62E25538D78.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1117D518-5AC0-4A6B-89F7-778210DF000F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-31D7BEF1-C24E-4EDD-B8CE-4E0EA72B832A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C1AEFD86-12E2-4B2A-A7B5-2E0838A54BA5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-24D6BA00-3DC0-4EDA-A00F-279EE7702328.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6B96DD81-F82D-4D27-B743-835F6B433341.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-EC32C074-7259-40DA-A6C0-9834E8CC6B09.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F9AA78EF-5D6E-4E48-B76A-2AD921CA38E8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-ED9C761D-B489-4ADD-BA88-E3E8C9D2E9B2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FA9A58DE-CE1A-4998-BDCD-E84143662AE9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-911B18B0-37F9-468B-9131-FA08D2FD7307.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BC420DD0-9538-4D54-A7A8-B9681FFC1794.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CC7B8641-7E0B-423D-973E-13DC973DC44F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1D393094-93E6-4F2E-816C-7DD87E2FBC03.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8DB018C2-8E42-4C80-AA8F-51AD6AF0035D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DEB3A669-60B9-4C99-8FAF-D8663233C4AE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-50850B70-98D4-4F55-AEDC-584C40856B41.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-69E83E2B-C380-4D6D-BE48-30BF462DF345.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4FEE4AB8-1190-4D2B-8F29-E93E9A240666.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-023A9DD9-C8CF-4FCE-A5D1-66DEB84EEA7D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6A231C48-FFBC-40A7-8F03-91E1505B0695.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7A674F9B-1D5B-4417-A9F0-9CB0424BDDF7.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B101CDC2-8471-491F-BB91-DE732184362D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E320203F-A902-4813-9F7E-6974495E37EB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-87783D15-110B-4BFA-ABE3-91FED5FA3BA3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2B14C99A-0E01-4F51-8851-3B0481F965E5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9606EB1B-1713-4A46-A848-49C2FFDD5C6C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3B7ABEA3-AC76-4600-A6F8-177D3B3AEA16.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4F7BC5CB-C6F5-4509-9EAD-8F432565D11A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-EEA6DE2D-3409-44FF-9ACD-7C2475990D0B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-245447D5-8CDD-4354-9416-8EAC370B40B4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-61D28940-A086-4D54-8135-865CAF983520.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7CF20388-FF6F-4132-A3AF-FC15EA83D595.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FCF3A3C7-AEA8-4C7D-89BF-745626BF58A6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D30D5B8B-CFD7-4689-9C82-7CCC4F5FCA1C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1F67396B-8560-4A5D-877D-B1EC707A93C4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4EEDEA8A-6174-492A-AE3F-BDFCEF185B97.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FC0969B2-0AA1-491C-891E-5948400C372C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-AAEF5F7D-3FD6-48E1-AD20-316E9B1520CD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-AB5DEA9F-641B-4D16-A170-9C2B91B811FE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A017856C-D4D8-4D6D-9149-83012C85CFDD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-09C52DC5-B7F1-47E4-8972-0F4EAA6FE702.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-305AA69F-4816-49A6-90D6-AF3C289AEF85.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-291245BB-EF1C-4580-ADB5-22936A60E413.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-61A9F791-7341-4CCA-9D42-1FE233A3E3F6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6DDCA6A2-B56B-4706-B5E1-1B44BA9C5321.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-352E9FF0-50F6-4572-B507-976EDE11AA28.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D7E6E7D8-FFD5-44C0-8EAF-730EF9145CFB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-AD5A6F21-1A67-44AE-BDD2-536D107D9DC2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-32B9BCAE-437C-43D2-8E0C-C4BD5AF8263D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8B627C4C-5B0B-4838-9674-279641B8F6FA.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-60CC29B8-7FD1-4EC6-AD25-5B09C4722F82.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3CCF3C8E-AABB-42BF-945A-FF5E952D7B33.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7E3B643D-AA89-4BEA-87CE-33D54F8F431F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-13494AD6-E44F-45FF-8217-7E60BDAAD9FB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9AE30783-9D1F-478F-9A9A-41DE095E695D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-877D349D-AB5A-419B-844F-C47DDE116ADE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-46741536-0464-4490-A9EC-F439C6A93113.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-24AB7862-630A-440D-AB28-175B68840CC0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-61045858-772C-46FE-A9C7-403982242882.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-763C737D-A589-4F5E-BC1D-6C0C157EABEF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C2967AC0-3697-457D-97B2-F7FB7C5314E9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-69D34DBB-5931-42B4-8F19-24FD492D7357.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7C355B2E-FBA7-4F34-AF40-C77F29021F4C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-220C4C75-6B74-4B5A-AFAD-EADCE93DEE31.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DEE0F887-76BD-4834-A5C5-DF88C18AE2F6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3B8DD358-06CE-4D96-BD0B-310E481899A2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3A9A48D6-1B8E-4A02-9133-AAD5489ED717.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1B0A2A28-F6C9-4D42-84A6-2341C767D88B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D3655942-5B3C-4C06-9BF3-FC3C70671531.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A38E9C1F-599C-4DFD-839E-AE94B0E760B8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6CC27DB2-EF3B-40E9-9BB4-1441FF7CAF5C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-926EFFFE-6042-498D-A00E-BF47D669641E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-AB95A0FF-B98C-4A54-A748-29A5DF2BA611.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-100817DE-EBD9-4E24-896D-CA332E2118D0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1E1989C3-8B5D-4ECB-8443-99BF0ACD38B4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-EBE0F5E3-61D2-423C-B7E1-2831281BEDBF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-00AE0ED1-7E3F-4484-8A79-E3A2C55F8D4D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FF3D5C13-277A-416D-BE11-A04BCBEC3026.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9B642F73-7528-4E4F-B649-94248BDAA11A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-39878A9F-47AB-4ABF-9209-54E780FA9190.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B89666F3-2E86-4DD1-98BE-1DDD7EADAB32.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-859DFC8D-86FF-4B88-B009-6306C1A87965.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-393CB657-9C71-4410-9A58-BB5333182671.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6CC15793-FEB7-4EC4-B6A2-381A4407C8D8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6C54D4B3-F61A-40E7-AB40-765BF0688540.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-787F8F93-AB89-423B-AEA7-A396F4AF892F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-53FBCFEE-1EC6-45CF-88B4-087C029DE046.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F85022BC-6048-411E-B287-457AF0D33693.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2CF9A349-FA14-44FE-84D9-46D3E9F7DD06.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E480E97C-2E5A-40CC-8B33-FB8838D64121.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-16D169A4-5B9F-4D09-B90B-59C346D9C64D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-459FE8F3-22C4-43F8-BF12-9A151E3A2651.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C16BB235-842C-4B2F-AA04-154204E10DC1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9FA7956C-CCCA-496D-B1EB-56699797BBA3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A01F0155-F2FE-4B3F-9CDC-64447555C301.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-77676D19-218C-48AF-86F1-B832F425B440.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2C634DA1-C65D-4EAA-AB4C-2A45A8C1609B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2D52E67F-B673-4718-90D6-94967C508BF9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-84190134-FE13-4BEC-A1DA-C3DF7B1C9425.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-66351BA7-3AC7-4EFD-8697-B1C6C0B33223.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9A8B1098-036B-467F-BBC7-8E4E6512C51C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7CD02A2B-87CD-4C35-B57A-183BBC7A57EE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3D4574E3-0F4E-4A61-A921-0DB28B0BB037.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E8B29C70-46FC-47AF-8C94-7BFA6F85154F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D9BC1A24-73D3-472A-8C27-A35C3D9DDDCF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-02122965-ADA6-484E-9203-E939287F5CA2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BD2DEC76-E825-44D9-9FB9-35CED9A6426D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FE29EDB5-65B2-441A-AB81-A6157A2EE308.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-81FA4F64-6F67-4F3D-9858-E8EC33D8A9FD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-73C6A296-98C7-4ED1-9424-EB89F8440ECE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CB3D99F4-6E7E-4F7F-8E96-EA8BA83D2253.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FCF3766B-4F6B-4025-8155-4DC4DBCCBCC1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-646415FB-C4D9-457A-BEC0-A53D4723605F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DE0EAC19-F0D1-4BFB-9828-349BA35FF508.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-17FFA5FE-8E4B-47D0-8B13-41DEF50A544F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9388FB39-E179-477F-B346-C41B4DC0EFDD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8ACBC5F3-DB55-4618-AFDD-2BE7C5C045B6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-129E386E-E482-4E8B-AB36-2543B4B85F2F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-24E6511E-264B-4F28-9FA5-7B8563B6746E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BF7A07C5-0EB8-4B15-98B7-BA98E469A3B4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-07F95AD2-AA03-4770-8981-ABD4A3123BA6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A0F8896F-0F62-46C8-959C-4C55E8A09125.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C1E27FCF-DFE3-4748-A232-3D6CAC64D9D2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-79A67076-2D30-4284-9194-4085C6CE3152.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FE83F060-837D-4E36-83F1-CE455DBDE8F2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C0DB79B6-5BC6-40C6-AB84-AFE291FAAA74.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1DFC7245-1E28-492A-9AAF-2235B07BC09E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-875B5665-0BDF-4421-A88A-FD4B988C71DB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3A8BD01F-037D-4617-81A1-F195D8A6543C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9B2AFE85-935B-4B17-93C4-3FFA37F8F831.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BE1E8E75-5C7C-494F-A1B3-DB570DBC3FB7.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E1454BCA-9F01-4D5D-AA14-93868617B27F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-241091E8-ED3B-46D1-A151-5906BB6DF642.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-469D927B-05E6-41F6-B432-C137729994CC.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7C0E0200-1A3B-4422-A143-04389BECB7E8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-87D4655B-5D5A-4D2A-BBD1-8E5ABC8EA815.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-00EFBCDC-F9AF-459A-A227-1A8DC0C1C82A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B59AC2DD-47B5-4F88-B173-CD8AEA8CFE0E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CC00C1B1-D57E-4DDF-BD74-B201DD3253CD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9D57EF1B-975B-40B7-B6BC-F538AAEBA445.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FA42AA2B-D57D-44A9-8D7A-8BB4373041D4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C5FDA13E-9CB7-4672-B009-3EB997E85FD5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3FE18AE8-98A7-49DD-AAE4-1749607A9EF9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1E7FCE0A-90B1-4B25-B5FA-6CF086E6220E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-67D2A233-6D31-4D6F-8D43-42E3E04190AE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CEF81C3C-DE3D-4D3E-AE0F-F6AECD447305.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0D636849-15A5-464D-8762-604B29ED0519.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6DD6CCD0-04D9-40A5-A3D7-751632829500.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CA61AC17-B74C-4331-A2F4-AF515A00EEB6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-456BD62A-DFAB-4472-B07B-2042EF107EBC.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D66DC18E-D014-49EE-9C9B-FBC6710500F6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-438B447F-764D-4DF8-A274-3B5270EA453E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2BD34B45-F159-4626-B7AC-83A9BAD7BD5D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BC358271-1300-464E-87B4-BB3B165A589A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8C249EDA-000B-4D76-A057-301E0C04A585.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B5703343-F229-496C-BA93-B0B0AFB03194.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BEC0AED9-D3EF-43DA-ABFF-56095A6FF9D0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9589F790-652B-42A1-8AEA-19691E4064D7.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8038A10B-DFD7-44F7-B970-FAAB4EF77345.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2441149A-E898-4C6F-9A00-4F33901919E3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BDFEA831-7985-4683-9E46-82D7D5A34553.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1C49DC62-2DFE-46F8-BD47-0A5FF5B04AE2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8C5A3DFB-079E-40A4-9906-3A7CBC7062DF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-01A4D0AA-1397-48D7-B9DD-4C07D9316B84.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0FD465C6-1F51-474E-89BF-DA8C5F7A8A7C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4D9990B3-29DF-4C6C-8DF1-2913BEAFD622.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FF63200B-7BF8-4A35-9F5F-3788012521BF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3E79E7F1-7455-4042-9144-0C0B5464E5DF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E8029879-0CEC-479A-A63F-7F516DB12572.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F7296ED1-A37B-4B33-BFF9-63BD67405FE2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-01AA2CCF-2B8B-40AF-BFA2-E7980253E07D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0B27BB41-C773-4BFA-9067-2BADD9CB8AFE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1A9654FF-4BBA-4D49-BA7A-CD3B77F8F813.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-147000F1-BCF8-4962-A69D-5F8EF70E4EB2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0EE336E5-44C2-4791-997A-7CF2186E913A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-45EFB80F-71A3-4458-A1E9-FE70483D22E6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9D9C7267-06E7-4783-ABB6-7EF3D39E6C58.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D53656DE-E88F-45D2-9AB6-330839BA40CF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-309258EF-7988-4053-A2C9-EB00A75247C0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-245B4185-8656-4F22-AFD5-0B80DCF7A4B2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A1C4A2C1-7EE8-41BA-993E-190B36D77701.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-34CE02E2-26FE-4429-9647-B2A6B904ED33.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BAC191E0-FED3-429C-83D4-ADA9A0982574.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B09943F5-C51B-49B7-97B2-510F9FFEB53D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1B2ADFAE-03C8-4239-99AD-609585DA21B1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1FB71E55-2E04-46F4-8DDC-331E6681F6C4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A432A254-45BE-413D-8E50-2FC48AE86ECC.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6DD850B4-1E14-40FA-B095-0D4A56D4735B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A6924747-9CCD-4E51-8EE8-C971D7378C7F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E998384D-9043-43E1-B273-385AF2529E62.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2B7CD55E-397B-41A3-8360-5159949914A3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-480677EF-4603-4255-A0CA-5245275A1328.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6F673DF2-B1B5-49EF-8982-D35E96106C65.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-157C3E5A-ACF6-4F3B-B233-85E1CC3D7493.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BBC0A984-631E-45FE-9D28-85CD2DFDE928.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CB8C3499-637B-4321-804F-64AF5207863B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C4557B60-D6D1-4F19-A03E-D9D97FB8FDA3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2E16860D-28B1-4C64-83A7-E7A115B3DDE9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CE889580-27B1-4100-AF15-F02D8F7A7E7E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-30E865D3-7362-4625-A84C-CACBC4FE37D2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1334CA8F-2FB2-4B22-A700-2A69359A4306.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BB2D248E-F939-4972-A4A5-448DE8A08A20.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-160EAB64-CE2D-4811-9B3D-EB79DF4F3D60.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-20270993-A7D5-489F-9F03-610E195B9E1A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-755E2CAB-2710-42C8-A1BB-1A9D73E4EC27.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4B3AF58E-4D42-443C-B779-100746D24F1B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-67893FDC-FF43-46F4-9959-D6B16436E9D1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B9C16E86-16E0-4A5A-A6C7-93908CD39376.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-67FD1C0B-D887-467A-8306-06B7763CD661.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-20285C70-2940-4CE8-9A97-8690165B9F49.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CF095473-E4E1-4D1C-90FB-2B2E8908EC94.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-89911F7F-2FC7-49F4-B7AC-7B988100A6C9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-AA5432C9-6EF9-4BBD-8A46-1217E4FF6FD1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-99A2FE73-F7C4-4DC7-AB52-D429D7EDA173.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-66360AFE-7381-4E51-AD29-BB87F0BC1520.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D7B34259-94A3-4880-9D62-E0131B032D1D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F02D0FC2-447A-4F86-9A13-819E40146648.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-753C0A3A-A4B5-4307-B3EB-1BBEF7ADDC08.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A788F6D0-B2A6-4963-9BC8-892B82DD5389.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-66541234-6798-4DA8-A8A2-2D86D4ADB2FE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2B376FB0-06AF-4BDC-A36D-2A3FB3C9C49D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2DCEC230-5C94-4D7E-9E40-9F48C8D7F376.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-90FAE527-C805-439D-82E0-742D2FE13A70.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CC408C64-CABB-4D93-8E47-B306FD47D4EA.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-799C86C3-0CB5-4ADD-AFB4-BCD72558D900.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-97E0D89F-B1CA-485B-8BE1-75E848DBEDC0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-98DF0F46-B938-4F28-A676-D95551A76060.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F01ED49C-B415-4EEE-8412-92DFF264A04D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-121F141D-D4D3-4F52-89AA-BC9DC2C8D52F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6CD3BBDF-FF10-46ED-8E4E-EC7B94F9765E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1C73796A-7914-422D-88DB-C76A3DAFE2F5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3C6ABD93-1525-4E39-A63E-B2A723F6C118.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-994F8755-9876-4FDF-9147-56AC5E9D9639.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5CBF01F0-7793-415D-A120-D267F830D476.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-69C9C78D-6C52-4252-9E66-3B1ED2B1BAAA.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-36EFC15A-4C16-4975-9ED9-2CAD83E931CD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BD22E1A5-7AEA-4773-8BA6-F691B26DFE30.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FCE041A0-0B1B-4ACD-8395-28CFBBF679A1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7EAC4BE6-22AA-46CA-A3DA-2195F737979F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6ABCB745-3C87-4DC7-990F-7E85F7E0E598.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-69F61411-AA0F-40BA-904B-F25B10429AAF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1C217177-D99D-4704-B6F2-878820E5E8DC.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A57D93B7-FA40-4771-A241-478A2119CA0E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E3918DC3-DFA6-4E18-92EC-89F41D5086EC.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2E27E415-F843-4789-B88A-BE58A6314E4F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0266108A-CE63-43B7-80E6-2ECEFA277C90.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-08F50D33-F546-400B-A072-FD932C7ABEB8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1DADBE1F-820D-418E-896E-E2D9E5E43268.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6737D26D-6D40-4861-82C4-F02814F27D73.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8CCB19D3-FFC3-4575-990C-D73A1CFEBDEA.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-16868AA8-AA9E-40FF-BA9B-BE6CB87B0A1D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C393E022-E424-4863-8BFE-4085C763FADF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DBF7D772-13AA-4C2A-95B5-1C1182ED64C0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-39ED0AC7-0E3C-4528-BF73-625634351028.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3B415E6E-B3D7-4316-AA52-B7026161EB3D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4C042081-98EF-44E3-B7CE-362C21227E42.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3ECD61C7-D237-4233-8D40-827961FE7879.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-14FCC349-B044-40F2-8240-A02FF54E9EE0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E8E6DDFF-D041-4B94-89A1-E0F8517F9236.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-59D62C0C-3074-437E-9E5A-B7743B0B1E0B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DE9AA3B6-FE0C-4BAF-8709-5CB68026F645.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4696D1AC-E081-4033-BD50-6F2A543997BE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-36446461-5523-4775-96A3-E38E59120D6F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E95949F0-5A2F-43D5-A501-0B4D922D3526.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F3687002-4BD4-425A-91C9-F7C0DFFB10A7.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9C25826F-CAE9-4309-92F7-D6A61827EF19.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-19CE4C0A-47DB-4E33-8588-852DA4FA7DBC.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FE5A7ECA-B99D-4C60-89F8-C757F25DA30A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DFE0A5A1-63E1-48F1-9DEB-A078A92085A0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E362793B-0CF7-47B3-B5F3-AAD9BCF09C1C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9B405A7A-AEC5-4D12-A35B-9586F45FD149.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6AA81518-4ADE-49E0-BFBB-8E11800F0EB6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2D5D58BF-0C92-4176-A6E7-D614FF7A485C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-401E0A02-66D0-4802-8B70-F7A322A45DC5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2FB97CA6-B79A-4BD0-A255-58F372BD3BEE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A19B9AC6-E209-4DDA-8038-A9C66F698446.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9A3D505E-D840-41B7-BBAD-C3AA73674503.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BBFB12CC-D04F-43ED-98EC-1B60BD1196EA.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-6A4729E6-E59E-488F-AB3E-B1B85EFE5E44.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-62AD676F-E43D-48AD-B845-768929F3D6C2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-83DA281B-2995-4FC8-B176-E9480B00B236.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-67C63F0C-2586-4CE3-9B93-346B28F6D348.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-461B0F49-F6FF-49D5-A0FA-39FCEED6B9BD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-63DC6719-D97D-4ACA-B750-DBC66FA69000.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1B8047D4-7962-4820-981C-01DD58ABA69C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5622443A-8CF6-4A73-92A0-3944EC774D86.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-26992AA8-A68B-452C-9199-5B1480045420.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3A17EC69-8005-4435-99F4-1FAF1373E724.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1D110D7C-0D6B-49DC-BB23-341390F37410.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E91D4A14-1809-4587-8A0E-085842DF9035.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7784C0C5-A9F5-4D16-9DA4-776C328DBB10.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-592E1942-2705-4A5B-875F-24D1F118EF09.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7126BD66-79B6-409F-B9F0-CBAD80F3DA83.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0E380208-77C3-4B2E-A44D-62A47273F636.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E31D2371-4683-481F-856E-3D6E5295DA1D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-944A1F62-14C2-47D9-AD14-8F80A1098285.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C963BAFA-63C2-4FE9-B093-E6863D2F1842.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-29F601B6-240C-4C70-9B88-B9B52AA29D1C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5FC46CDA-79E0-4068-B0A7-F1DF66B281DD.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F55DB783-AF89-463D-A6D8-AFE0A15CC762.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-77D25858-F0D3-4F6A-96E3-BFFB8CC27F4F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C9A98AC0-8F4F-43A0-B09F-436068CD5883.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4EA85331-5B53-4F98-A52D-3A8ED827EC86.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-D3A9DC81-E818-4087-810C-7F5CDECD0437.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-FBD91E7B-AD8D-44CE-AD90-61EB528CF6D2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-661D198F-3B6E-4072-8A70-9460CDAD70F6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-3A3D7F74-DB66-4675-ADE9-A311BFA271E4.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2B480313-8625-4079-B5F3-7C7C93D7FD8C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0BA7804D-D986-4978-B087-DAFAEE0D715D.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DCC1B8F3-0001-4A27-870C-F166763EC807.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-381136A5-0394-4C81-946B-B37A77F32000.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-462E783C-A4BF-4509-A95E-2529623BF755.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-34CCDD83-F97F-4AC0-A10C-E86344BF25B2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-802FCA56-2EE1-4DDD-B5AA-55393065F0E1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-251253A2-F9B9-4304-984C-C9B5E01CC552.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9989B2EB-B848-4126-A75E-9C713968A75F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-73DFCF8D-DAB1-4D8D-838E-783A0CBCFD91.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-742B2C50-055D-46D4-BE4F-63DA96A984A9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-46726E1E-D14C-4B4B-A22E-6C324E2AD586.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-93437E0E-0542-46AF-823E-51F2C1ADA4B5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C88CC782-742E-41FE-8A3A-2BD92F9D131A.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C4FAC984-7151-494C-9730-159624F8A12F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2B7542E5-512B-478D-A908-58EC2999C915.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5CB7D04E-ED30-4B89-8998-18B797B5BBAB.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8DBF118C-77DC-44BF-831C-011711175268.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-565A125B-07BA-4B49-83D4-D65900452636.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-4D7D6982-CB4D-4795-95D1-58A786144DD0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-ED691505-EF49-4D64-8F54-843ABF792C37.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-62C85A47-93BD-43E8-97E3-58252192E45B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-89BB67DE-C256-4D1F-AD7E-26D0F4451F2E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C5CA58A9-D962-4D98-BB87-208D107525B8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-BE5AC323-71DE-45BE-B57A-660F05936123.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-70B6B4AD-8B4C-40A2-A4AE-91FE5137F97E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CAA6650A-DD9A-426C-8136-7F9F87C7E5D5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-F470CF3C-6662-43B4-B4C2-20FCB0FB3FB0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A0D884DD-6FC3-4852-87A1-60F0831690B6.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5097BA83-4AA2-4623-9F1B-9AF4C3790356.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-B8CD2A7A-1CFB-4F2B-B80F-0FC0CEC5AC75.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DC7A1156-90A0-47DF-B8C0-DC331541D2CF.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-780EA95C-5C28-4012-8076-AA8B68D75E7C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-0839224F-2C59-4236-BD46-4A368D15BA46.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-8F46A945-5CA2-404E-95CE-06846FA44A3C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-754405DB-21C9-4AD1-B272-CF2C013EE853.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-9B838CBD-265E-4051-B5BD-70B2BF28342F.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-11B72DBA-51E1-4551-808A-6E3D051DD2D9.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-1F56B2EA-E7DE-4E4F-A242-5CFE77D8A3B8.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-DB22A6ED-6996-48CE-8040-04B7F9B2C747.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A079CC46-C777-4D2A-9157-6A1973614778.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-21BE0D1B-C132-41EA-8D0F-6DA1BB03BFF5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-928C2F79-F29E-4308-B015-F5E1C43F6E7E.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-2B047F94-5A95-48A5-84C5-A2090417C82C.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-7948C808-B023-4E5D-9262-75712D01ECB3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-030D215C-0704-48D2-BAD3-6E8C102F4AC5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-C3E574CE-D389-42ED-9709-BCBB9FBD5B5B.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-921B77AF-4328-43AA-9D59-0E197391FC74.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E411DCC0-181C-443E-AAAD-016CDC036FD3.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-85069320-4C89-4CD2-9C9A-C762E441F7EE.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-CA135E73-4423-4E5A-A7D4-5D8BC9AEF607.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-5B86E39B-6011-443B-8925-C53DAEB9B699.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-801FEECD-14AB-4D77-B669-AE389F30B7E2.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-38DDC261-309E-4F54-B154-DF358944EAD5.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-E70C2B6D-5DE9-4221-AD15-97E41D17BF12.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A6AB4A27-084B-44FA-B67D-3A7FEDFE8F66.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Locktime\NetLimiter\2\Stats\nlstats-A824BCAE-E9D0-4223-8486-078769BC22B2.dat Object is locked skipped
C:\Docu
Poste seulement les lignes infectées, car rapport incomplet.
Répondre à XmichouX
C:\avenger\backup.zip/avenger/ntos.exe Infected:
Trojan-Spy.Win32.Broker.af skipped
C:\avenger\backup.zip ZIP: infected - 1 skipped
----------
C:\Documents and Settings\Jean-Marc Moeremans\Mes
documents\Clean\clean\pskill.exe Infected:
not-a-virus:RiskTool.Win32.PsKill.k skipped
----------
C:\Documents and Settings\Jean-Marc
Moeremans\Bureau\clean.zip/clean/pskill.exe Infected:
not-a-virus:RiskTool.Win32.PsKill.k skipped
---------
C:\Documents and Settings\Jean-Marc Moeremans\Bureau\clean.zip ZIP:
infected - 1 skipped
--------
C:\System Volume
Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP1\A0000502.exe
Infected: Trojan-Spy.Win32.Broker.af skipped
--------
C:\System Volume
Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\A0001048.exe
Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
--------
C:\System Volume
Information\_restore{6DD57169-3FA0-4F63-807C-A4BC20F23A78}\RP3\change.log
Object is locked skipped
Bien.
Désactive-réactive la restauration système
Désinstalle, supprime tous les logiciels utilisés pour la désinfection ainsi que les dossiers créés correspondants.. Garde ccleaner, avg et antivir si nous les avons installé..
Rapporte ton infection sur Malware Complaints
Tuto
Ton infection :Wareout, trojans
Message édité par XmichouX le 28-11-2007 à 20:10:59
Répondre à XmichouX
Merci Michou... Penses-tu que cette attaque puisse être délibérée, je veux dire intentionnelle et personnelle ? Je ne te demande pas si c'est le cas, évidemment, mais seulement si cela pourrait l'être ? Et si oui, si en théorie, on pourrait en identifier la source ?
L'attaque n'est pas personnelle, elle ne vise pas une personne en particulier, elle vise le plus de personnes possibles (les personnes qui font pas attention à leur navigation
) Pour les sources, je ne peux pas te dire.
Comme ils disent dans les guignols : L'état créée des virus pour refourguer de l'antivirus
Bonne soirée
Répondre à XmichouX
OkOK... Je mets ma parano en humble berne... et vais tenter de redoubler de prudence dans mes pérégrinations inter... ( ... ) Ce que je dis en tant que guignol avec un petit g, c'est qu'heureusement qu'il y a des gens comme toi pour contrecarrer ces tdc... Chapeau bas, Monsieur
Fais gaffe à tes pérégrinations dorénavant
A +
Répondre à XmichouX
Il y a 2529 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
