Programme impossible à supprimer
Forum Sécurité - Virus : Programme impossible à supprimer
Bonjour,
J'ai constaté récemment que j'ai des programmes éxécutables un peu partout dans mon PC (systématiquement à la racine de chaque disque dur mais également dans des dossiers divers et variés)
Ces programmes ont des noms qui changent et qui sont imprononcables, ils sont accompagnés d'un fichier AUTORUN.INF
Lorsque je les supprime, ils réapparaissent automatiquement.
Dans le gestionnaire de tâche, onglet processus, je vois les .exe. si je fais "terminer le processus", il réapparaissent aussitôt.
Dans msconfig, où je sélectionne les applications à lancer au démarrage du pc, les programmes malveillants sont présents. si je les décoche, ils se recochent automatiquement.
Lorsque je fais une analyse anti-virus, les divers anti-virus détectent les problèmes mais n'arrivent pas non plus à les supprimer.
Le scénario est le même en mode sans echec.
Je suis sous windows XP.
Mis à part ca, ces programmes essayent constamment de modifier des paramètres du registre. De plus, dès que je connecte un nouveau périphérique (clé usb, disque dur externe, etc...) ils se propagent instantanément.
Tout ça pour dire que je suis maintenant à court d'idée pour réussir à supprimer ces programmes. Si quelqu'un a une idée ou une solution à me proposer?
Merci d'avance.
D
Salut,
- Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.
- Double-clique sur RSIT.exe afin de lancer le programme.
- Clique sur Continue à l'écran Disclaimer.
- Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
- Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
Note : les rapports sont sauvegardés dans le dossier C:\rsit\.
Bonjour,
Merci pour votre réponse. Toutefois, j'aimerais juste savoir à quoi ca sert de publier les logs? En effet, les fichiers vérolés sont déjà identifiés et le problème est juste que je n'arrive pas à les supprimer.
Qu'est-ce que vous espérez voir de plus dans les fichiers logs? J'aimerais juste comprendre ce que vous me faites faire.
D.
C'est pour voir des choses que tu n'as peut-être pas vu.
OK, les voici:
log.txt
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrateur at 2009-02-25 19:36:46
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 4 GB (21%) free of 20 GB
Total RAM: 1023 MB (48% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:36 , on 25/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\tsnpstd3.exe
C:\WINDOWS\system32\havlopnde.exe
C:\program Files\Topdesk\topdesk.exe
C:\program Files\Clock\Clock.exe
C:\program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program Files\Windows Sidebar\sidebar.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\Administrateur.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windows-unattended.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://windows-unattended.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://windows-unattended.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windows-unattended.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://windows-unattended.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://windows-unattended.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windows-unattended.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Orkas Ultimate Edition
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [MDM Rock 4] C:\WINDOWS\system32\havlopnde.exe
O4 - HKCU\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe
O4 - HKCU\..\Run: [Horlorge] C:\program Files\Clock\Clock.exe
O4 - HKCU\..\Run: [Sidebar] C:\program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Vistadrv] C:\Windows\Drive\vsdrv.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Signature] C:\Windows\Drive\sign.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Horlorge] C:\program Files\Clock\Clock.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\program Files\Windows Sidebar\sidebar.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 7192 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - D:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-10 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-10 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-10 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
LinksFolderName
SaveLinksOrder
Locked
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-06-28 16258048]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2009-02-24 69632]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-26 8445952]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-26 81920]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe [2006-07-07 274432]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2009-02-24 843776]
"MDM Rock 4"=C:\WINDOWS\system32\havlopnde.exe [2006-11-29 90624]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"3D"=C:\program Files\Topdesk\topdesk.exe [2006-11-06 205312]
"Horlorge"=C:\program Files\Clock\Clock.exe [2006-11-11 152576]
"Sidebar"=C:\program Files\Windows Sidebar\sidebar.exe [2006-11-12 1258496]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 25088]
"SpybotSD TeaTimer"=D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bnagtnag]
c:\documents and settings\administrateur\local settings\application data\bnagtnag.exe [2009-02-24 289792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE [2009-02-24 131267]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MDM Rock 4]
C:\WINDOWS\system32\havlopnde.exe [2006-11-29 90624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ORAHSSSessionManager]
C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2007-12-12 107248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Signature]
C:\Windows\Drive\sign.exe [2009-02-24 435353]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2009-02-24 2879488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vistadrv]
C:\WINDOWS\Drive\vsdrv.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FileZilla\FileZilla.exe"="C:\Program Files\FileZilla\FileZilla.exe:*:Enabled:FileZilla"
"D:\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe"="D:\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe:*:Enabled
layOnline Viewer"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\VideoLAN\VLC\vlc.exe"="D:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"D:\Program Files\Vuze\Azureus.exe"="D:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\eMule\emule.exe"="D:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
"C:\WINDOWS\system32\gwcbrpzfp.exe"="C:\WINDOWS\system32\gwcbrpzfp.exe:*:Enabled:MDM Rock 4"
"C:\WINDOWS\system32\tdwenvxpq.exe"="C:\WINDOWS\system32\tdwenvxpq.exe:*:Enabled:MDM Rock 4"
"C:\WINDOWS\system32\mgdrwfsvl.exe"="C:\WINDOWS\system32\mgdrwfsvl.exe:*:Enabled:MDM Rock 4"
"C:\WINDOWS\system32\gfcfrhqhg.exe"="C:\WINDOWS\system32\gfcfrhqhg.exe:*:Enabled:MDM Rock 4"
"C:\WINDOWS\system32\havlopnde.exe"="C:\WINDOWS\system32\havlopnde.exe:*:Enabled:MDM Rock 4"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
shell\Auto\command - C:\qkwoyoxlj.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL qkwoyoxlj.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\Auto\command - D:\qkwoyoxlj.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL qkwoyoxlj.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{690f04de-4ddc-11dd-bf3a-001617d68d44}]
shell\Auto\command - cmd /C launch.bat
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{84232d7c-bcbf-11dd-bfad-001617d68d44}]
shell\Auto\command - G:\gdkninxoh.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL gdkninxoh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b27d5af2-e73e-11dd-bfd4-001617d68d44}]
shell\AutoRun\command - G:\jeorels.cmd
shell\open\command - G:\jeorels.cmd
======List of files/folders created in the last 1 months======
2009-02-25 19:31:50 ----D---- C:\Program Files\trend micro
2009-02-25 19:31:49 ----D---- C:\rsit
2009-02-25 19:30:03 ----H---- C:\axonbczso.exe
2009-02-24 22:15:30 ----D---- C:\WINDOWS\AU_Temp
2009-02-06 21:38:01 ----D---- C:\WINDOWS\report
2009-02-06 21:36:57 ----D---- C:\WINDOWS\AU_Backup
2009-02-06 21:36:57 ----A---- C:\WINDOWS\tsc.ini
2009-02-06 21:36:56 ----A---- C:\WINDOWS\vsapi32.dll
2009-02-06 21:36:56 ----A---- C:\WINDOWS\tsc.exe
2009-02-06 21:36:56 ----A---- C:\WINDOWS\hcextoutput.dll
2009-02-06 21:36:56 ----A---- C:\WINDOWS\BPMNT.dll
2009-02-06 21:36:34 ----D---- C:\WINDOWS\AU_Log
2009-02-06 21:36:34 ----A---- C:\WINDOWS\GetServer.ini
2009-02-06 21:36:30 ----A---- C:\WINDOWS\UNZIP.DLL
2009-02-06 21:36:30 ----A---- C:\WINDOWS\TMUPDATE.DLL
2009-02-06 21:36:29 ----A---- C:\WINDOWS\PATCH.EXE
======List of files/folders modified in the last 1 months======
2009-02-25 19:31:50 ----RD---- C:\Program Files
2009-02-25 19:31:14 ----A---- C:\WINDOWS\ntbtlog.txt
2009-02-25 19:30:33 ----D---- C:\Program Files\Mozilla Firefox
2009-02-25 19:30:08 ----D---- C:\WINDOWS\Temp
2009-02-25 19:29:05 ----D---- C:\WINDOWS\system32
2009-02-25 19:29:04 ----D---- C:\WINDOWS\system32\drivers
2009-02-25 18:49:06 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-02-24 23:24:50 ----SH---- C:\boot.ini
2009-02-24 23:24:50 ----A---- C:\WINDOWS\win.ini
2009-02-24 23:24:50 ----A---- C:\WINDOWS\system.ini
2009-02-24 23:17:33 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-24 23:14:37 ----D---- C:\WINDOWS
2009-02-24 22:00:50 ----A---- C:\WINDOWS\winhlp32.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\wul.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\wscntfy.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\winhlp32.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\wextract.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\upnpcont.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\tscon.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\telnet.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\tcpsvcs.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\taskman.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\tasklist.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\syskey.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\subst.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\stimon.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\smbinst.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\nvcolor.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\netdde.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\narrator.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\mrinfo.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\mqbkup.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\makecab.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\lpq.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\hostname.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\getmac.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\freecell.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\findstr.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\find.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\fc.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\eventcreate.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\esentutl.exe
2009-02-24 22:00:45 ----A---- C:\WINDOWS\system32\cmd.exe
2009-02-24 22:00:45 ----A---- C:\WINDOWS\system32\clspack.exe
2009-02-24 22:00:44 ----RA---- C:\WINDOWS\SkyTel.exe
2009-02-24 22:00:44 ----RA---- C:\WINDOWS\RTLCPL.EXE
2009-02-24 22:00:44 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\WISPTIS.EXE
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\ckcnv.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\blastcln.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\atmadm.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\arp.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\setdebug.exe
2009-02-24 22:00:42 ----RA---- C:\WINDOWS\ALCWZRD.EXE
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\xcopy.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wupdmgr.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wscript.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\write.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wpabaln.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wjview.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winver.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winmsd.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winmine.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winfxdocobj.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\spnpinst.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\spiisupd.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\spider.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\sort.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\sol.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\skeys.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\sigverif.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shutdown.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shrpubw.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shmgrate.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shadow.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sfc.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\setup.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sethc.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\secedit.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sdbinst.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\scardsvr.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sc.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\savedump.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\runonce.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\runas.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rsvp.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rsopprov.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rsnotify.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsmui.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsmsink.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsm.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsh.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\routemon.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\route.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rexec.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\reset.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\replace.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\migpwd.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\magnify.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\lpr.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\logoff.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\logman.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\logagent.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\lodctr.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\locator.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\lnkstub.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\lights.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\label.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\help.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\grpconv.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\gpupdate.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\gpresult.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\ftp.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fsutil.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fsquirt.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\forcedos.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fontview.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fixmapi.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\finger.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\extrac32.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\expand.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\eventvwr.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\eudcedit.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dxdiag.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dwwin.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dvdplay.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\drwtsn32.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\defrag.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\ddeshare.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\cscript.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\convert.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\control.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\conime.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\compact.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\comp.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\cmstp.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\cmmon32.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cmdl32.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\clipsrv.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cliconfg.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cisvc.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cipher.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cidaemon.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\chkntfs.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\chkdsk.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\charmap.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\calc.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cacls.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\bootvrfy.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\bootok.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\bootcfg.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\auditusr.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\attrib.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\at.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\Restoration.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\asr_ldm.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\ahui.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\actmovie.exe
2009-02-24 22:00:07 ----RA---- C:\WINDOWS\SOUNDMAN.EXE
2009-02-24 22:00:07 ----RA---- C:\WINDOWS\RtlUpd.exe
2009-02-24 22:00:07 ----RA---- C:\WINDOWS\MicCal.exe
2009-02-24 22:00:07 ----A---- C:\WINDOWS\notepad.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\vsnpstd3.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\w32tm.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\vssvc.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\vssadmin.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\verifier.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\verclsid.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\userinit.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\relog.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regwiz.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regsvr32.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regini.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regedt32.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\reg.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\recover.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rcp.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rcimlby.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rasphone.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rasdial.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rasautou.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\proxycfg.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\proquota.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\progman.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\print.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\powercfg.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\ping6.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\ping.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\perfmon.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\pentnt.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\nvcplui.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\mshta.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\logonui.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\keystone.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\jview.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\jdbgmgr.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\irftp.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipxroute.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipv6.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipsec6.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipconfig.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\imapi.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\iexpress.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\dumprep.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\driverquery.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\doskey.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dmremote.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dmadmin.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dllhst3g.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dllhost.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\VttHooks.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\Performence.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\diskperf.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\diskpart.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\diantz.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2009-02-24 21:59:35 ----A---- C:\WINDOWS\system32\MyDrivers.EXE
2009-02-24 21:59:35 ----A---- C:\WINDOWS\regedit.exe
2009-02-24 21:59:34 ----RA---- C:\WINDOWS\ALCMTR.EXE
2009-02-24 21:59:08 ----A---- C:\WINDOWS\twunk_32.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\utilman.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\usrshuta.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\usrprbda.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\usrmlnka.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\ups.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\unlodctr.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\typeperf.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tskill.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tracert6.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tracert.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tracerpt.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tlntsess.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tftp.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tcmsetup.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\taskmgr.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\taskkill.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\systray.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\systeminfo.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\syncapp.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\pathping.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\packager.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\osuninst.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\osk.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\openfiles.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\odbcconf.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\odbcad32.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\nwscript.exe
2009-02-24 21:59:05 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nwiz.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nvunrm.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nvappbar.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\ntvdm.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\ntsd.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\ntbackup.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nslookup.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\netstat.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\netsh.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\netsetup.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\net1.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\net.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\nddeapir.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\nbtstat.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\msswchx.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\msg.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mqsvc.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mpnotify.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mountvol.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mobsync.exe
2009-02-24 21:59:03 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-02-24 21:59:03 ----A---- C:\WINDOWS\system32\mmcperf.exe
2009-02-24 21:59:03 ----A---- C:\WINDOWS\system32\mmc.exe
2009-02-24 21:58:57 ----A---- C:\WINDOWS\system32\Pagedfrg.exe
2009-02-24 21:58:56 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-02-24 21:58:56 ----A---- C:\WINDOWS\system32\MSCONFIG.EXE
2009-02-24 21:58:56 ----A---- C:\WINDOWS\hh.exe
2009-02-24 21:58:56 ----A---- C:\WINDOWS\amcap.exe
2009-02-24 21:58:24 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-02-24 20:01:09 ----SD---- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2009-02-23 18:49:19 ----D---- C:\Documents and Settings\Administrateur\Application Data\Azureus
2009-02-17 19:06:36 ----D---- C:\WINDOWS\system32\CatRoot2
2009-02-07 00:28:59 ----D---- C:\Program Files\Windows Media Player
2009-02-06 22:26:20 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2009-02-06 22:26:20 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-02-06 22:26:20 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-02-06 22:23:30 ----D---- C:\WINDOWS\Drive
2009-02-06 21:38:01 ----D---- C:\WINDOWS\Debug
2009-02-06 21:36:32 ----SD---- C:\WINDOWS\Downloaded Program Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-28 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-28 4304384]
R3 irsir;Pilote série infrarouge Microsoft; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-26 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-26 6780768]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2006-09-15 10205696]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 251392]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-12-11 77824]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-10 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-26 176195]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 927744]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
-----------------EOF-----------------
et info.txt:
info.txt logfile of random's system information tool 1.05 2009-02-25 19:32:17
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
ASUS Enhanced Display Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x40c -removeonly
Cener Connector V1-->MsiExec.exe /I{8B4BE99C-9887-43D3-AA9A-641A07DBDD53}
eMule-->"D:\Program Files\eMule\Uninstall.exe"
EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
FINAL FANTASY XI: Chains of Promathia-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A9110D4F-86DC-46DC-A1E6-097692C2D2FF}
FINAL FANTASY XI: Les guerriers de la Déesse-->C:\Program Files\InstallShield Installation Information\{19451766-07CE-4A79-9A6A-61FC0395C319}\setup.exe -runfromtemp -l0x040c
FINAL FANTASY XI: Rise of the Zilart-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A4CC41E4-2AED-448D-9D1C-61EB028C2C6D}
FINAL FANTASY XI: Treasures of Aht Urhgan-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1EB8607F-C1F8-476E-9D54-AFD8CDA09B6B}
FINAL FANTASY XI-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{45105F2B-0294-4354-A92A-5D1F575E24A5}
GenoPro 2.0.1.6-->D:\Program Files\GenoPro\Uninstall.exe
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
ImgBurn 2.3.2.0 Fr-->"D:\Program Files\ImgBurn\unins000.exe"
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jewel Quest 2 Deluxe-->"C:\Program Files\Zylom Games\Jewel Quest 2 Deluxe\GameInstlr.exe" --uninstall UnInstall.log
K-Lite Mega Codec Pack 1.59-->"d:\Program Files\K-Lite Codec Pack\unins000.exe"
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB925672)-->MsiExec.exe /I{A9CF9052-F4A0-475D-A00F-A8388C62DD63}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 6.0 Parser (KB927977)-->MsiExec.exe /I{025B7033-5D4A-4B72-A1C2-84BE4BE2F72F}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
PDFCreator-->D:\Program Files\PDFCreator\unins000.exe
PlayOnline Viewer and Tetra Master-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A82B049B-14E7-4E0E-946D-024AC4050EF8}
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Security Update for Microsoft .NET Framework 2.0 (KB917283)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {967B098A-042D-4367-BAC9-8BC11684174F} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update pour Microsoft .NET Framework 2.0 (KB922770)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Skype 3.1-->"C:\Program Files\Skype\Phone\unins000.exe"
Skype Plugin Manager-->MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
Spybot - Search & Destroy-->"D:\Program Files\Spybot - Search & Destroy\unins000.exe"
USB PC Camera Plus-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECD03DA7-5952-406A-8156-5F0C93618D1F}\Setup.exe" -l0x40c
VideoLAN VLC media player 0.8.6c-->D:\Program Files\VideoLAN\VLC\uninstall.exe
Vuze-->D:\Program Files\Vuze\uninstall.exe
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
======Hosts File======
127.0.0.1 mpa.one.microsoft.com
System event log
Computer Name: ORKAS
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FA76032D-60B7-4E6D-B2CD-1D99A590467B} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.
Record Number: 10109
Source Name: Tcpip
Time Written: 20081122202905.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 8033
Message: L'explorateur a forcé une élection sur le réseau \Device\NetBT_Tcpip_{FA76032D-60B7-4E6D-B2CD-1D99A590467B} car un maître explorateur a été arrêté.
Record Number: 10108
Source Name: BROWSER
Time Written: 20081122202835.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 4202
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FA76032D-60B7-4E6D-B2CD-1D99A590467B} était déconnectée du réseau,
et la configuration réseau de la carte a été abandonnée. Si la carte
réseau n'était pas déconnectée, ceci peut indiquer un disfonctionnement.
Contactez le fabricant pour des pilotes mis à jour.
Record Number: 10107
Source Name: Tcpip
Time Written: 20081122202835.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 4201
Message: Le système a détecté que la carte réseau \DEVICE\TCPIP_{FA76032D-60B7-4E6D-B2CD-1D99A590467B} était connectée au réseau,
et a lancé une opération normale sur la carte réseau.
Record Number: 10106
Source Name: Tcpip
Time Written: 20081122202341.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 7036
Message: Le service Gestionnaire de connexion automatique d'accès distant est entré dans l'état : en cours d'exécution.
Record Number: 10105
Source Name: Service Control Manager
Time Written: 20081122201530.000000+060
Event Type: Informations
User:
Application event log
Computer Name: ORKAS
Event Code: 101
Message: wuauclt (220) Le moteur de base de données est arrêté.
Record Number: 10316
Source Name: ESENT
Time Written: 20090106125614.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 103
Message: wuaueng.dll (220) SUS20ClientDataStore: Le moteur de base de données a arrêté une instance (0).
Record Number: 10315
Source Name: ESENT
Time Written: 20090106125614.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 102
Message: wuaueng.dll (220) SUS20ClientDataStore: Le moteur de base de données a démarré une nouvelle instance (0).
Record Number: 10314
Source Name: ESENT
Time Written: 20090106125114.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 100
Message: wuauclt (220) Le moteur de base de données 5.01.2600.2780 est démarré.
Record Number: 10313
Source Name: ESENT
Time Written: 20090106125114.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 1047
Message: Windows ne peut pas lire l'historique des objets de paramètre de groupe à partir du Registre. Le traitement de la stratégie de groupe continue.
Record Number: 10312
Source Name: Userenv
Time Written: 20090106122752.000000+060
Event Type: erreur
User: AUTORITE NT\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 95 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=5f02
"NUMBER_OF_PROCESSORS"=1
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"DEVMGR_SHOW_DETAILS"=1
-----------------EOF-----------------
Merci d'avance pour vous intéresser à mon cas!
D.
Message édité par Destrio5.
Message édité par Destrio5 le 25-02-2009 à 20:16:09
le voilà:
-------------- UsbFix V2.414.3 ---------------
* User : Administrateur - ORKAS
* Outils mis a jours le 18/01/2009 par Chiquitine29 et Chimay8
* Recherche effectuée à 20:04:37 le 25/02/2009
* Windows Xp - Internet Explorer 7.0.5730.11
--------------- [ Processus actifs ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
--------------- [ Informations lecteurs ] ----------------
C: - Lecteur fixe D: - Lecteur fixe F: - Lecteur fixe G: - Lecteur amovible H: - Lecteur amovible
+- Contenu de l'autorun : C:\autorun.inf
+- Contenu de l'autorun : D:\autorun.inf
+- Contenu de l'autorun : F:\autorun.inf
+- Contenu de l'autorun : G:\autorun.inf
+- Contenu de l'autorun : H:\autorun.inf
[AutoRun]
open=ypudxrdgx.exe
shellexecute=ypudxrdgx.exe
shell\Auto\command=ypudxrdgx.exe
shell=Auto
[VVflagRun]
aabb=kdkfjdkfk1
--------------- [ Lecteur C ] ----------------
C: - Lecteur fixe
+- Listing des fichiers présents :
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38 Orkas Ultimate][-rahs----] C:\NTDETECT.COM
[29/11/2006 20:40 Orkas Ultimate][---h-----] C:\ypudxrdgx.exe
[24/02/2009 23:24 Orkas Ultimate][---hs----] C:\boot.ini
[25/02/2009 19:59 Orkas Ultimate][d--h-----] C:\autorun.inf
[25/02/2009 20:04 Orkas Ultimate][--a------] C:\UsbFix.txt
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\CONFIG.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\IO.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\MSDOS.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\pagefile.sys
--------------- [ Lecteur D ] ----------------
D: - Lecteur fixe
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] D:\ypudxrdgx.exe
[25/02/2009 19:59 Orkas Ultimate][d--h-----] D:\autorun.inf
--------------- [ Lecteur F ] ----------------
F: - Lecteur fixe
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] F:\ypudxrdgx.exe
[25/02/2009 19:59 Orkas Ultimate][d--h-----] F:\autorun.inf
--------------- [ Lecteur G ] ----------------
G: - Lecteur amovible
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] G:\ypudxrdgx.exe
[25/02/2009 19:59 Orkas Ultimate][d--h-----] G:\autorun.inf
--------------- [ Lecteur H ] ----------------
H: - Lecteur amovible
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] H:\axonbczso.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] H:\ypudxrdgx.exe
[10/05/2008 11:29 Orkas Ultimate][--a------] H:\_DS_MENU.INI
[25/02/2009 20:03 Orkas Ultimate][--ah-----] H:\AUTORUN.INF
[24/02/2009 20:11 Orkas Ultimate][--a------] H:\_DS_MENU.SYS
--------------- [ Registre / Startup ] ----------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://windows-unattended.fr"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
3D=C:\program Files\Topdesk\topdesk.exe
Horlorge=C:\program Files\Clock\Clock.exe
Sidebar=C:\program Files\Windows Sidebar\sidebar.exe
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer=D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
RTHDCPL=RTHDCPL.EXE
Alcmtr=ALCMTR.EXE
NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
tsnpstd3=C:\WINDOWS\tsnpstd3.exe
snpstd3=C:\WINDOWS\vsnpstd3.exe
MDM Rock 4=C:\WINDOWS\system32\havlopnde.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=
--------------- [ Registre / Mountpoint2 ] ----------------
-> Recherche négative.
--------------- [ Nettoyage des disques ] ----------------
Echec de la supression !! - [25/02/2009 20:06 Orkas Ultimate] C:\autorun.inf
Supprimé ! - [25/02/2009 20:06 Orkas Ultimate][d--------] C:\autorun.inf
Echec de la supression !! - [25/02/2009 20:06 Orkas Ultimate] D:\autorun.inf
Supprimé ! - [25/02/2009 20:06 Orkas Ultimate][d--------] D:\autorun.inf
Echec de la supression !! - [25/02/2009 19:59 Orkas Ultimate] F:\autorun.inf
Supprimé ! - [25/02/2009 19:59 Orkas Ultimate][d--------] F:\autorun.inf
Echec de la supression !! - [25/02/2009 19:59 Orkas Ultimate] G:\autorun.inf
Supprimé ! - [25/02/2009 19:59 Orkas Ultimate][d--------] G:\autorun.inf
Supprimé ! - [25/02/2009 20:03 Orkas Ultimate][--ah-----] H:\autorun.inf
--------------- [ Resumé ] ----------------
-> /!\ Le resultat doit etre [http://www.virustotal.com/fr/ interprété] par un spécialiste /!\
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38 Orkas Ultimate][-rahs----] C:\NTDETECT.COM
[29/11/2006 20:40 Orkas Ultimate][---h-----] C:\ypudxrdgx.exe
[24/02/2009 23:24 Orkas Ultimate][---hs----] C:\boot.ini
[29/11/2006 20:40 Orkas Ultimate][---h-----] D:\ypudxrdgx.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] F:\ypudxrdgx.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] G:\ypudxrdgx.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] H:\axonbczso.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] H:\ypudxrdgx.exe
[10/05/2008 11:29 Orkas Ultimate][--a------] H:\_DS_MENU.INI
--------------- [ Vaccination ] ----------------
C:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
D:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
F:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
G:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
H:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
--------------- ! Fin du rapport ! ----------------
Windows Orkas Ultimate est illégal.
- Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.
- Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
- Double-clique sur OTMoveIt3.exe afin de le lancer.
- Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
|
- Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
- Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
- Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
---> Le nom du rapport correspond au moment de sa création : date_heure.log
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder C:\ypudxrdgx.exe not found.
File/Folder D:\ypudxrdgx.exe not found.
File/Folder F:\ypudxrdgx.exe not found.
File/Folder G:\ypudxrdgx.exe not found.
File/Folder H:\axonbczso.exe not found.
File/Folder H:\ypudxrdgx.exe not found.
File/Folder C:\WINDOWS\system32\gwcbrpzfp.exe not found.
C:\WINDOWS\system32\tdwenvxpq.exe moved successfully.
C:\WINDOWS\system32\mgdrwfsvl.exe moved successfully.
C:\WINDOWS\system32\gfcfrhqhg.exe moved successfully.
C:\WINDOWS\system32\havlopnde.exe moved successfully.
c:\documents and settings\administrateur\local settings\application data\bnagtnag.exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\gwcbrpzfp.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\tdwenvxpq.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\mgdrwfsvl.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\gfcfrhqhg.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\havlopnde.exe deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MDM Rock 4\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bnagtnag\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MDM Rock 4 deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_TpJAyYgbm0YVH79fqtVT scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_484.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02252009_202607
Files moved on Reboot...
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_TpJAyYgbm0YVH79fqtVT moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_484.dat moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Mozilla\Firefox\Profiles\94817rjl.default\XUL.mfl moved successfully.
- Refais un scan RSIT et poste le rapport log.
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrateur at 2009-02-25 20:56:30
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 4 GB (20%) free of 20 GB
Total RAM: 1023 MB (43% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:56 , on 25/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\tsnpstd3.exe
C:\program Files\Topdesk\topdesk.exe
C:\program Files\Clock\Clock.exe
C:\program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
C:\Program Files\trend micro\Administrateur.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windows-unattended.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://windows-unattended.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://windows-unattended.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windows-unattended.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://windows-unattended.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windows-unattended.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
O4 - HKLM\..\Run: [MDM Rock 4] C:\WINDOWS\system32\havlopnde.exe
O4 - HKLM\..\RunOnce: [OTMoveIt] C:\Documents and Settings\Administrateur\Bureau\OTMoveIt3.exe
O4 - HKCU\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe
O4 - HKCU\..\Run: [Horlorge] C:\program Files\Clock\Clock.exe
O4 - HKCU\..\Run: [Sidebar] C:\program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Vistadrv] C:\Windows\Drive\vsdrv.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Signature] C:\Windows\Drive\sign.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Horlorge] C:\program Files\Clock\Clock.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\program Files\Windows Sidebar\sidebar.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [3D] C:\program Files\Topdesk\topdesk.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 6891 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - D:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-10 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-10 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-10 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
LinksFolderName
SaveLinksOrder
Locked
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-06-28 16258048]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2009-02-24 69632]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-04-26 8445952]
"KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-04-26 81920]
"tsnpstd3"=C:\WINDOWS\tsnpstd3.exe [2006-07-07 274432]
"snpstd3"=C:\WINDOWS\vsnpstd3.exe [2009-02-24 843776]
"MDM Rock 4"=C:\WINDOWS\system32\havlopnde.exe []
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"OTMoveIt"=C:\Documents and Settings\Administrateur\Bureau\OTMoveIt3.exe [2009-02-25 357888]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"3D"=C:\program Files\Topdesk\topdesk.exe [2006-11-06 205312]
"Horlorge"=C:\program Files\Clock\Clock.exe [2006-11-11 152576]
"Sidebar"=C:\program Files\Windows Sidebar\sidebar.exe [2006-11-12 1258496]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 25088]
"SpybotSD TeaTimer"=D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE [2009-02-24 131267]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ORAHSSSessionManager]
C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2007-12-12 107248]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Signature]
C:\Windows\Drive\sign.exe [2009-02-24 435353]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
C:\WINDOWS\SkyTel.EXE [2009-02-24 2879488]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vistadrv]
C:\WINDOWS\Drive\vsdrv.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\FileZilla\FileZilla.exe"="C:\Program Files\FileZilla\FileZilla.exe:*:Enabled:FileZilla"
"D:\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe"="D:\PlayOnline\SquareEnix\PlayOnlineViewer\pol.exe:*:Enabled
layOnline Viewer"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\Program Files\VideoLAN\VLC\vlc.exe"="D:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player"
"D:\Program Files\Vuze\Azureus.exe"="D:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus"
"D:\Program Files\eMule\emule.exe"="D:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
======List of files/folders created in the last 1 months======
2009-02-25 20:26:07 ----D---- C:\_OTMoveIt
2009-02-25 20:07:23 ----N---- C:\jqrugftho.exe
2009-02-25 20:06:49 ----HD---- C:\autorun.inf
2009-02-25 19:57:42 ----A---- C:\UsbFix.txt
2009-02-25 19:52:33 ----D---- C:\Program Files\UsbFix
2009-02-25 19:31:50 ----D---- C:\Program Files\trend micro
2009-02-25 19:31:49 ----D---- C:\rsit
2009-02-24 22:15:30 ----D---- C:\WINDOWS\AU_Temp
2009-02-06 21:38:01 ----D---- C:\WINDOWS\report
2009-02-06 21:36:57 ----D---- C:\WINDOWS\AU_Backup
2009-02-06 21:36:57 ----A---- C:\WINDOWS\tsc.ini
2009-02-06 21:36:56 ----A---- C:\WINDOWS\vsapi32.dll
2009-02-06 21:36:56 ----A---- C:\WINDOWS\tsc.exe
2009-02-06 21:36:56 ----A---- C:\WINDOWS\hcextoutput.dll
2009-02-06 21:36:56 ----A---- C:\WINDOWS\BPMNT.dll
2009-02-06 21:36:34 ----D---- C:\WINDOWS\AU_Log
2009-02-06 21:36:34 ----A---- C:\WINDOWS\GetServer.ini
2009-02-06 21:36:30 ----A---- C:\WINDOWS\UNZIP.DLL
2009-02-06 21:36:30 ----A---- C:\WINDOWS\TMUPDATE.DLL
2009-02-06 21:36:29 ----A---- C:\WINDOWS\PATCH.EXE
======List of files/folders modified in the last 1 months======
2009-02-25 20:29:46 ----D---- C:\Program Files\Mozilla Firefox
2009-02-25 20:29:38 ----A---- C:\WINDOWS\ntbtlog.txt
2009-02-25 20:28:29 ----D---- C:\WINDOWS\Temp
2009-02-25 20:26:07 ----D---- C:\WINDOWS\system32
2009-02-25 20:03:45 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-02-25 19:52:33 ----RD---- C:\Program Files
2009-02-25 19:29:04 ----D---- C:\WINDOWS\system32\drivers
2009-02-24 23:24:50 ----SH---- C:\boot.ini
2009-02-24 23:24:50 ----A---- C:\WINDOWS\win.ini
2009-02-24 23:24:50 ----A---- C:\WINDOWS\system.ini
2009-02-24 23:17:33 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-24 23:14:37 ----D---- C:\WINDOWS
2009-02-24 22:00:50 ----A---- C:\WINDOWS\winhlp32.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\wul.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\wscntfy.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\winhlp32.exe
2009-02-24 22:00:50 ----A---- C:\WINDOWS\system32\wextract.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\upnpcont.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\tscon.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\telnet.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\tcpsvcs.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\taskman.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\tasklist.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\syskey.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\subst.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\stimon.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\smbinst.exe
2009-02-24 22:00:49 ----A---- C:\WINDOWS\system32\nvcolor.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\netdde.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\narrator.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\msiexec.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\mrinfo.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\mqbkup.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\makecab.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\lpq.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\hostname.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\getmac.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\freecell.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\findstr.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\find.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\fc.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\eventcreate.exe
2009-02-24 22:00:48 ----A---- C:\WINDOWS\system32\esentutl.exe
2009-02-24 22:00:45 ----A---- C:\WINDOWS\system32\cmd.exe
2009-02-24 22:00:45 ----A---- C:\WINDOWS\system32\clspack.exe
2009-02-24 22:00:44 ----RA---- C:\WINDOWS\SkyTel.exe
2009-02-24 22:00:44 ----RA---- C:\WINDOWS\RTLCPL.EXE
2009-02-24 22:00:44 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\WISPTIS.EXE
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\ckcnv.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\blastcln.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\atmadm.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\system32\arp.exe
2009-02-24 22:00:44 ----A---- C:\WINDOWS\setdebug.exe
2009-02-24 22:00:42 ----RA---- C:\WINDOWS\ALCWZRD.EXE
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\xcopy.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wupdmgr.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wscript.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\write.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wpnpinst.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wpabaln.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\wjview.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winver.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winmsd.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winmine.exe
2009-02-24 22:00:26 ----A---- C:\WINDOWS\system32\winfxdocobj.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\spnpinst.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\spiisupd.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\spider.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\sort.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\sol.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\smlogsvc.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\skeys.exe
2009-02-24 22:00:22 ----A---- C:\WINDOWS\system32\sigverif.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shutdown.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shrpubw.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shmgrate.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\shadow.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sfc.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\setup.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sethc.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\secedit.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sdbinst.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\schtasks.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\scardsvr.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\sc.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\savedump.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\runonce.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\runas.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rsvp.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rsopprov.exe
2009-02-24 22:00:21 ----A---- C:\WINDOWS\system32\rsnotify.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsmui.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsmsink.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsm.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rsh.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\routemon.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\route.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\rexec.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\reset.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\replace.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\migpwd.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\magnify.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\lpr.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\logoff.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\logman.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\logagent.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\lodctr.exe
2009-02-24 22:00:20 ----A---- C:\WINDOWS\system32\locator.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\lnkstub.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\lights.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\label.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\help.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\grpconv.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\gpupdate.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\gpresult.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\ftp.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fsutil.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fsquirt.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\forcedos.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fontview.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\fixmapi.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\finger.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\extrac32.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\expand.exe
2009-02-24 22:00:19 ----A---- C:\WINDOWS\system32\eventvwr.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\eventtriggers.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\eudcedit.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dxdiag.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dwwin.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dvdupgrd.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\dvdplay.exe
2009-02-24 22:00:18 ----A---- C:\WINDOWS\system32\drwtsn32.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\dfrgfat.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\defrag.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\ddeshare.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\cscript.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\convert.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\control.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\conime.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\compact.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\comp.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\cmstp.exe
2009-02-24 22:00:10 ----A---- C:\WINDOWS\system32\cmmon32.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cmdl32.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\clipsrv.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cliconfg.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cleanmgr.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cisvc.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cipher.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cidaemon.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\chkntfs.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\chkdsk.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\charmap.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\calc.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\cacls.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\bootvrfy.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\bootok.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\bootcfg.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\auditusr.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\attrib.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\at.exe
2009-02-24 22:00:09 ----A---- C:\WINDOWS\system32\asr_pfu.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\Restoration.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\asr_ldm.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\asr_fmt.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\ahui.exe
2009-02-24 22:00:08 ----A---- C:\WINDOWS\system32\actmovie.exe
2009-02-24 22:00:07 ----RA---- C:\WINDOWS\SOUNDMAN.EXE
2009-02-24 22:00:07 ----RA---- C:\WINDOWS\RtlUpd.exe
2009-02-24 22:00:07 ----RA---- C:\WINDOWS\MicCal.exe
2009-02-24 22:00:07 ----A---- C:\WINDOWS\notepad.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\vsnpstd3.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\w32tm.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\vssvc.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\vssadmin.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\verifier.exe
2009-02-24 21:59:43 ----A---- C:\WINDOWS\system32\verclsid.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\userinit.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\relog.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regwiz.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regsvr32.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regini.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\regedt32.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\reg.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\recover.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rcp.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rcimlby.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rasphone.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rasdial.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\rasautou.exe
2009-02-24 21:59:42 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\proxycfg.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\proquota.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\progman.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\print.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\powercfg.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\ping6.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\ping.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\perfmon.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\pentnt.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\nvcplui.exe
2009-02-24 21:59:41 ----A---- C:\WINDOWS\system32\mshta.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\logonui.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\keystone.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\jview.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\jdbgmgr.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\irftp.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipxroute.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipv6.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipsec6.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\ipconfig.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\imapi.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\iexpress.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\dumprep.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\driverquery.exe
2009-02-24 21:59:40 ----A---- C:\WINDOWS\system32\dpvsetup.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dplaysvr.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\doskey.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dmremote.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dmadmin.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dllhst3g.exe
2009-02-24 21:59:39 ----A---- C:\WINDOWS\system32\dllhost.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\VttHooks.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\Performence.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\diskperf.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\diskpart.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\diantz.exe
2009-02-24 21:59:36 ----A---- C:\WINDOWS\system32\dfrgntfs.exe
2009-02-24 21:59:35 ----A---- C:\WINDOWS\system32\MyDrivers.EXE
2009-02-24 21:59:35 ----A---- C:\WINDOWS\regedit.exe
2009-02-24 21:59:34 ----RA---- C:\WINDOWS\ALCMTR.EXE
2009-02-24 21:59:08 ----A---- C:\WINDOWS\twunk_32.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\utilman.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\usrshuta.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\usrprbda.exe
2009-02-24 21:59:08 ----A---- C:\WINDOWS\system32\usrmlnka.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\ups.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\unlodctr.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\typeperf.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tskill.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tracert6.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tracert.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tracerpt.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tlntsvr.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tlntsess.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tlntadmn.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tftp.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\tcmsetup.exe
2009-02-24 21:59:07 ----A---- C:\WINDOWS\system32\taskmgr.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\taskkill.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\systray.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\systeminfo.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\sysocmgr.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\syncapp.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\pathping.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\packager.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\osuninst.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\osk.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\openfiles.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\odbcconf.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\odbcad32.exe
2009-02-24 21:59:06 ----A---- C:\WINDOWS\system32\nwscript.exe
2009-02-24 21:59:05 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nwiz.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nvunrm.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nvappbar.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\ntvdm.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\ntsd.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\ntbackup.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\nslookup.exe
2009-02-24 21:59:05 ----A---- C:\WINDOWS\system32\netstat.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\netsh.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\netsetup.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\net1.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\net.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\nddeapir.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\nbtstat.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\msswchx.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\msg.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mqtgsvc.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mqsvc.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mpnotify.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mountvol.exe
2009-02-24 21:59:04 ----A---- C:\WINDOWS\system32\mobsync.exe
2009-02-24 21:59:03 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-02-24 21:59:03 ----A---- C:\WINDOWS\system32\mmcperf.exe
2009-02-24 21:59:03 ----A---- C:\WINDOWS\system32\mmc.exe
2009-02-24 21:58:57 ----A---- C:\WINDOWS\system32\Pagedfrg.exe
2009-02-24 21:58:56 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-02-24 21:58:56 ----A---- C:\WINDOWS\system32\MSCONFIG.EXE
2009-02-24 21:58:56 ----A---- C:\WINDOWS\hh.exe
2009-02-24 21:58:56 ----A---- C:\WINDOWS\amcap.exe
2009-02-24 21:58:24 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-02-24 20:01:09 ----SD---- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2009-02-23 18:49:19 ----D---- C:\Documents and Settings\Administrateur\Application Data\Azureus
2009-02-17 19:06:36 ----D---- C:\WINDOWS\system32\CatRoot2
2009-02-07 00:28:59 ----D---- C:\Program Files\Windows Media Player
2009-02-06 22:26:20 ----A---- C:\WINDOWS\system32\wiaacmgr.exe
2009-02-06 22:26:20 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-02-06 22:26:20 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-02-06 22:23:30 ----D---- C:\WINDOWS\Drive
2009-02-06 21:38:01 ----D---- C:\WINDOWS\Debug
2009-02-06 21:36:32 ----SD---- C:\WINDOWS\Downloaded Program Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 asuskbnt;Enhanced Display Driver Helper Service; C:\WINDOWS\system32\drivers\atkkbnt.sys [2005-10-18 11008]
R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-04 14848]
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 EIO;EIO; \??\C:\WINDOWS\system32\drivers\EIO.sys []
R2 irda;Protocole IrDA; C:\WINDOWS\system32\DRIVERS\irda.sys [2004-08-04 87424]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-28 9600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-28 4304384]
R3 irsir;Pilote série infrarouge Microsoft; C:\WINDOWS\system32\DRIVERS\irsir.sys [2001-08-17 18688]
R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2006-11-26 12288]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-04-26 6780768]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-03-22 52736]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-03-22 18944]
R3 Rasirda;Miniport réseau étendu (IrDA); C:\WINDOWS\system32\DRIVERS\rasirda.sys [2001-08-17 19584]
R3 SNPSTD3;USB PC Camera (SNPSTD3); C:\WINDOWS\system32\DRIVERS\snpstd3.sys [2006-09-15 10205696]
R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCAMPR5.SYS []
S3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\PCANDIS5.SYS []
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ATKKeyboardService;ATK Keyboard Service; C:\WINDOWS\ATKKBService.exe [2006-09-04 251392]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2007-12-11 77824]
R2 Irmon;Moniteur infrarouge; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-10 152984]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-04-26 176195]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-24 927744]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.05 2009-02-25 20:57:44
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
ASUS Enhanced Display Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x40c -removeonly
Cener Connector V1-->MsiExec.exe /I{8B4BE99C-9887-43D3-AA9A-641A07DBDD53}
eMule-->"D:\Program Files\eMule\Uninstall.exe"
EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
FINAL FANTASY XI: Chains of Promathia-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A9110D4F-86DC-46DC-A1E6-097692C2D2FF}
FINAL FANTASY XI: Les guerriers de la Déesse-->C:\Program Files\InstallShield Installation Information\{19451766-07CE-4A79-9A6A-61FC0395C319}\setup.exe -runfromtemp -l0x040c
FINAL FANTASY XI: Rise of the Zilart-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A4CC41E4-2AED-448D-9D1C-61EB028C2C6D}
FINAL FANTASY XI: Treasures of Aht Urhgan-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{1EB8607F-C1F8-476E-9D54-AFD8CDA09B6B}
FINAL FANTASY XI-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{45105F2B-0294-4354-A92A-5D1F575E24A5}
GenoPro 2.0.1.6-->D:\Program Files\GenoPro\Uninstall.exe
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
ImgBurn 2.3.2.0 Fr-->"D:\Program Files\ImgBurn\unins000.exe"
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Jewel Quest 2 Deluxe-->"C:\Program Files\Zylom Games\Jewel Quest 2 Deluxe\GameInstlr.exe" --uninstall UnInstall.log
K-Lite Mega Codec Pack 1.59-->"d:\Program Files\K-Lite Codec Pack\unins000.exe"
Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
Mozilla Firefox (3.0.6)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB925672)-->MsiExec.exe /I{A9CF9052-F4A0-475D-A00F-A8388C62DD63}
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 6.0 Parser (KB927977)-->MsiExec.exe /I{025B7033-5D4A-4B72-A1C2-84BE4BE2F72F}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenOffice.org 3.0-->MsiExec.exe /I{6860B340-530D-46B3-91F8-1AE1F70F7C33}
Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
PDFCreator-->D:\Program Files\PDFCreator\unins000.exe
PlayOnline Viewer and Tetra Master-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A82B049B-14E7-4E0E-946D-024AC4050EF8}
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Security Update for Microsoft .NET Framework 2.0 (KB917283)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {967B098A-042D-4367-BAC9-8BC11684174F} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Security Update pour Microsoft .NET Framework 2.0 (KB922770)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
Skype 3.1-->"C:\Program Files\Skype\Phone\unins000.exe"
Skype Plugin Manager-->MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
Spybot - Search & Destroy-->"D:\Program Files\Spybot - Search & Destroy\unins000.exe"
USB PC Camera Plus-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ECD03DA7-5952-406A-8156-5F0C93618D1F}\Setup.exe" -l0x40c
UsbFix-->C:\Program Files\UsbFix\Uninstal.exe
VideoLAN VLC media player 0.8.6c-->D:\Program Files\VideoLAN\VLC\uninstall.exe
Vuze-->D:\Program Files\Vuze\uninstall.exe
Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
======Hosts File======
127.0.0.1 mpa.one.microsoft.com
System event log
Computer Name: ORKAS
Event Code: 8033
Message: L'explorateur a forcé une élection sur le réseau \Device\NetBT_Tcpip_{FA76032D-60B7-4E6D-B2CD-1D99A590467B} car un maître explorateur a été arrêté.
Record Number: 10154
Source Name: BROWSER
Time Written: 20081122210715.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 7036
Message: Le service Gestionnaire de connexion automatique d'accès distant est entré dans l'état : en cours d'exécution.
Record Number: 10153
Source Name: Service Control Manager
Time Written: 20081122210541.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexion automatique d'accès distant.
Record Number: 10152
Source Name: Service Control Manager
Time Written: 20081122210541.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM
Computer Name: ORKAS
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service PCAMPR5 NDIS Protocol Driver.
Record Number: 10151
Source Name: Service Control Manager
Time Written: 20081122210425.000000+060
Event Type: Informations
User: ORKAS\Administrateur
Computer Name: ORKAS
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service PCANDIS5 NDIS Protocol Driver.
Record Number: 10150
Source Name: Service Control Manager
Time Written: 20081122210425.000000+060
Event Type: Informations
User: ORKAS\Administrateur
Application event log
Computer Name: ORKAS
Event Code: 701
Message: msnmsgr (1272) La défragmentation en ligne a terminé un passage complet dans la base de données '\\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\pamoulette@hotmail.fr\SharingMetadata\Working\database_B6C0_7F16_C07E_DC55\dfsr.db'.
Record Number: 10328
Source Name: ESENT
Time Written: 20090106160004.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 700
Message: msnmsgr (1272) La défragmentation en ligne commence un passage complet dans la base de données '\\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\pamoulette@hotmail.fr\SharingMetadata\Working\database_B6C0_7F16_C07E_DC55\dfsr.db'.
Record Number: 10327
Source Name: ESENT
Time Written: 20090106160004.000000+060
Event Type: Informations
User:
Computer Name: ORKAS
Event Code: 1047
Message: Windows ne peut pas lire l'historique des objets de paramètre de groupe à partir du Registre. Le traitement de la stratégie de groupe continue.
Record Number: 10326
Source Name: Userenv
Time Written: 20090106154353.000000+060
Event Type: erreur
User: AUTORITE NT\SYSTEM
Computer Name: ORKAS
Event Code: 1047
Message: Windows ne peut pas lire l'historique des objets de paramètre de groupe à partir du Registre. Le traitement de la stratégie de groupe continue.
Record Number: 10325
Source Name: Userenv
Time Written: 20090106154353.000000+060
Event Type: erreur
User: AUTORITE NT\SYSTEM
Computer Name: ORKAS
Event Code: 701
Message: msnmsgr (1272) La défragmentation en ligne a terminé un passage complet dans la base de données '\\.\C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Messenger\pamoulette@hotmail.fr\SharingMetadata\Working\database_B6C0_7F16_C07E_DC55\dfsr.db'.
Record Number: 10324
Source Name: ESENT
Time Written: 20090106150004.000000+060
Event Type: Informations
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 95 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=5f02
"NUMBER_OF_PROCESSORS"=1
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"DEVMGR_SHOW_DETAILS"=1
-----------------EOF-----------------
Tu peux refaire un scan avec UsbFix ?
-------------- UsbFix V2.414.3 ---------------
* User : Administrateur - ORKAS
* Outils mis a jours le 18/01/2009 par Chiquitine29 et Chimay8
* Recherche effectuée à 21:09:24 le 25/02/2009
* Windows Xp - Internet Explorer 7.0.5730.11
--------------- [ Processus actifs ] ----------------
--------------- [ Informations lecteurs ] ----------------
C: - Lecteur fixe
D: - Lecteur fixe
F: - Lecteur fixe
G: - Lecteur amovible
H: - Lecteur amovible
+- Contenu de l'autorun : C:\autorun.inf
+- Contenu de l'autorun : D:\autorun.inf
+- Contenu de l'autorun : F:\autorun.inf
+- Contenu de l'autorun : G:\autorun.inf
+- Contenu de l'autorun : H:\autorun.inf
--------------- [ Lecteur C ] ----------------
C: - Lecteur fixe
+- Listing des fichiers présents :
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38 Orkas Ultimate][-rahs----] C:\NTDETECT.COM
[29/11/2006 20:40 Orkas Ultimate][---------] C:\jqrugftho.exe
[24/02/2009 23:24 Orkas Ultimate][---hs----] C:\boot.ini
[25/02/2009 20:06 Orkas Ultimate][d--h-----] C:\autorun.inf
[25/02/2009 21:09 Orkas Ultimate][--a------] C:\UsbFix.txt
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\CONFIG.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\IO.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\MSDOS.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\pagefile.sys
--------------- [ Lecteur D ] ----------------
D: - Lecteur fixe
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] D:\jqrugftho.exe
[25/02/2009 20:06 Orkas Ultimate][d--h-----] D:\autorun.inf
--------------- [ Lecteur F ] ----------------
F: - Lecteur fixe
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] F:\jqrugftho.exe
[25/02/2009 20:06 Orkas Ultimate][d--h-----] F:\autorun.inf
--------------- [ Lecteur G ] ----------------
G: - Lecteur amovible
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] G:\jqrugftho.exe
[25/02/2009 20:06 Orkas Ultimate][d--h-----] G:\autorun.inf
--------------- [ Lecteur H ] ----------------
H: - Lecteur amovible
+- Listing des fichiers présents :
[29/11/2006 20:40 Orkas Ultimate][---h-----] H:\jqrugftho.exe
[10/05/2008 11:29 Orkas Ultimate][--a------] H:\_DS_MENU.INI
[25/02/2009 20:06 Orkas Ultimate][d--h-----] H:\autorun.inf
[24/02/2009 20:11 Orkas Ultimate][--a------] H:\_DS_MENU.SYS
--------------- [ Registre / Startup ] ----------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://windows-unattended.fr"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
3D=C:\program Files\Topdesk\topdesk.exe
Horlorge=C:\program Files\Clock\Clock.exe
Sidebar=C:\program Files\Windows Sidebar\sidebar.exe
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer=D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
RTHDCPL=RTHDCPL.EXE
Alcmtr=ALCMTR.EXE
NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
tsnpstd3=C:\WINDOWS\tsnpstd3.exe
snpstd3=C:\WINDOWS\vsnpstd3.exe
MDM Rock 4=C:\WINDOWS\system32\havlopnde.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=
--------------- [ Registre / Mountpoint2 ] ----------------
-> Recherche négative.
--------------- [ Nettoyage des disques ] ----------------
Echec de la supression !! - [25/02/2009 21:09 Orkas Ultimate] C:\autorun.inf
Supprimé ! - [25/02/2009 21:09 Orkas Ultimate][d--------] C:\autorun.inf
Echec de la supression !! - [25/02/2009 21:09 Orkas Ultimate] D:\autorun.inf
Supprimé ! - [25/02/2009 21:09 Orkas Ultimate][d--------] D:\autorun.inf
Echec de la supression !! - [25/02/2009 20:06 Orkas Ultimate] F:\autorun.inf
Supprimé ! - [25/02/2009 20:06 Orkas Ultimate][d--------] F:\autorun.inf
Echec de la supression !! - [25/02/2009 20:06 Orkas Ultimate] G:\autorun.inf
Supprimé ! - [25/02/2009 20:06 Orkas Ultimate][d--------] G:\autorun.inf
Echec de la supression !! - [25/02/2009 20:06 Orkas Ultimate] H:\autorun.inf
Supprimé ! - [25/02/2009 20:06 Orkas Ultimate][d--------] H:\autorun.inf
--------------- [ Resumé ] ----------------
-> /!\ Le resultat doit etre [http://www.virustotal.com/fr/ interprété] par un spécialiste /!\
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38 Orkas Ultimate][-rahs----] C:\NTDETECT.COM
[29/11/2006 20:40 Orkas Ultimate][---------] C:\jqrugftho.exe
[24/02/2009 23:24 Orkas Ultimate][---hs----] C:\boot.ini
[29/11/2006 20:40 Orkas Ultimate][---h-----] D:\jqrugftho.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] F:\jqrugftho.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] G:\jqrugftho.exe
[29/11/2006 20:40 Orkas Ultimate][---h-----] H:\jqrugftho.exe
[10/05/2008 11:29 Orkas Ultimate][--a------] H:\_DS_MENU.INI
--------------- [ Vaccination ] ----------------
C:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
D:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
F:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
G:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
H:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
--------------- ! Fin du rapport ! ----------------
Les infections se cachent.
A faire en mode sans échec :
- Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.
- Branche tes sources de données externes à ton PC (clé USB, disque dur externe, carte SD, etc...) sans les ouvrir.
- Double-clique sur OTMoveIt3.exe afin de le lancer.
- Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
|
- Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
- Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
- Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
---> Le nom du rapport correspond au moment de sa création : date_heure.log
le pc s'est éteint suite à l'éxécution de OTMoveIt3 et ne veut plus redémarrer sauf en mode sans echec
En mode normal, il se passe quoi ?
il démarre presque jusqu'à l'affichage du bureau. mais aucune icône n'apparait, pas de barre des tâches, rien.
- Presse CTRL+ALT+SUPPR pour afficher le gestionnaire des tâches.
- Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide.
Non, il ne réagit pas au ctrl alt suppr
- Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
- Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
- Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
- Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
- Sélectionne Exécuter un examen rapidet.
- Clique sur Rechercher.
- L'analyse démarre.
- A la fin de l'analyse, un message s'affiche :
| Citation : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés. |
- Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
- Ferme tes navigateurs.
- Si des malwares ont été détectés, clique sur Afficher les résultats.
- Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
- MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
Mais je n'arrive pas à me connecter à internet en mode sans echec, donc je ne peux rien télécharger.
là je suis obligé de profiter de la gentillesse des voisins pour vous répondre.
Et en mode sans échec avec prise en charge réseau ?
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1802
Windows 5.1.2600 Service Pack 2
25/02/2009 22:50:53
mbam-log-2009-02-25 (22-50-53).txt
Type de recherche: Examen rapide
Eléments examinés: 60267
Temps écoulé: 2 minute(s), 16 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Nous allons essayer une nouvelle manipulation :
- Télécharge SDFix (créé par AndyManchesta) sur ton Bureau.
- Double-clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
- Redémarre ton ordinateur en Mode sans échec.
Pour redémarrer en mode sans échec :
- Redémarre ton PC.
- Au démarrage, tapote sur F8 (F5 sur certains PC) juste après l'affichage du BIOS et juste avant le chargement de Windows.
- Dans le menu d'options avancées, choisis Mode sans échec.
- Choisis ta session.
Déroule la liste des instructions ci-dessous :
- Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double-clique sur RunThis.bat pour lancer le script.
- Appuie sur Y pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
- Appuie sur une touche pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
- Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse.
SDFix: Version 1.240
Run by Administrateur on 25/02/2009 at 23:11 Orkas Ultimate
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-25 23:18:18
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\FileZilla\\FileZilla.exe"="C:\\Program Files\\FileZilla\\FileZilla.exe:*:Enabled:FileZilla"
"D:\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe"="D:\\PlayOnline\\SquareEnix\\PlayOnlineViewer\\pol.exe:*:Enabled
layOnline Viewer"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"D:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="D:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"D:\\Program Files\\Vuze\\Azureus.exe"="D:\\Program Files\\Vuze\\Azureus.exe:*:Enabled:Azureus"
"D:\\Program Files\\eMule\\emule.exe"="D:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype. Take a deep breath "
"C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Remaining Files :
Files with Hidden Attributes :
Tue 24 Feb 2009 33,280 A..H. --- "C:\Program Files\Clock\tcplayer.exe"
Tue 24 Feb 2009 83,968 A..H. --- "C:\Program Files\Clock\tcprop.exe"
Tue 24 Feb 2009 37,888 A..H. --- "C:\Program Files\Clock\tcsntp.exe"
Tue 24 Feb 2009 37,888 A..H. --- "C:\Program Files\Clock\tctimer.exe"
Tue 24 Feb 2009 1,249,280 A..H. --- "C:\Program Files\Windows Sidebar\sidebar_clear.exe"
Wed 8 Nov 2006 40,960 A..H. --- "C:\Program Files\Windows Sidebar\vadvapi32.dll"
Wed 8 Nov 2006 40,960 A..H. --- "C:\Program Files\Windows Sidebar\vadvapi32.dll001"
Wed 8 Nov 2006 137,216 A..H. --- "C:\Program Files\Windows Sidebar\vcomctl32.dll"
Wed 8 Nov 2006 137,216 A..H. --- "C:\Program Files\Windows Sidebar\vcomctl32.dll001"
Wed 8 Nov 2006 8,704 A..H. --- "C:\Program Files\Windows Sidebar\vduser.dll"
Wed 8 Nov 2006 8,704 A..H. --- "C:\Program Files\Windows Sidebar\vduser.dll001"
Wed 8 Nov 2006 3,072 A..H. --- "C:\Program Files\Windows Sidebar\vdwmapi.dll"
Wed 8 Nov 2006 3,072 A..H. --- "C:\Program Files\Windows Sidebar\vdwmapi.dll001"
Wed 8 Nov 2006 9,216 A..H. --- "C:\Program Files\Windows Sidebar\viphlpapi.dll"
Wed 8 Nov 2006 9,216 A..H. --- "C:\Program Files\Windows Sidebar\viphlpapi.dll001"
Wed 8 Nov 2006 51,200 A..H. --- "C:\Program Files\Windows Sidebar\vkernel32.dll"
Wed 8 Nov 2006 51,200 A..H. --- "C:\Program Files\Windows Sidebar\vkernel32.dll001"
Wed 8 Nov 2006 10,752 A..H. --- "C:\Program Files\Windows Sidebar\vmsvcrt.dll"
Wed 8 Nov 2006 10,752 A..H. --- "C:\Program Files\Windows Sidebar\vmsvcrt.dll001"
Wed 8 Nov 2006 2,560 A..H. --- "C:\Program Files\Windows Sidebar\vnetapi32.dll"
Wed 8 Nov 2006 2,560 A..H. --- "C:\Program Files\Windows Sidebar\vnetapi32.dll001"
Wed 8 Nov 2006 77,312 A..H. --- "C:\Program Files\Windows Sidebar\vntdll.dll"
Wed 8 Nov 2006 77,312 A..H. --- "C:\Program Files\Windows Sidebar\vntdll.dll001"
Wed 8 Nov 2006 3,584 A..H. --- "C:\Program Files\Windows Sidebar\vpropsys.dll"
Wed 8 Nov 2006 3,584 A..H. --- "C:\Program Files\Windows Sidebar\vpropsys.dll001"
Wed 8 Nov 2006 21,504 A..H. --- "C:\Program Files\Windows Sidebar\vshell32.dll"
Wed 8 Nov 2006 21,504 A..H. --- "C:\Program Files\Windows Sidebar\vshell32.dll001"
Wed 8 Nov 2006 38,912 A..H. --- "C:\Program Files\Windows Sidebar\vshellext.dll"
Wed 8 Nov 2006 147,968 A..H. --- "C:\Program Files\Windows Sidebar\vslc.dll"
Wed 8 Nov 2006 147,968 A..H. --- "C:\Program Files\Windows Sidebar\vslc.dll001"
Wed 8 Nov 2006 35,328 A..H. --- "C:\Program Files\Windows Sidebar\vuser32.dll"
Wed 8 Nov 2006 35,328 A..H. --- "C:\Program Files\Windows Sidebar\vuser32.dll001"
Wed 8 Nov 2006 6,144 A..H. --- "C:\Program Files\Windows Sidebar\vuxtheme.dll"
Wed 8 Nov 2006 6,144 A..H. --- "C:\Program Files\Windows Sidebar\vuxtheme.dll001"
Wed 8 Nov 2006 3,072 A..H. --- "C:\Program Files\Windows Sidebar\vwlanapi.dll"
Wed 8 Nov 2006 3,072 A..H. --- "C:\Program Files\Windows Sidebar\vwlanapi.dll001"
Wed 8 Nov 2006 3,072 A..H. --- "C:\Program Files\Windows Sidebar\vwlanutil.dll"
Wed 8 Nov 2006 3,072 A..H. --- "C:\Program Files\Windows Sidebar\vwlanutil.dll001"
Tue 24 Feb 2009 435,353 A..H. --- "C:\WINDOWS\Drive\SIGN.exe"
Wed 29 Nov 2006 90,624 A..H. --- "C:\_OTMoveIt\MovedFiles\02252009_212422\jqrugftho.exe"
Wed 29 Nov 2006 90,624 A.SHR --- "C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\gfcfrhqhg.exe"
Wed 29 Nov 2006 90,624 A.SHR --- "C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\mgdrwfsvl.exe"
Wed 29 Nov 2006 90,624 A.SHR --- "C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\tdwenvxpq.exe"
Tue 24 Feb 2009 150,528 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\sauvegarde pampam\Projet Master 2\Ecrits\~WRL0001.tmp"
Finished!
Des changements ?
oui, le pc démarre maintenant en mode normal. merci beaucoup.
est-ce synonyme de succès total?
Il faudrait refaire un scan avec UsbFix pour vérifier.
Je reviens d'ici 20 minutes.
- Désinstalle les programmes suivants :
- Java(TM) 6 Update 11
- Java(TM) 6 Update 7
- Mets à jour Java.
- Mets à jour Adobe Reader.
voici le rapport d'usbfix:
-------------- UsbFix V2.414.3 ---------------
* User : Administrateur - ORKAS
* Outils mis a jours le 18/01/2009 par Chiquitine29 et Chimay8
* Recherche effectuée à 23:50:09 le 25/02/2009
* Windows Xp - Internet Explorer 7.0.5730.11
--------------- [ Processus actifs ] ----------------
--------------- [ Informations lecteurs ] ----------------
C: - Lecteur fixe D: - Lecteur fixe F: - Lecteur fixe G: - Lecteur amovible H: - Lecteur amovible
+- Contenu de l'autorun : C:\autorun.inf
+- Contenu de l'autorun : D:\autorun.inf
+- Contenu de l'autorun : F:\autorun.inf
+- Contenu de l'autorun : G:\autorun.inf
+- Contenu de l'autorun : H:\autorun.inf
--------------- [ Lecteur C ] ----------------
C: - Lecteur fixe
+- Listing des fichiers présents :
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38 Orkas Ultimate][-rahs----] C:\NTDETECT.COM
[24/02/2009 23:24 Orkas Ultimate][---hs----] C:\boot.ini
[25/02/2009 21:09 Orkas Ultimate][d--h-----] C:\autorun.inf
[25/02/2009 23:50 Orkas Ultimate][--a------] C:\UsbFix.txt
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\CONFIG.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\IO.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\MSDOS.SYS
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\pagefile.sys
--------------- [ Lecteur D ] ----------------
D: - Lecteur fixe
+- Listing des fichiers présents :
[25/02/2009 21:09 Orkas Ultimate][d--h-----] D:\autorun.inf
--------------- [ Lecteur F ] ----------------
F: - Lecteur fixe
+- Listing des fichiers présents :
[25/02/2009 21:09 Orkas Ultimate][d--h-----] F:\autorun.inf
--------------- [ Lecteur G ] ----------------
G: - Lecteur amovible
+- Listing des fichiers présents :
[25/02/2009 21:09 Orkas Ultimate][d--h-----] G:\autorun.inf
--------------- [ Lecteur H ] ----------------
H: - Lecteur amovible
+- Listing des fichiers présents :
[10/05/2008 11:29 Orkas Ultimate][--a------] H:\_DS_MENU.INI
[25/02/2009 21:09 Orkas Ultimate][d--h-----] H:\autorun.inf
[24/02/2009 20:11 Orkas Ultimate][--a------] H:\_DS_MENU.SYS
--------------- [ Registre / Startup ] ----------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://windows-unattended.fr"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
3D=C:\program Files\Topdesk\topdesk.exe
Horlorge=C:\program Files\Clock\Clock.exe
Sidebar=C:\program Files\Windows Sidebar\sidebar.exe
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer=D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
RTHDCPL=RTHDCPL.EXE
Alcmtr=ALCMTR.EXE
NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
tsnpstd3=C:\WINDOWS\tsnpstd3.exe
snpstd3=C:\WINDOWS\vsnpstd3.exe
MDM Rock 4=C:\WINDOWS\system32\havlopnde.exe
SunJavaUpdateSched="D:\Program Files\Java\jre6\bin\jusched.exe"
Adobe Reader Speed Launcher="D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=
--------------- [ Registre / Mountpoint2 ] ----------------
-> Recherche négative.
--------------- [ Nettoyage des disques ] ----------------
Echec de la supression !! - [25/02/2009 23:50 Orkas Ultimate] C:\autorun.inf
Supprimé ! - [25/02/2009 23:50 Orkas Ultimate][d--------] C:\autorun.inf
Echec de la supression !! - [25/02/2009 23:50 Orkas Ultimate] D:\autorun.inf
Supprimé ! - [25/02/2009 23:50 Orkas Ultimate][d--------] D:\autorun.inf
Echec de la supression !! - [25/02/2009 21:09 Orkas Ultimate] F:\autorun.inf
Supprimé ! - [25/02/2009 21:09 Orkas Ultimate][d--------] F:\autorun.inf
Echec de la supression !! - [25/02/2009 21:09 Orkas Ultimate] G:\autorun.inf
Supprimé ! - [25/02/2009 21:09 Orkas Ultimate][d--------] G:\autorun.inf
Echec de la supression !! - [25/02/2009 21:09 Orkas Ultimate] H:\autorun.inf
Supprimé ! - [25/02/2009 21:09 Orkas Ultimate][d--------] H:\autorun.inf
--------------- [ Resumé ] ----------------
-> /!\ Le resultat doit etre [http://www.virustotal.com/fr/ interprété] par un spécialiste /!\
[13/04/2007 21:09 Orkas Ultimate][--a------] C:\AUTOEXEC.BAT
[03/08/2004 22:38 Orkas Ultimate][-rahs----] C:\NTDETECT.COM
[24/02/2009 23:24 Orkas Ultimate][---hs----] C:\boot.ini
[10/05/2008 11:29 Orkas Ultimate][--a------] H:\_DS_MENU.INI
--------------- [ Vaccination ] ----------------
C:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
D:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
F:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
G:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
H:\autorun.inf -> Dossier autorun.inf crée par UsbFix !
--------------- ! Fin du rapport ! ----------------
Bien, désinstalle UsbFix.
- Installe Antivir et mets-le à jour.
- Double-clique sur l'icône d'Antivir (Parapluie) dans la barre des tâches.
- Dans Antivir, choisis Outils puis Configuration.
- Coche Mode Expert et coche Rech. Rootkit au dém. de la recherche à droite dans Autres réglages.
- Fais un scan complet et poste le rapport.
UsbFix ne veut pas se désinstaller.
dans ajouter/supprimer des programmes, j'ai une fenêtre popup avec un "!" dans une bulle à acquitter et rien se se passe
On verra ça après à ce moment-là.
autre pb, antivir n'arrive pas à s'installer.
j'ai le pop up suivant:
La somme CRC de
C:\DOCUMEN~1\ADMINI~1\LOCALS~1\Temp\RarSFX0\basic\setup.exe
été modifié ! Cela pourrait avoir été provoqué par un virus !
Est-ce que je peux vous proposer de continuer cette discussion demain svp? Je commence à fatiguer et j'ai bien peur que ce n'est pas bientôt terminé^^
Dans tous les cas, je vous remercie déjà pour votre patience et pour le temps que vous m'avez accordé ce soir!
D.
Dans ce cas-là, je te propose cet antivirus :
http://www.commentcamarche.net/tel [...] ee-edition
Bonne nuit
Bonjour, me revoilà!
Verdict, antivir s'est installé mais il ne démarre pas. il est impossible à désinstaller.
Quant à AVG, il ne s'installe pas.
Je ne peux pas non plus désinstaller usbfix.
le comportement est le même en mode sans echec.
Les version modifiées comme Orkas sont boguées, ça pourrait expliquer ce qui t'arrive.
- Repère le dossier C:\_OTMoveIt.
- Mets-le dans une archive (avec WinRar par exemple).
- Upload l'archive sur MediaFire : Lien
- Donne-moi le lien de l'upload.
Modération : suppression du lien par précaution
Message édité par OmaR le 27-02-2009 à 02:50:47
Oula, certains fichiers infectés ont été détectés comme du Virut par mon antivrus.
C'est une infection très dure voire impossible à retirer.
Fais un scan avec AVPTool comme expliqué ici :
http://www.commentcamarche.net/faq [...] de-avptool
voici le rapport d'AVPTool :
Scan
----
Scanned: 803767
Detected: 240
Untreated: 2
Start time: 26/02/2009 19:49 Orkas Ultimate
Duration: 03:12:46
Finish time: 26/02/2009 23:02 Orkas Ultimate
Detected
--------
Status Object
------ ------
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.n File: C:\WINDOWS\Explorer.EXE
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\ctfmon.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\system32\rundll32.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\rthdcpl.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\tsnpstd3.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\avira\antivir personaledition classic\avgnt.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\topdesk\topdesk.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\clock\clock.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\windows sidebar\sidebar.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\system32\alg.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\avira\antivir personaledition classic\sched.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\avira\antivir personaledition classic\avguard.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\atkkbservice.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\fichiers communs\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\system32\nvsvc32.exe
disinfected: virus Virus.Win32.Virut.n File: c:\windows\system32\spoolsv.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\windows media player\wmpnetwk.exe
disinfected: virus Virus.Win32.Virut.n File: c:\program files\malwarebytes' anti-malware\mbam.exe
disinfected: virus Virus.Win32.Virut.n File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\startup.exe
will be disinfected when the computer is restarted: virus Virus.Win32.Virut.n File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\is-v3gg1.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\gfcfrhqhg.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\havlopnde.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\mgdrwfsvl.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\tdwenvxpq.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_212422\jqrugftho.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_compiler.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_regbrowsers.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_regsql.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\CasPol.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\dfsvc.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DotNetInstaller.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DvsParse.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DvsParse.vshost.exe.bac_a03624//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\English-1.25.rar.bac_a03624//CryptFF.b/ryUVC11.com
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\fpremadm.exe.bac_a03624//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03432//CryptFF.b/c84E5Vu.com
disinfected: virus Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03436//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03624//CryptFF.b/WVsHq5q.com
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\IEExec.exe.bac_a03624//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\images_brand.zip.bac_a01248//CryptFF.b/V6p1b2E.gif .scr
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\InstallUtil.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\jsc.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\launcher_gui.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\lights.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\MSBuild.exe.bac_a03624//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\npds.zip.bac_a01248//CryptFF.b/xBGP786.gif .scr
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\nvudisp.exe.bac_a03624//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\r4sdhc1.21.rar.bac_a03624//CryptFF.b/xL115n5.com
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\RegAsm.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\regedt32.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\RegSvcs.exe.bac_a03624//CryptFF.b
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\SpiderSolitaire.exe.bac_a03624//CryptFF.b
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\Bureau\English-1.25.rar/ryUVC11.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\Bureau\English.1.52_RP.rar/TYfPIg8.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\Bureau\French-1.25.rar/WVsHq5q.com
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\Bureau\OTMoveIt3.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Documents and Settings\Administrateur\Bureau\r4sdhc1.21.rar/xL115n5.com
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\minst.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\drivers\drvins32.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avconfig.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\fact.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\licmgr.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\preupd.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setup.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\update.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AboutBox.zip/g67V8jB.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AssemblyInfo.zip/pg03nH6.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AssemblyInfoInternal.zip/yC0xNG2.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\Form.zip/cQs7g4w.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\MDIParent.zip/L24iQkR.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\UserControl.zip/HR4vYUR.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\Visualizer.zip/NotcNg5.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\AppConfigurationInternal.zip/op620SW.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\AssemblyInfoInternal.zip/DjMc17X.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\Dialog.zip/qGNnRXJ.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\Explorer.zip/hpHfwWJ.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\Form.zip/x5I75X7.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\LoginForm.zip/HtCXcG3.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\MDIParent.zip/Wj0UOq7.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\SplashScreen.zip/tyBer5S.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1036\UserControl.zip/tX8o02m.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\images.zip/yBjGTYN.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\images_classic.zip/ge201re.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\images_crystal.zip/dv2e08G.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\images_hicontrast.zip/OF8IOhj.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\images_industrial.zip/e4VHDEn.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\images_tango.zip/C7b2P6R.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\glas-blue.zip/f8x40SL.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\glas-green.zip/S64425l.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\glas-red.zip/M8WxWcE.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\round-gorilla.zip/rH4oLSf.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\round-white.zip/l2WLD0x.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\simple.zip/cL5I3CS.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\square-blue.zip/ijiFeMO.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\square-gray.zip/cP601C3.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\square-green.zip/t76bT28.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\square-red.zip/j8vx7T4.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\OpenOffice.org 3\Basis\share\config\wizard\web\buttons\square-yellow.zip/qODuef8.gif .scr
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\OrangeHSS\Uninstall\Mobile_CustoUpdate\shell.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\Alcmtr.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\AlcWzrd.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\ChCfg.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\CPLUtl64.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\MicCal.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\RTHDCPL.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\RTLCPL.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\RtlUpd.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\RtlUpd64.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\SkyTel.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Realtek\InstallShield\SoundMan.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\UsbFix\Uninstal.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\UsbFix\Tools\Kill.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\UsbFix\Tools\nircmd.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\UsbFix\Tools\Proc.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\UsbFix\Tools\swreg.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Connect 2\wmccds.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Connect 2\WMCCFG.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\Program Files\Windows Media Player\npdrmv2.zip/r1ySUr2.gif .scr
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Player\wmdbexport.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Player\wmlaunch.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Player\wmpenc.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Player\wmpnscfg.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Player\wmpshare.exe
disinfected: virus Virus.Win32.Virut.n File: C:\Program Files\Windows Media Player\wmsetsdk.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\catchme.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\Cghtme.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\cliptext.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\download.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\ERUNT.EXE
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\FixPath.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\grep.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\isadmin.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\LS.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\MD5File.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\moveex.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\Process.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\procs.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\psservice.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\RestartIt!.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\sc.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\sed.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\SF.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\shutdown.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\Swreg.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\swsc.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\UnRAR.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\unzip.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\vfind.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\WINMSG.EXE
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\zip.exe
disinfected: virus Virus.Win32.Virut.n File: C:\SDFix\apps\Replace\regedit.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\AU_Temp\AU_Down\engine\engv87_nt386.zip/ds6mHUB.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\AU_Temp\AU_Down\pattern\vsapi863.zip/tHe0Dco.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\AU_Temp\AU_Down\product\auhccup1.zip/FlexkSs.gif .scr
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\Installer\{6860B340-530D-46B3-91F8-1AE1F70F7C33}\soffice.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\java\Packages\137TJPZ1.ZIP/iiiH8Pp.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\java\Packages\4N3PZ9J9.ZIP/q7T0Ryi.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\java\Packages\JTB7P753.ZIP/IrnKqwx.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\java\Packages\RLBRJPRL.ZIP/H315E02.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\java\Packages\UO77HFJB.ZIP/uBn6Xq3.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\WINDOWS\java\Packages\YO9B57LV.ZIP/o33e.gif .scr
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\ChCfg.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\drmupgds.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\HdAShCut.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\nvuide.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\uwdf.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\wdfmgr.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\wpdshextautoplay.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\wuauclt.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\WudfHost.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\dllcache\author.exe
disinfected: virus Virus.Win32.Virut.n File: C:\WINDOWS\system32\dllcache\shtml.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\gfcfrhqhg.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\havlopnde.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\mgdrwfsvl.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\tdwenvxpq.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: C:\_OTMoveIt\MovedFiles\02252009_212422\jqrugftho.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Logiciels\DvsParse-1.7.2.zip/luh46Ht.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Logiciels\time-adjuster_time_adjuster_3.1_francais_11087.zip/Q364430.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Logiciels\Windower-3.23.zip/YP3hKQ6.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Logiciels\Windower-3.26.zip/t4p6y0l.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Logiciels\Windower-3.3.zip/qQ6gw8Y.gif .scr
disinfected: virus Virus.Win32.Virut.n File: D:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe
deleted: adware not-a-virus:AdWare.Win32.Agent.fub File: D:\Program Files\eMule\Uninstall.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268a.zip/fHVK4l1.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268b.zip/l52yNBx.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268c.zip/s0kMOmi.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268d.zip/B5Fqh7R.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268e.zip/j5UJb38.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268f.zip/p74xixg.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268g.zip/w2i433P.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268h.zip/g2Xt686.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268i.zip/L258Di2.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268j.zip/S7qpt0s.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268k.zip/B1L3uGd.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\eMule\Incoming\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73)\f4m1268l.zip/IH6o6pu.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\K-Lite Codec Pack\tools\XviD_Quant_Matrices.zip/GJ_Ndf4.gif .scr
disinfected: virus Virus.Win32.Virut.n File: D:\Program Files\Spybot - Search & Destroy\SDFiles.exe
disinfected: virus Virus.Win32.Virut.n File: D:\Program Files\Spybot - Search & Destroy\SDShred.exe
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\Program Files\Vuze\jre\lib\deploy\ffjcext.zip/jiy665E.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\travail\Galileo OS SIS ICD 23rd May 2006.zip/Xmjku81.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: D:\travail\Systèmes de navigation et de guidage\Doc M DAURES\geodico\GEODICO_Ed1.zip/HpT6NRL.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\[PC Games] JEWEL QUEST + serial.rar/g4D4Rb4.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\Luxor 2 Jewel Quest Magic Ball Zuma deluxe 4---Game.rar/IK2fBC2.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\Jewel.Quest.III.v1.054.Cracked-F4CG (Razor73).[sharethefiles.com].zip/jrnSQ6l.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 07 - Episode 031 à 035 - Vostfr - By Berserk.zip/WUS665J.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 01 - Episode 001 à 005 - Vostfr - By Berserk.zip/lmss30p.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 02 - Episode 006 à 010 - Vostfr - By Berserk.zip/mm6uHC1.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 03 - Episode 011 à 015 - Vostfr - By Berserk.zip/ptELoFn.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 04 - Episode 016 à 020 - Vostfr - By Berserk.zip/yn4xH2I.gif .scr
detected: virus Virus.Win32.Virut.n File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 05 - Episode 021 à 025 - Vostfr - By Berserk.zip/pH5OkQ4.gif .scr
detected: virus Virus.Win32.Virut.n File: F:\animes\naruto\Naruto Shippuden[Mirage-Team] - Pack 06 - Episode 026 à 030 - Vostfr - By Berserk.zip/b7nbC0d.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\SPAWN\Spawn.English.Subs-VALiOMEDiA.[tvu.org.ru].rar/J65TG3g.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\SPAWN\Spawn_10th_Season2_07to12_3languages.rar/n4Vnu8v.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\animes\SPAWN\Spawn_10th_Season3_13to18_3languages.rar/S1Q187J.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Private Practice\Private_Practice___1x03_In_Which_Addison_Finds_The_Magic__HDTV_CAPH___SubTs_.zip/g4jB8D7.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01.Subs.DVDRip.XviD-TOPAZ.[tvu.org.ru].rar/3io5Pg.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E01.Pilot.DVDRip.XviD-TOPAZ.rar/qm1F5oD.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E02.Identity.DVDRip.XviD-TOPAZ.rar/lvu5QCU.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E03.Fight.Or.Flight.REPACK.DVDRip.XviD-TOPAZ.rar/r485Fsv.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E04.Old.Friends.DVDRip.XviD-TOPAZ.rar/K5Io4o1.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E05.Family.Business.DVDRip.XviD-TOPAZ.rar/nC20j63.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E06.Unpaid.Debts.DVDRip.XviD-TOPAZ.rar/tQl3WRj.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E07.Broken.Rules.DVDRip.XviD-TOPAZ.rar/M743f1k.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E08.Wanted.Man.DVDRip.XviD-TOPAZ.rar/bOOYq5i.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E09.Hard.Bargain.DVDRip.XviD-TOPAZ.rar/l1vT1F0.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E10.False.Flag.DVDRip.XviD-TOPAZ.rar/cxdpin2.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S01E11.E12.Loose.Ends.DVDRip.XviD-TOPAZ.rar/H17HeI3.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S02E01.VO.VF.rar/c7SC408.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S02E02.VO.VF.rar/rMQwu0T.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S02E05.Scatter.Point.PROPER.HDTV.XviD-FQM.VO.VF.rar/f1H18QE.com
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.202.VO.VF.zip/bKD72Rx.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: F:\series\Série Julien\Burn notice\temp\Burn.Notice.S02E03.HDTV.XviD-0TV.VO.VF.zip/q3RDVe4.gif .scr
deleted: Trojan program Backdoor.Win32.Rbot.itx File: G:\klmdvorrw.exe
Events
------
Time Name Status Reason
---- ---- ------ ------
26/02/2009 19:49 Orkas Ultimate File: C:\WINDOWS\Explorer.EXE detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:49 Orkas Ultimate File: C:\WINDOWS\Explorer.EXE not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: C:\WINDOWS\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: C:\WINDOWS\system32\ctfmon.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\system32\rundll32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\system32\rundll32.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: C:\WINDOWS\system32\rundll32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: C:\WINDOWS\system32\rundll32.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\explorer.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\explorer.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: C:\WINDOWS\explorer.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: C:\WINDOWS\explorer.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\rthdcpl.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\rthdcpl.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\tsnpstd3.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\tsnpstd3.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avgnt.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avgnt.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\program files\topdesk\topdesk.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\program files\topdesk\topdesk.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\program files\clock\clock.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\program files\clock\clock.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\program files\windows sidebar\sidebar.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\program files\windows sidebar\sidebar.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\system32\ctfmon.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\system32\alg.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\system32\alg.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\sched.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\sched.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avguard.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avguard.exe not disinfected postponed
26/02/2009 19:50 Orkas Ultimate File: c:\windows\atkkbservice.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:50 Orkas Ultimate File: c:\windows\atkkbservice.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\nvsvc32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\nvsvc32.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\spoolsv.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\spoolsv.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\windows media player\wmpnetwk.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\windows media player\wmpnetwk.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\malwarebytes' anti-malware\mbam.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\malwarebytes' anti-malware\mbam.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\startup.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\startup.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\is-v3gg1.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\is-v3gg1.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\Explorer.EXE detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\Explorer.EXE not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\system32\ctfmon.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\rundll32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\rundll32.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\system32\rundll32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\system32\rundll32.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\explorer.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\explorer.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\explorer.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: C:\WINDOWS\explorer.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\rthdcpl.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\rthdcpl.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\tsnpstd3.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\tsnpstd3.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avgnt.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avgnt.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\topdesk\topdesk.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\topdesk\topdesk.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\clock\clock.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\clock\clock.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\windows sidebar\sidebar.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\windows sidebar\sidebar.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\ctfmon.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\ctfmon.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\alg.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\alg.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\sched.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\sched.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avguard.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\avira\antivir personaledition classic\avguard.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\atkkbservice.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\atkkbservice.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\progra~1\fichie~1\france telecom\shared modules\ftrtsvc\0\ftrtsvc.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\nvsvc32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\nvsvc32.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\spoolsv.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\windows\system32\spoolsv.exe not disinfected postponed
26/02/2009 19:51 Orkas Ultimate File: c:\program files\windows media player\wmpnetwk.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:51 Orkas Ultimate File: c:\program files\windows media player\wmpnetwk.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: c:\program files\malwarebytes' anti-malware\mbam.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: c:\program files\malwarebytes' anti-malware\mbam.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\startup.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\startup.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\is-v3gg1.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: c:\documents and settings\administrateur\bureau\virus removal tool\is-v3gg1\is-v3gg1.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\gfcfrhqhg.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\gfcfrhqhg.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\havlopnde.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\havlopnde.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\mgdrwfsvl.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\mgdrwfsvl.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\tdwenvxpq.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_202607\WINDOWS\system32\tdwenvxpq.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_212422\jqrugftho.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\_OTMoveIt.rar/_OTMoveIt\MovedFiles\02252009_212422\jqrugftho.exe not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_compiler.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_compiler.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_regbrowsers.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_regbrowsers.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_regsql.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\aspnet_regsql.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\CasPol.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:52 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\CasPol.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\dfsvc.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\dfsvc.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DotNetInstaller.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DotNetInstaller.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DvsParse.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DvsParse.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DvsParse.vshost.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\DvsParse.vshost.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\English-1.25.rar.bac_a03624//CryptFF.b/ryUVC11.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\English-1.25.rar.bac_a03624//CryptFF.b/ryUVC11.com not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\fpremadm.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\fpremadm.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03432//CryptFF.b/c84E5Vu.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03432//CryptFF.b/c84E5Vu.com not disinfected postponed
26/02/2009 19:55 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03436//CryptFF.b detected virus 'Virus.Win32.Virut.n' by hash
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03624//CryptFF.b/WVsHq5q.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\French-1.25.rar.bac_a03624//CryptFF.b/WVsHq5q.com not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\IEExec.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\IEExec.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\images_brand.zip.bac_a01248//CryptFF.b/V6p1b2E.gif .scr detected Trojan program 'Backdoor.Win32.Rbot.itx'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\images_brand.zip.bac_a01248//CryptFF.b/V6p1b2E.gif .scr not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\InstallUtil.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\InstallUtil.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\jsc.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\jsc.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\launcher_gui.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\launcher_gui.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\lights.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\lights.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\MSBuild.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\MSBuild.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\npds.zip.bac_a01248//CryptFF.b/xBGP786.gif .scr detected Trojan program 'Backdoor.Win32.Rbot.itx'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\npds.zip.bac_a01248//CryptFF.b/xBGP786.gif .scr not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\nvudisp.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\nvudisp.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\r4sdhc1.21.rar.bac_a03624//CryptFF.b/xL115n5.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\r4sdhc1.21.rar.bac_a03624//CryptFF.b/xL115n5.com not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\RegAsm.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\RegAsm.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\regedt32.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\regedt32.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\RegSvcs.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\RegSvcs.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\SpiderSolitaire.exe.bac_a03624//CryptFF.b detected virus 'Virus.Win32.Virut.n'
26/02/2009 19:56 Orkas Ultimate File: C:\Documents and Settings\Administrateur\.housecall6.6\Quarantine\SpiderSolitaire.exe.bac_a03624//CryptFF.b not disinfected postponed
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\English-1.25.rar/ryUVC11.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\English-1.25.rar/ryUVC11.com not disinfected postponed
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\English.1.52_RP.rar/TYfPIg8.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\English.1.52_RP.rar/TYfPIg8.com not disinfected postponed
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\French-1.25.rar/WVsHq5q.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\French-1.25.rar/WVsHq5q.com not disinfected postponed
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\OTMoveIt3.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\OTMoveIt3.exe not disinfected postponed
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\r4sdhc1.21.rar/xL115n5.com detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:05 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\r4sdhc1.21.rar/xL115n5.com not disinfected postponed
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\is-V3GG1.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\is-V3GG1.exe not disinfected postponed
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\minst.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\minst.exe not disinfected postponed
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\startup.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\startup.exe not disinfected postponed
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\drivers\drvins32.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:06 Orkas Ultimate File: C:\Documents and Settings\Administrateur\Bureau\Virus Removal Tool\is-V3GG1\drivers\drvins32.exe not disinfected postponed
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MailSkinnerrtk.zip/msksetup.log password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MailSkinnerrtk.zip/sbRecovery.ini password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride.zip/sbRecovery.reg password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusOverride.zip/sbRecovery.ini password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip/sbRecovery.reg password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip/sbRecovery.ini password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallOverride.zip/sbRecovery.reg password protected
26/02/2009 20:08 Orkas Ultimate File: C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallOverride.zip/sbRecovery.ini password protected
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avconfig.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avconfig.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\avscan.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\fact.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\fact.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\guardgui.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\licmgr.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\licmgr.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\preupd.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\preupd.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setup.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\setup.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\update.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Avira\AntiVir PersonalEdition Classic\update.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Clock\Clock.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Clock\Clock.exe not disinfected postponed
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:14 Orkas Ultimate File: C:\Program Files\Fichiers communs\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe not disinfected postponed
26/02/2009 20:15 Orkas Ultimate File: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe detected virus 'Virus.Win32.Virut.n'
26/02/2009 20:15 Orkas Ultimate File: C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe not disinfected postponed
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AboutBox.zip/g67V8jB.gif .scr detected Trojan program 'Backdoor.Win32.Rbot.itx'
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AboutBox.zip/g67V8jB.gif .scr not disinfected postponed
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AssemblyInfo.zip/pg03nH6.gif .scr detected Trojan program 'Backdoor.Win32.Rbot.itx'
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AssemblyInfo.zip/pg03nH6.gif .scr not disinfected postponed
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AssemblyInfoInternal.zip/yC0xNG2.gif .scr detected Trojan program 'Backdoor.Win32.Rbot.itx'
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\AssemblyInfoInternal.zip/yC0xNG2.gif .scr not disinfected postponed
26/02/2009 20:17 Orkas Ultimate File: C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1036\Form.zip/cQs7g4w.gif
le programme n'arrivait pas à désinfecter les derniers fichiers par manque de place. Au début, j'ai essayé de faire un peu de place sur C
Ensuite, j'ai supprimé manuellement les fichiers en question (SHIFT + SUPPR), j'espère que j'ai bien fait.
Ton Windows est mort, il est pourri par Virut.
http://www.commentcamarche.net/faq [...] imer-virut
donc formatage? avec le killdisk comme conseillé dans le lien?
et que faire pour les disques durs externes? je suppose que ça ne sert à rien de formater le pc si c'est pour remettre une clé infectée après?
+ j'ai un deuxième pc, sur lequel j'ai utilisé les clés usb infectées. il ne me semble pas infecté mais bon, il l'est peut-être quand même.
La majorité de tes questions ont leurs réponses dans l'astuce que je t'ai donné.
S'il reste un seul fichier contaminé par Virut, il réinfectera les autres.
Pour ton deuxième PC, tu peux toujours passer un coup d'AVPTool.
OK, il n'y a plus qu'à!
je reviendrais si jamais j'ai des doutes sur l'éradication complète de ce Virut :-)
encore merci pour toute cette patience et ce temps que vous m'avez accordé!
D.
Tiens-moi au courant
Bonjour,
Voici le rapport d'AVPTool effectué sur le deuxième PC. Je suis un peu moins confiant qu'avant quant au fait qu'il n'ait pas été infecté ^^
Hmmm il ne passe pas. le rapport fait 1.65Mo. il y a une taille max à ne pas dépasser pour poster un message?
Je vais essayer de le poster en 2 fois
Il y a 1828 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
