david875
asked on
Problem with autorun.inf
Hello,
I have a problem with an autorun.inf in my WD External Hard drive and this affect any USB storage has autorun.inf I also have a folder called RECYCLER containing a file named jwgkvsq.vmx also reported as a malware, please help
Avira reported the autorun.inf as :
Guard : Malware fund
A virus or unwanted program 'WORM/Kido.IX' was found in file I:\files\autorun.inf.block ed'
Access to this file was denied
I can't delete it, using the keyboard 'Suppr' or with MS DOS and even on Safe Mode on Windows, please help me
I have a problem with an autorun.inf in my WD External Hard drive and this affect any USB storage has autorun.inf I also have a folder called RECYCLER containing a file named jwgkvsq.vmx also reported as a malware, please help
Avira reported the autorun.inf as :
Guard : Malware fund
A virus or unwanted program 'WORM/Kido.IX' was found in file I:\files\autorun.inf.block
Access to this file was denied
I can't delete it, using the keyboard 'Suppr' or with MS DOS and even on Safe Mode on Windows, please help me
Hello David,
I have provided the solution to the autotun.inf problem before. You could try those solution here in link below:
https://www.experts-exchange.com/questions/25472927/delete-autorun-inf-virus-from-windows-2003-Users-Shared-Folders-myusername.html
or
You could also try these tools to remove the autorun.inf from the flash drives and HDD. I would recommend removing the virus using these and then running Autorun Eater to stop the further infection of this virus. Hope it would help you and others too.
Tools you need are:
InfBlocker 2.0 and InfBlocker PLUS 2.0
Download Link: http://www.brothersoft.com/infblocker-294427.html
InfBlocker 2.0:
"InfBlocker is a small antivirus."BSEditor:
InfBlocker can help you delete Infection of AutoRun.inf MS32DLL.dll.vbs Worm
Download Link: http://www.brothersoft.com/infblocker-plus-294977.html
InfBlocker PLUS 2.0:
"InfBlocker PLUS: Pendrive HDD antivirusHDD e System drive protection."
+---$RECYCLE.BIN.exe
+---AdobeR.exe
+---algsrvs.exe
+---antivirus.bat
+---arona.exe
+---AutoRun.bat
+---autorun.com
+---Autorun.inf
+---autorun.inf.exe
+---autorun.ini
+---autorun.rar
+---autorun.reg
+---autorun.vbs
+---AUTORUN_.INF
+---boot.exe
+---comment.htt
+---Copy.exe
+---desktop.vbs
+---desktop2.exe
+---dialer.exe
+---Folder.exe
+---Folders.exe
+---found.000
+---FUN.XLS.EXE
+---handydriver.exe
+---Host.exe
+---hvNrtID.exe
+---knight.exe
+---logon.bat
+---MS32DLL.dll.vbs
+---msfun80.exe
+---msime82.exe
+---msvcr71.dll
+---New Folder.exe
+---Ravmon.exe
+---ravmon.log
+---Recycler.exe
+---run.bat
+---setup.dll.vb
+---slp2.exe
+---startup.vbs
+---Svchost.exe
+---svchost32.exe
+---Svchosts.exe
+---sys.exe
+---sys32_.exe
+---temp.ftp
+---Thumbs.com
+---Thumbs.exe
+---video.exe
+---windows.bat
+---windows.cmd
+---windows.com
+---winfile.exe
+---WinLog.exe
+---_autorun.inf
====================Altern atively=== ========== ========
Autorun.inf virus actually spread mainly from portable media such as USB drives, Memory Cards etc. If you are a victim of this virus then you may experience following problems:
[1] You can’t enable “Show Hidden Files and Folders”
[2] Task Manager will be disabled and you can’t open it.
[3] Autorun.inf can enable more viruses when portable devices are used.
[4] Access to Registry Editor will be locked.
[5] It can open the drives in new window each time when you try to open them.
When an infected device is infected with a malware and an ‘autorun.inf’ file is dropped, the shell menu is normally modified to execute the malware whenever the unsuspecting user double-clicks the infected drive. Actually Autorun.inf changes few entries on the registry of your system, and you can’t restore those manually as access to the Registry Editor already disabled by this virus.
So, it’s a real problem if you are affected with this virus. Normally, popular antivirus software often fails to detect and remove Autorun.inf completely. To get rid of this, you can try a nice FREE utility called AutorunEater. It’s a very fast and easy to use tool and helps you to remove Autorun.inf and restore all registry changes.
Autorun Eater will remove any suspicious ‘autorun.inf’ files even before the user attempts to access the drive.
(http://www.softpedia.com/progDownload/Autorun-Eater-Download-85585.html) - Autorun Eater 2.4
One Important Point I would like to tell you that some antivirus and antispyware programs may show ‘false positive‘ behaviour which means they can flag Autorun Eater as being infected/malware, although the application is perfectly safe and does not pose a threat to your system. If you already have other antivirus or anti-malware installed then they can detect AutorunEater as virus, just ignore this. Also you can disable and exit all antivirus program installed on your system before running AutorunEater.
Read more: http://inforids.com/remove-autoruninf-virus-easily/#ixzz0j1ETqdVV
Thanks and Regards,
Sudeep
I have provided the solution to the autotun.inf problem before. You could try those solution here in link below:
https://www.experts-exchange.com/questions/25472927/delete-autorun-inf-virus-from-windows-2003-Users-Shared-Folders-myusername.html
or
You could also try these tools to remove the autorun.inf from the flash drives and HDD. I would recommend removing the virus using these and then running Autorun Eater to stop the further infection of this virus. Hope it would help you and others too.
Tools you need are:
InfBlocker 2.0 and InfBlocker PLUS 2.0
Download Link: http://www.brothersoft.com/infblocker-294427.html
InfBlocker 2.0:
"InfBlocker is a small antivirus."BSEditor:
InfBlocker can help you delete Infection of AutoRun.inf MS32DLL.dll.vbs Worm
Download Link: http://www.brothersoft.com/infblocker-plus-294977.html
InfBlocker PLUS 2.0:
"InfBlocker PLUS: Pendrive HDD antivirusHDD e System drive protection."
+---$RECYCLE.BIN.exe
+---AdobeR.exe
+---algsrvs.exe
+---antivirus.bat
+---arona.exe
+---AutoRun.bat
+---autorun.com
+---Autorun.inf
+---autorun.inf.exe
+---autorun.ini
+---autorun.rar
+---autorun.reg
+---autorun.vbs
+---AUTORUN_.INF
+---boot.exe
+---comment.htt
+---Copy.exe
+---desktop.vbs
+---desktop2.exe
+---dialer.exe
+---Folder.exe
+---Folders.exe
+---found.000
+---FUN.XLS.EXE
+---handydriver.exe
+---Host.exe
+---hvNrtID.exe
+---knight.exe
+---logon.bat
+---MS32DLL.dll.vbs
+---msfun80.exe
+---msime82.exe
+---msvcr71.dll
+---New Folder.exe
+---Ravmon.exe
+---ravmon.log
+---Recycler.exe
+---run.bat
+---setup.dll.vb
+---slp2.exe
+---startup.vbs
+---Svchost.exe
+---svchost32.exe
+---Svchosts.exe
+---sys.exe
+---sys32_.exe
+---temp.ftp
+---Thumbs.com
+---Thumbs.exe
+---video.exe
+---windows.bat
+---windows.cmd
+---windows.com
+---winfile.exe
+---WinLog.exe
+---_autorun.inf
====================Altern
Autorun.inf virus actually spread mainly from portable media such as USB drives, Memory Cards etc. If you are a victim of this virus then you may experience following problems:
[1] You can’t enable “Show Hidden Files and Folders”
[2] Task Manager will be disabled and you can’t open it.
[3] Autorun.inf can enable more viruses when portable devices are used.
[4] Access to Registry Editor will be locked.
[5] It can open the drives in new window each time when you try to open them.
When an infected device is infected with a malware and an ‘autorun.inf’ file is dropped, the shell menu is normally modified to execute the malware whenever the unsuspecting user double-clicks the infected drive. Actually Autorun.inf changes few entries on the registry of your system, and you can’t restore those manually as access to the Registry Editor already disabled by this virus.
So, it’s a real problem if you are affected with this virus. Normally, popular antivirus software often fails to detect and remove Autorun.inf completely. To get rid of this, you can try a nice FREE utility called AutorunEater. It’s a very fast and easy to use tool and helps you to remove Autorun.inf and restore all registry changes.
Autorun Eater will remove any suspicious ‘autorun.inf’ files even before the user attempts to access the drive.
(http://www.softpedia.com/progDownload/Autorun-Eater-Download-85585.html) - Autorun Eater 2.4
One Important Point I would like to tell you that some antivirus and antispyware programs may show ‘false positive‘ behaviour which means they can flag Autorun Eater as being infected/malware, although the application is perfectly safe and does not pose a threat to your system. If you already have other antivirus or anti-malware installed then they can detect AutorunEater as virus, just ignore this. Also you can disable and exit all antivirus program installed on your system before running AutorunEater.
Read more: http://inforids.com/remove-autoruninf-virus-easily/#ixzz0j1ETqdVV
Thanks and Regards,
Sudeep
Download Flash_Disinfector.exe by sUBs and save it to your desktop.
http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
Also ComboFix and show us the log.
ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe
Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
Also ComboFix and show us the log.
ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
ASKER
when i downloaded Flash_Disinfector.exe and installed i tried to click on the autorun.inf directory in my External hard drive and suddenly the computer crashed and reboot automatically, i don't understand why when i did it again it didn't happen, but i still have problem with the autorun.inf
Flash)Disinfector supposed to delete the harmful autorun.inf, and then create a harmless autorun.inf folder also, to stop spreading autorun.inf infection.
Try ComboFix, and if it's not removed in its first run we can use its script function to remove it.
Try ComboFix, and if it's not removed in its first run we can use its script function to remove it.
ASKER
ComboFix didn't help, even with MS Dos commands, i attached 2 screenshot to show you what i was trying to do
screenshot-auotorun.JPG
Screenshot-MSDOS.JPG
screenshot-auotorun.JPG
Screenshot-MSDOS.JPG
Did you tried InfBlocker and Autorun eater as suggested by me above?
Sudeep
Sudeep
ASKER
Well, Autorun did nothing and i just couldn't figure out how to use it, it gives you to scan volume A which never exists and Scan volume B to scan which doesn't exists i can't use it at all, any idea? and infBlocker it just create folders, so how to remove the virus shown in the screenshot?
Can you please post the ComboFix log? using its script function can remove any files that exists in the system.
ASKER
ComboFix 10-07-01.02 - David 02/07/2010 19:55:11.2.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18. 1526.1056 [GMT 1:00]
Lancé depuis: c:\documents and settings\David\Mes documents\Téléchargements\ ComboFix.e xe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-F DD3350758C 7}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F 8FCFF809F8 B}
* Un antivirus résident est actif
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((( (((((((((( Autres suppressions )))))))))))))))))))))))))) )))))))))) )))))))))) ))
.
c:\documents and settings\David\Application Data\.#
c:\documents and settings\David\Application Data\QUAD Backups
c:\documents and settings\David\Application Data\QUAD Backups\01.11.2010,21-55-4 5\Automati c.reg
c:\documents and settings\David\Application Data\QUAD Backups\01.14.2010,23-47-1 3\Automati c.reg
c:\documents and settings\David\Application Data\QUAD Backups\02.26.2010,23-02-5 6\Automati c.reg
c:\documents and settings\David\Application Data\QUAD Backups\02.26.2010,23-19-3 0\Automati c.reg
c:\program files\QUAD Utilities
c:\program files\QUAD Utilities\QUAD Registry Cleaner\program.log
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner website.url
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner.exe
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner.exe.BAK
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Scheduler.exe
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Styles\Vista.cjsty les
c:\program files\QUAD Utilities\QUAD Registry Cleaner\uninst.exe
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Vista Scheduler.dll
C:\Thumbs.db
c:\windows\Downloaded Program Files\f3initialsetup1.0.1. 3.inf
c:\windows\jestertb.dll
I:\install.exe
.
(((((((((((((((((((((((((( ((( Fichiers créés du 2010-06-02 au 2010-07-02 )))))))))))))))))))))))))) ))))))))))
.
2010-07-01 23:20 . 2010-07-01 23:20 -------- d-----w- C:\autorunhelp
2010-07-01 23:14 . 2010-07-01 23:14 -------- d-----w- c:\program files\Autorun Eater
2010-07-01 21:14 . 2010-07-01 21:14 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb18.tmp.e xe
2010-06-28 23:25 . 2010-06-28 23:25 -------- d-----w- c:\program files\Oracle
2010-06-15 21:29 . 2010-06-15 21:31 -------- d-----w- c:\documents and settings\David\Application Data\VMware
2010-06-15 20:44 . 2010-06-15 21:38 664 ----a-w- c:\windows\system32\d3d9ca ps.dat
2010-06-15 18:37 . 2010-06-15 21:38 -------- d-----w- c:\documents and settings\LocalService\Appl ication Data\VMware
2010-06-15 18:28 . 2010-06-15 22:04 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
2010-06-12 00:31 . 2010-05-06 10:33 743424 -c----w- c:\windows\system32\dllcac he\iedvtoo l.dll
2010-06-08 21:02 . 2010-06-08 21:02 -------- d-----w- c:\windows\system32\ivtMob Cache
2010-06-08 12:30 . 2010-06-08 12:30 111312 ----a-w- c:\windows\system32\driver s\VBoxNetF lt.sys
2010-06-08 12:30 . 2010-06-08 12:30 133648 ----a-w- c:\windows\system32\VBoxNe tFltNotify .dll
2010-06-06 01:02 . 2010-06-06 01:02 61440 ----a-w- c:\documents and settings\David\Application Data\GRETECH\GomPlayer\GrL auncherTem pSetup.exe
2010-06-06 01:02 . 2007-03-22 10:46 126976 ----a-w- c:\documents and settings\David\Application Data\GRETECH\GomPlayer\GrL auncher.ex e
.
(((((((((((((((((((((((((( (((((((( Compte-rendu de Find3M )))))))))))))))))))))))))) )))))))))) )))))))))) ))
.
2010-07-02 18:54 . 2001-08-24 12:00 81824 ----a-w- c:\windows\system32\perfc0 0C.dat
2010-07-02 18:54 . 2001-08-24 12:00 503894 ----a-w- c:\windows\system32\perfh0 0C.dat
2010-07-02 18:50 . 2010-06-02 18:24 1345 --sha-w- c:\windows\system32\mmf.sy s
2010-07-02 18:48 . 2010-07-02 18:49 112640 ----a-w- c:\windows\Internet Logs\xDBB7.tmp
2010-07-02 18:35 . 2010-01-02 22:28 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-01 23:14 . 2010-01-07 23:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Autorun Eater
2010-07-01 20:19 . 2009-10-15 12:20 -------- d-----w- c:\program files\Messenger Plus! Live
2010-06-30 23:41 . 2010-06-30 23:43 22016 ----a-w- c:\windows\Internet Logs\xDBB6.tmp
2010-06-30 23:36 . 2010-01-03 22:09 -------- d-----w- c:\program files\DAEMON Tools
2010-06-30 23:33 . 2010-06-30 23:34 25088 ----a-w- c:\windows\Internet Logs\xDBB5.tmp
2010-06-30 23:32 . 2009-10-20 21:42 639224 ----a-w- c:\windows\system32\driver s\sptd.sys
2010-06-30 23:17 . 2010-06-30 23:18 35328 ----a-w- c:\windows\Internet Logs\xDBB4.tmp
2010-06-30 15:37 . 2010-06-30 15:38 24064 ----a-w- c:\windows\Internet Logs\xDBB3.tmp
2010-06-30 02:46 . 2010-06-30 15:10 28672 ----a-w- c:\windows\Internet Logs\xDBB2.tmp
2010-06-30 02:20 . 2010-01-01 14:56 -------- d-----w- c:\documents and settings\David\Application Data\vlc
2010-06-29 17:04 . 2010-06-29 20:37 44544 ----a-w- c:\windows\Internet Logs\xDBB1.tmp
2010-06-28 02:18 . 2010-06-28 02:18 120311 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2010_06_28_ 02_54_41_s mall.dmp.z ip
2010-06-27 20:55 . 2010-06-27 23:00 28672 ----a-w- c:\windows\Internet Logs\xDBB0.tmp
2010-06-27 19:53 . 2010-06-27 19:54 38912 ----a-w- c:\windows\Internet Logs\xDBAF.tmp
2010-06-26 02:30 . 2010-06-26 14:28 26112 ----a-w- c:\windows\Internet Logs\xDBAE.tmp
2010-06-25 02:02 . 2010-06-25 22:38 27136 ----a-w- c:\windows\Internet Logs\xDBAD.tmp
2010-06-25 01:26 . 2010-02-16 18:04 -------- d-----w- c:\documents and settings\David\Application Data\Nokia
2010-06-24 20:26 . 2010-06-25 01:09 29696 ----a-w- c:\windows\Internet Logs\xDBAC.tmp
2010-06-24 00:52 . 2010-06-24 17:58 32256 ----a-w- c:\windows\Internet Logs\xDBAB.tmp
2010-06-23 19:16 . 2010-06-23 21:46 28160 ----a-w- c:\windows\Internet Logs\xDBAA.tmp
2010-06-23 15:54 . 2010-06-23 15:55 44032 ----a-w- c:\windows\Internet Logs\xDBA9.tmp
2010-06-23 14:27 . 2009-10-26 22:05 -------- d-----w- c:\documents and settings\David\Application Data\Skinux
2010-06-22 02:10 . 2010-06-22 21:32 25600 ----a-w- c:\windows\Internet Logs\xDBA8.tmp
2010-06-21 23:00 . 2010-06-22 00:32 43008 ----a-w- c:\windows\Internet Logs\xDBA7.tmp
2010-06-20 22:52 . 2010-06-20 22:58 37888 ----a-w- c:\windows\Internet Logs\xDBA6.tmp
2010-06-19 18:06 . 2010-06-19 19:22 19456 ----a-w- c:\windows\Internet Logs\xDBA5.tmp
2010-06-19 01:42 . 2010-06-19 17:48 24576 ----a-w- c:\windows\Internet Logs\xDBA4.tmp
2010-06-18 14:28 . 2010-06-18 23:35 30208 ----a-w- c:\windows\Internet Logs\xDBA3.tmp
2010-06-18 00:40 . 2010-06-18 13:06 32256 ----a-w- c:\windows\Internet Logs\xDBA2.tmp
2010-06-16 19:25 . 2009-11-06 13:44 4321611 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-06-16 02:05 . 2010-06-16 19:25 27136 ----a-w- c:\windows\Internet Logs\xDBA1.tmp
2010-06-15 22:07 . 2010-06-15 22:08 43520 ----a-w- c:\windows\Internet Logs\xDBA0.tmp
2010-06-15 20:57 . 2010-06-15 20:58 36352 ----a-w- c:\windows\Internet Logs\xDB9F.tmp
2010-06-15 18:39 . 2010-06-15 18:40 31232 ----a-w- c:\windows\Internet Logs\xDB9E.tmp
2010-06-15 01:55 . 2010-06-15 18:17 62464 ----a-w- c:\windows\Internet Logs\xDB9D.tmp
2010-06-15 00:34 . 2009-10-15 12:20 -------- d-----w- c:\program files\mIRC
2010-06-14 23:39 . 2009-10-26 23:04 -------- d-----w- c:\documents and settings\David\Application Data\Skype
2010-06-14 23:11 . 2009-10-26 23:07 -------- d-----w- c:\documents and settings\David\Application Data\skypePM
2010-06-14 02:17 . 2010-06-14 17:55 47616 ----a-w- c:\windows\Internet Logs\xDB9C.tmp
2010-06-13 17:52 . 2010-06-13 21:52 45056 ----a-w- c:\windows\Internet Logs\xDB9B.tmp
2010-06-13 02:36 . 2010-06-13 14:10 50176 ----a-w- c:\windows\Internet Logs\xDB9A.tmp
2010-06-12 16:56 . 2010-06-12 21:05 27648 ----a-w- c:\windows\Internet Logs\xDB99.tmp
2010-06-12 02:14 . 2010-06-12 13:11 123392 ----a-w- c:\windows\Internet Logs\xDB98.tmp
2010-06-09 20:30 . 2009-11-18 00:35 -------- d-----w- c:\documents and settings\David\Application Data\dvdcss
2010-06-09 02:31 . 2010-06-09 17:47 56320 ----a-w- c:\windows\Internet Logs\xDB97.tmp
2010-06-09 00:17 . 2009-10-15 12:18 -------- d-----w- c:\program files\FTP Commander
2010-06-08 12:30 . 2010-01-06 16:47 142928 ----a-w- c:\windows\system32\driver s\VBoxDrv. sys
2010-06-08 12:30 . 2010-01-06 16:47 31504 ----a-w- c:\windows\system32\driver s\VBoxUSB. sys
2010-06-08 12:30 . 2010-01-06 16:47 41744 ----a-w- c:\windows\system32\driver s\VBoxUSBM on.sys
2010-06-08 12:30 . 2009-12-17 15:02 100496 ----a-w- c:\windows\system32\driver s\VBoxNetA dp.sys
2010-06-08 02:05 . 2010-06-08 20:57 54784 ----a-w- c:\windows\Internet Logs\xDB96.tmp
2010-06-07 20:39 . 2010-06-07 21:12 47616 ----a-w- c:\windows\Internet Logs\xDB95.tmp
2010-06-07 02:19 . 2010-06-07 16:06 44032 ----a-w- c:\windows\Internet Logs\xDB94.tmp
2010-06-07 02:14 . 2009-10-15 09:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-06 15:46 . 2010-06-06 22:56 52736 ----a-w- c:\windows\Internet Logs\xDB93.tmp
2010-06-06 01:05 . 2010-06-06 13:14 51712 ----a-w- c:\windows\Internet Logs\xDB92.tmp
2010-06-05 02:26 . 2010-06-05 23:14 48128 ----a-w- c:\windows\Internet Logs\xDB91.tmp
2010-06-04 00:57 . 2010-06-04 22:50 30720 ----a-w- c:\windows\Internet Logs\xDB90.tmp
2010-06-03 01:57 . 2010-06-03 22:49 81920 ----a-w- c:\windows\Internet Logs\xDB8F.tmp
2010-06-02 18:24 . 2010-06-02 18:24 48640 ----a-w- c:\windows\mmfs.dll
2010-06-02 18:24 . 2010-06-02 18:24 2560 ----a-w- c:\windows\Runservice.exe
2010-06-02 11:25 . 2010-06-02 11:25 -------- d-----w- c:\program files\Apstel
2010-06-02 11:25 . 2010-06-02 11:25 -------- d--h--w- c:\program files\InstallJammer Registry
2010-06-02 01:20 . 2010-06-02 11:22 42496 ----a-w- c:\windows\Internet Logs\xDB8E.tmp
2010-06-01 01:10 . 2010-06-01 21:38 91648 ----a-w- c:\windows\Internet Logs\xDB8D.tmp
2010-05-30 23:14 . 2010-03-15 11:51 -------- d-----w- c:\program files\WinBlackJackBot V3.0
2010-05-30 23:14 . 2010-03-13 22:55 -------- d-----w- c:\program files\Vegas Magic Casino
2010-05-30 01:54 . 2010-01-07 00:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-29 02:35 . 2010-05-29 23:03 80896 ----a-w- c:\windows\Internet Logs\xDB8C.tmp
2010-05-29 00:35 . 2010-05-29 00:35 -------- d-----w- c:\documents and settings\All Users\Application Data\CounterPath
2010-05-27 00:28 . 2010-05-27 21:56 56832 ----a-w- c:\windows\Internet Logs\xDB8B.tmp
2010-05-26 22:22 . 2010-02-02 00:39 -------- d-----w- c:\program files\CounterPath
2010-05-26 22:16 . 2010-05-26 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\CounterPath Corporation
2010-05-26 22:16 . 2010-05-26 22:16 -------- d-----w- c:\documents and settings\David\Application Data\CounterPath Corporation
2010-05-26 20:51 . 2010-05-26 20:51 -------- d-----w- c:\program files\Axon Data
2010-05-26 19:36 . 2010-04-14 21:23 -------- d-----w- c:\documents and settings\David\Application Data\uTorrent
2010-05-26 11:49 . 2010-05-26 17:06 111616 ----a-w- c:\windows\Internet Logs\xDB8A.tmp
2010-05-24 01:58 . 2010-05-24 21:35 40448 ----a-w- c:\windows\Internet Logs\xDB89.tmp
2010-05-23 02:24 . 2010-05-23 20:47 50176 ----a-w- c:\windows\Internet Logs\xDB88.tmp
2010-05-22 04:07 . 2010-05-22 22:51 73216 ----a-w- c:\windows\Internet Logs\xDB86.tmp
2010-05-22 04:07 . 2010-05-22 22:51 4149760 ----a-w- c:\windows\Internet Logs\xDB87.tmp
2010-05-20 01:48 . 2010-05-20 20:46 45568 ----a-w- c:\windows\Internet Logs\xDB85.tmp
2010-05-19 18:08 . 2010-05-19 21:35 27136 ----a-w- c:\windows\Internet Logs\xDB84.tmp
2010-05-19 02:40 . 2010-05-19 17:48 92160 ----a-w- c:\windows\Internet Logs\xDB83.tmp
2010-05-18 20:15 . 2010-05-16 02:27 -------- d-----w- c:\program files\prosonsoft
2010-05-17 03:24 . 2010-05-17 12:32 49664 ----a-w- c:\windows\Internet Logs\xDB82.tmp
2010-05-16 02:52 . 2010-05-16 21:48 107008 ----a-w- c:\windows\Internet Logs\xDB81.tmp
2010-05-15 01:48 . 2009-10-15 12:16 -------- d-----w- c:\program files\Realtek
2010-05-14 23:41 . 2010-05-14 23:42 25088 ----a-w- c:\windows\Internet Logs\xDB80.tmp
2010-05-14 23:33 . 2010-05-14 23:34 26112 ----a-w- c:\windows\Internet Logs\xDB7F.tmp
2010-05-14 23:23 . 2010-05-14 23:24 25600 ----a-w- c:\windows\Internet Logs\xDB7E.tmp
2010-05-14 22:31 . 2010-05-14 23:16 62464 ----a-w- c:\windows\Internet Logs\xDB7D.tmp
2010-05-14 03:10 . 2010-05-14 19:19 56832 ----a-w- c:\windows\Internet Logs\xDB7C.tmp
2010-05-14 00:40 . 2010-05-14 00:36 -------- d-----w- c:\program files\90 Second Website Builder
2010-05-14 00:35 . 2010-05-14 00:37 737280 ----a-w- c:\windows\iun6002.exe
2009-11-25 11:33 . 2009-11-25 11:33 135680 ----a-w- c:\program files\mozilla firefox\components\GoogleD esktopMozi lla.dll
.
------- Sigcheck -------
[-] 2008-04-14 . 917C64008889003E6EA19CF079 3CBD72 . 551424 . . [5.1.2600.5512] . . c:\windows\ServicePackFile s\i386\win logon.exe
[-] 2008-04-14 . 917C64008889003E6EA19CF079 3CBD72 . 551424 . . [5.1.2600.5512] . . c:\windows\system32\winlog on.exe
[7] 2008-04-14 . DD73D6B9F6B4CB630CF35B438B 540174 . 512000 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ winlogon.e xe
[-] 2004-08-03 . BDBD27FA935D482A3D6890C699 13F8A4 . 546304 . . [5.1.2600.2180] . . c:\windows\$NtServicePackU ninstall$\ winlogon.e xe
[-] 2008-04-14 . 2176257E2D5C71B238B95D8F1C 4635FD . 724992 . . [5.82] . . c:\windows\ServicePackFile s\i386\com ctl32.dll
[-] 2008-04-14 . 2176257E2D5C71B238B95D8F1C 4635FD . 724992 . . [5.82] . . c:\windows\system32\comctl 32.dll
[7] 2008-04-14 . B4AA331468315B6A174C3F0D5B 3BC135 . 617472 . . [5.82] . . c:\windows\VistaMizer\old\ comctl32.d ll
[-] 2004-08-03 . 7F5AE144A8351E605C5900C34F 03D569 . 718848 . . [5.82] . . c:\windows\$NtServicePackU ninstall$\ comctl32.d ll
[-] 2008-04-14 . 543B0B5CB3737D17FEEB7FDC20 B1A181 . 588800 . . [5.1.2600.5512] . . c:\windows\ServicePackFile s\i386\use r32.dll
[-] 2008-04-14 . 543B0B5CB3737D17FEEB7FDC20 B1A181 . 588800 . . [5.1.2600.5512] . . c:\windows\system32\user32 .dll
[7] 2008-04-14 . E853F84D3CE2FAA2A802E33CF8 9AC023 . 579584 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ user32.dll
[7] 2004-08-03 . E46FB493E3B33704F0715020CF 52106B . 578048 . . [5.1.2600.2180] . . c:\windows\$NtServicePackU ninstall$\ user32.dll
[-] 2008-04-14 . E7F63819E78A8C4BB43657472B CEF2C3 . 1556480 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[-] 2008-04-14 . E7F63819E78A8C4BB43657472B CEF2C3 . 1556480 . . [6.00.2900.5512] . . c:\windows\ServicePackFile s\i386\exp lorer.exe
[7] 2008-04-14 . F2317622D29F9FF0F88AEECD5F 60F0DD . 1037824 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\ explorer.e xe
[-] 2004-08-03 . 53F294A168AA0D3F68C1409A4D 101E14 . 1554944 . . [6.00.2900.2180] . . c:\windows\$NtServicePackU ninstall$\ explorer.e xe
[-] 2008-04-14 . 6F88A39FD32BF0BE9D0BC0FD40 90E9EB . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFile s\i386\ctf mon.exe
[-] 2008-04-14 . 6F88A39FD32BF0BE9D0BC0FD40 90E9EB . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon .exe
[7] 2008-04-14 . 59DC5BB82E4C8E0B3EADCFDBC4 4BA6E4 . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ ctfmon.exe
[-] 2004-08-03 . AF699A4A5F2FB5E3D73E931C2E 6BEDC4 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackU ninstall$\ ctfmon.exe
.
(((((((((((((((((((((((((( ((((((( Points de chargement Reg )))))))))))))))))))))))))) )))))))))) )))))))))) ))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR E\Microsof t\Windows\ CurrentVer sion\Run]
"Z810PNP"="c:\program files\Modem Samsung SCH-U209\SamsungPnPService Manager.ex e" [2009-02-13 176128]
"Z810SysStart"="c:\program files\Modem Samsung SCH-U209\sysctrlU.exe" [2009-02-11 311296]
"DriveCrypt5"="d:\drivecry pt 5\DriveCrypt.exe" [2009-12-02 3398616]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Windows \CurrentVe rsion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.ex e" [2009-02-16 981384]
"SensorsViewPro31"="c:\pro gram files\SensorsViewPro31\svi ewpro.exe" [2008-04-27 1650468]
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtT ray.exe" [2008-08-04 226816]
"eDataSecurity Loader"="c:\acer\Empowerin g Technology\eDataSecurity\e DSloader.e xe" [2005-12-27 69632]
"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [2010-05-06 516216]
[HKEY_USERS\.DEFAULT\Softw are\Micros oft\Window s\CurrentV ersion\Run ]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\windows \currentve rsion\poli cies\syste m]
"ConsentPromptBehaviorAdmi n"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM \CurrentCo ntrolSet\C ontrol\Saf eBoot\Mini mal\Wdf010 00.sys]
@="Driver"
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Menu Démarrer^Programmes^Démarr age^Lancem ent rapide de Microsoft Office OneNote 2003.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarr age\Lancem ent rapide de Microsoft Office OneNote 2003.lnk
backup=c:\windows\pss\Lanc ement rapide de Microsoft Office OneNote 2003.lnkCommon Startup
[HKLM\~\startupfolder\C:^D ocuments and Settings^All Users^Menu Démarrer^Programmes^Démarr age^Logici el Kodak EasyShare.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarr age\Logici el Kodak EasyShare.lnk
backup=c:\windows\pss\Logi ciel Kodak EasyShare.lnkCommon Startup
[HKLM\~\startupfolder\C:^D ocuments and Settings^David^Menu Démarrer^Programmes^Démarr age^Adobe Gamma.lnk]
path=c:\documents and settings\David\Menu Démarrer\Programmes\Démarr age\Adobe Gamma.lnk
backup=c:\windows\pss\Adob e Gamma.lnkStartup
[HKLM\~\startupfolder\C:^D ocuments and Settings^David^Menu Démarrer^Programmes^Démarr age^ShutDo wn After.lnk]
path=c:\documents and settings\David\Menu Démarrer\Programmes\Démarr age\ShutDo wn After.lnk
backup=c:\windows\pss\Shut Down After.lnkStartup
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ combofix]
c:\combofix\CF21825.cfxxe [X]
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Adobe Photo Downloader]
2005-06-06 23:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy. exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Alcmtr]
2006-08-16 11:20 69632 ----a-w- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ AlcWzrd]
2006-08-16 11:20 2808832 ----a-w- c:\windows\alcwzrd.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Autorun Eater]
2010-05-06 17:59 516216 ----a-w- c:\program files\Autorun Eater\oldmcdonald.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ AzMixerSel ]
2006-08-16 11:20 53248 ------w- c:\program files\Realtek\InstallShiel d\AzMixerS el.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ ctfmon.exe ]
2008-04-14 02:33 25088 ------w- c:\windows\system32\ctfmon .exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ DAEMON Tools]
2006-11-12 10:48 157592 ----a-w- c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ DriveCrypt 5]
2009-12-02 14:55 3398616 ----a-w- d:\drivecrypt 5\DriveCrypt.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Easy-Print ToolBox]
2004-01-14 01:10 409600 ----a-w- c:\program files\Canon\Easy-PrintTool Box\BJPSMA IN.EXE
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Google Desktop Search]
2009-11-25 11:33 1838592 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Google Update]
2009-10-15 12:42 133104 ----atw- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleU pdate.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ iCall Internet Phone]
2008-12-18 15:44 1587576 ----a-w- c:\program files\iCall\iCall.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ igfxhkcmd]
2006-03-23 10:13 77824 ------w- c:\windows\system32\hkcmd. exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ igfxpers]
2006-03-23 10:17 118784 ------w- c:\windows\system32\igfxpe rs.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ igfxtray]
2006-03-23 10:17 94208 ------w- c:\windows\system32\igfxtr ay.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ iTunesHelp er]
2009-07-13 14:03 292128 ----a-w- c:\program files\iTunes\iTunesHelper. exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Malwarebyt es' Anti-Malware]
2010-04-29 14:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ MessengerP lus3]
2009-11-20 01:22 190024 ----a-w- c:\program files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ msnmsgr]
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ PCSuiteTra yApplicati on]
2007-03-23 13:20 227328 ----a-w- c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ Propel Accelerator]
2009-07-29 01:49 69632 ----a-w- c:\program files\Propel Accelerator\trayctl.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ QuickTime Task]
2009-05-26 17:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ RTHDCPL]
2006-08-16 11:23 16248320 ----a-w- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SafeBit]
2007-07-18 14:52 1447360 ----a-w- c:\progra~1\SafeBit\safebi t.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SkyTel]
2006-08-16 11:21 2879488 ----a-w- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SoundMan]
2006-08-16 11:21 86016 ----a-w- c:\windows\SoundMan.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SunJavaUpd ateSched]
2009-10-21 21:12 149280 ----a-w- c:\program files\Java\jre6\bin\jusche d.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ SxgTkBar]
2002-07-22 16:03 53248 ----a-w- c:\windows\system32\Sxgtkb ar.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ TrojanScan ner]
2008-11-16 20:08 1234312 ----a-w- c:\program files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\startupreg\ UVS12 Preload]
2008-06-09 11:03 397456 ----a-w- c:\program files\Corel\Corel VideoStudio 12\uvPL.exe
[HKEY_LOCAL_MACHINE\softwa re\microso ft\shared tools\msconfig\services]
"ose"=3 (0x3)
"MDM"=2 (0x2)
"JavaQuickStarterService"= 2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"UleadBurningHelper"=2 (0x2)
"OpenVPNService"=3 (0x3)
"MyWebSearchService"=2 (0x2)
"LightScribeService"=2 (0x2)
"ESDClientService"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"a2AntiDialer"=2 (0x2)
"ServiceLayer"=3 (0x3)
"gupdate"=2 (0x2)
"wampmysqld"=3 (0x3)
"wampapache"=3 (0x3)
"TuneUp.ProgramStatisticsS vc"=2 (0x2)
"PSI_SVC_2"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"vmwriter"=3 (0x3)
"VMwareHostd"=2 (0x2)
"VMAuthdService"=2 (0x2)
"VMnetDHCP"=2 (0x2)
"VMware NAT Service"=2 (0x2)
"VMwareServerWebAccess"=2 (0x2)
"MBAMService"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
[HKEY_LOCAL_MACHINE\softwa re\microso ft\securit y center]
"AntiVirusOverride"=dword: 00000001
"FirewallOverride"=dword:0 0000001
[HKEY_LOCAL_MACHINE\softwa re\microso ft\securit y center\Monitoring\ZoneLabs Firewall]
"DisableMonitoring"=dword: 00000001
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile\Auth orizedAppl ications\L ist]
"%windir%\\system32\\sessm gr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\B lueSoleilC S.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe" =
"c:\\Program Files\\Bonjour\\mDNSRespon der.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe" =
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.e xe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.ex e"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e xe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\iCall\\iCall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent. exe"=
"c:\\Program Files\\TeamViewer\\Version 5\\TeamVie wer.exe"=
"c:\\Program Files\\CounterPath\\X-Lite \\x-lite.e xe"=
"c:\\Program Files\\Skype\\Phone\\Skype .exe"=
[HKLM\~\services\sharedacc ess\parame ters\firew allpolicy\ standardpr ofile\Glob allyOpenPo rts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22 009
"1723:TCP"= 1723:TCP:PPTP
"47:TCP"= 47:TCP:PPTP2
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system3 2\drivers\ BtHidBus.s ys [31/07/2008 19:45 20616]
R0 DCR;DCR;c:\windows\system3 2\drivers\ DCR.sys [06/03/2010 20:46 294408]
R0 DCVP;DCVP;c:\windows\syste m32\driver s\DCVP.sys [06/03/2010 20:46 19624]
R0 sensorsview;sensorsview;c: \windows\s ystem32\dr ivers\sens orsview.sy s [10/01/2008 12:34 4224]
R1 VBoxDrv;VirtualBox Service;c:\windows\system3 2\drivers\ VBoxDrv.sy s [06/01/2010 17:47 142928]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32 \drivers\V BoxUSBMon. sys [06/01/2010 17:47 41744]
R2 AntiVirSchedulerService;Av ira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [15/10/2009 10:55 135336]
R2 BsMobileCS;BsMobileCS;c:\p rogram files\IVT Corporation\BlueSoleil\BsM obileCS.ex e [01/08/2008 14:55 143467]
R2 DriveCryptService;DriveCry pt Service;d:\drivecrypt 5\DCRServ.exe [06/03/2010 20:46 96680]
R2 hidedir;hidedir;c:\windows \system32\ drivers\hi dedir.sys [25/03/2010 21:48 8704]
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system3 2\drivers\ IvtBtBus.s ys [02/07/2008 13:58 26248]
R3 SOFTXG;YAMAHA XG SoftSynthesizer;c:\windows \system32\ drivers\sx gxgwdm.sys [11/04/2010 01:29 966784]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system3 2\drivers\ VBoxNetFlt .sys [08/06/2010 13:30 111312]
R3 vdisk;Virtual Disk Driver;c:\windows\system32 \drivers\v disk.sys [25/03/2010 21:48 23152]
S2 LicCtrlService;LicCtrl Service;c:\windows\Runserv ice.exe [02/06/2010 19:24 2560]
S3 MBAMProtector;MBAMProtecto r;c:\windo ws\system3 2\drivers\ mbam.sys [30/05/2010 02:54 20952]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system3 2\drivers\ VBoxNetAdp .sys [17/12/2009 16:02 100496]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\dr ivers\VBox USB.sys [06/01/2010 17:47 31504]
S4 ESDClientService;ESDClient Service;c: \program files\Western Union\ESD System\ESDClientService.ex e [04/01/2010 08:50 196608]
S4 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\Google Update.exe [03/02/2010 02:23 135664]
S4 MBAMService;MBAMService;c: \program files\Malwarebytes' Anti-Malware\mbamservice.e xe [30/05/2010 02:54 304464]
S4 sptd;sptd;c:\windows\syste m32\driver s\sptd.sys [20/10/2009 22:42 639224]
HKEY_LOCAL_MACHINE\SOFTWAR E\Microsof t\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-04-09 c:\windows\Tasks\AppleSoft wareUpdate .job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-07-02 c:\windows\Tasks\GoogleUpd ateTaskMac hineCore.j ob
- c:\program files\Google\Update\Google Update.exe [2010-02-03 01:22]
2010-07-02 c:\windows\Tasks\GoogleUpd ateTaskMac hineUA.job
- c:\program files\Google\Update\Google Update.exe [2010-02-03 01:22]
2010-07-02 c:\windows\Tasks\GoogleUpd ateTaskUse rS-1-5-21- 57989841-1 220945662- 725345543- 1003Core.j ob
- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleU pdate.exe [2009-10-15 12:42]
2010-07-02 c:\windows\Tasks\GoogleUpd ateTaskUse rS-1-5-21- 57989841-1 220945662- 725345543- 1003UA.job
- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleU pdate.exe [2009-10-15 12:42]
2010-07-02 c:\windows\Tasks\User_Feed _Synchroni zation-{F2 011298-950 9-4F9B-BEC C-8A40EA63 B876}.job
- c:\windows\system32\msfeed ssync.exe [2007-08-13 04:31]
.
.
------- Examen supplémentaire -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = http=localhost:8080
uInternet Settings,ProxyOverride = <local>
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhoto s.scr/200
IE: Copy to &Lightning Note - c:\program files\Corel\WordPerfect Lightning\Programs\WPLight ningCopyTo Note.hta
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFIC E11\EXCEL. EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\ Resource.d ll/RC_AddT oList.html
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\ Resource.d ll/RC_HSPr int.html
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\ Resource.d ll/RC_Prin t.html
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\ Resource.d ll/RC_Prev iew.html
IE: Envoyer via Bluetooth - c:\program files\IVT Corporation\BlueSoleil\Tra nsSend\IE\ tsinfo.htm
IE: Envoyer via message(&M)... - c:\program files\IVT Corporation\BlueSoleil\Tra nsSend\IE\ tssms.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleTo olbarDynam ic_mui_en_ 2EC7709873 947E87.dll /cmsidewik i.html
IE: Open with WordPerfect - c:\program files\Corel\WordPerfect Office X4\Programs\WPLauncher.hta
IE: Refresh Pa&ge with Full Quality - c:\program files\Propel Accelerator\pac-page.html
IE: Refresh Pi&cture with Full Quality - c:\program files\Propel Accelerator\pac-image.html
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Télécharger le site avec Free Download Manager - file://c:\program files\Free Download Manager\dlpage.htm
LSP: c:\program files\Propel Accelerator\prplsf.dll
FF - ProfilePath - c:\documents and settings\David\Application Data\Mozilla\Firefox\Profi les\p1jr57 lv.default \
FF - component: c:\program files\Mozilla Firefox\components\GoogleD esktopMozi lla.dll
FF - plugin: c:\documents and settings\David\Application Data\Facebook\npfbplugin_1 _0_3.dll
FF - plugin: c:\documents and settings\David\Application Data\Mozilla\Firefox\Profi les\p1jr57 lv.default \extension s\VMwareVM RC@vmware. com\plugin s\np-vmwar e-vmrc-2.5 .0-122581. dll
FF - plugin: c:\documents and settings\David\Local Settings\Application Data\Google\Update\1.2.183 .23\npGoog leOneClick 8.dll
FF - plugin: c:\program files\Google\Update\1.2.18 3.23\npGoo gleOneClic k8.dll
FF - plugin: c:\program files\Opera\program\plugin s\nppdf32. dll
FF - plugin: c:\program files\Picasa2\npPicasa3.dl l
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-0 8825760534 b} - c:\windows\Microsoft.NET\F ramework\v 3.5\Window s Presentation Foundation\DotNetAssistant Extension\
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-a-squared - c:\program files\a-squared Anti-Dialer\a2adguard.exe
MSConfigStartUp-QUAD Scheduler - c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Scheduler.exe
MSConfigStartUp-QUAD Windows service - c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner.exe
MSConfigStartUp-QuickFinde r Scheduler - c:\program files\Corel\WordPerfect Office X4\Programs\QFSCHD140.EXE
MSConfigStartUp-SUPERAntiS pyware - c:\program files\SUPERAntiSpyware\SUP ERAntiSpyw are.exe
AddRemove-Vegas Magic Casino - c:\program files\Vegas Magic Casino\Install.exe
AddRemove-_{EAB6F4ED-B18D- 4BF5-B18E- 3C7921560E C4} - d:\corel painter sketch pad\Setup\SetupARP.exe
************************** ********** ********** ********** ********** ********
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-02 20:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Run
Z810PNP = c:\program files\Modem Samsung SCH-U209\SamsungPnPService Manager.ex e???? ??|`??|????]??|di?w??????? ?????D???? ??w??????? ????????w? ??w|???|?? ????w???w? ?????????? ?????T???) ??w????)?? w???w????? ??w??@???? ?P???P???? ?:~??@???? ?????????? ???x?"|x?" |????`??6e ????VDE
Z810SysStart = c:\program files\Modem Samsung SCH-U209\sysctrlU.exe??:~? ?????:~??: ~??e?}???? ???,?:~??? ?????????? ???4???s?? |????????? ?e?}?????? ?????????D ?A?S?:~N?: ~??:~????? ?????????? ???:~L&<?? ???L?????: ~????????? ???????`?? ???A?????? ?????????? ?r?A?????? ?????????? ???????A
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
************************** ********** ********** ********** ********** ********
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\softwa re\Classes \CLSID\{BF 865BB3-BAE 1-5B2B-43B 7-7BC32F1F 8A5F}\InPr ocServer32 *]
"jadnjijmofnlohdhjnoo"=hex :6b,61,6d, 6b,6e,70,6 3,6e,6f,66 ,6e,65,69, 6a,67,6c,6 5,
6d,70,6e,6b,68,00,00
"iadnhjdnmoacjhmmcf"=hex:6 b,61,6d,6b ,6e,70,63, 6e,6f,66,6 e,65,69,6a ,67,6c,65, 6d,
70,6e,6b,68,00,00
[HKEY_LOCAL_MACHINE\softwa re\LicCtrl \LicCtrl\L icCtrl\Lic Ctrl*lkzs$ i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347]
"1"=hex:6a,0b,56,13,c1,93, dc,9c,fb,6 1,a2,a0,e4 ,ff,91,20, 60,bf,2f,c 2,35,91,ae ,
25
"2"=hex:fb,e6,50,7f,41,f4, 51,a7,7f,e c,2d,f9,42 ,45,3a,02, 3a,b7,45,1 5,3f,9d,8b ,
c3
"3"=hex:6a,0b,56,13,c1,93, dc,9c,fb,6 1,a2,a0,e4 ,ff,91,20, 5d,f5,58,d 1,21,e0,48 ,
8b,38,57,44,9c,4e,8d,78,88 ,fd,f1,01, 9d,86,d8,b 5,cb,d9,bf ,23,55,4a, bb,31,1f
[HKEY_LOCAL_MACHINE\softwa re\LicCtrl \LicCtrl\L icCtrl\Lic Ctrl*lkzs$ i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\B7F5EA51 3569EA3E98 352E3A3D1D 6A3D]
"1"=hex:df,c7,3a,96,ab,66, 13,d2,36,7 8,6c,b8,10 ,1c,c4,b0, a6,93,a9,2 5,23,fb,66 ,
2c,77,d8,5d,6a,fe,59,6e,ef
"2"=hex:14,ce,87,8d,79,74, ee,b2
"3"=hex:81,20,8f,ab,28,6a, 52,9c
"4"=hex:2f,ad,a2,e7,8a,bf, 05,5e
"5"=hex:bf,e5,23,7b,b0,66, d6,fc,b8,e 8,6b,a0,96 ,52,f7,32, 80,09,8f,2 4,b7,b3,55 ,
1a,98,d1,47,16,02,43,61,1c ,b9,d5,8f, 2a,7b,81,b 1,fb,95,22 ,f8,b3,2c, 53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66, d6,fc,bc,6 4,22,fb,7e ,d3,39,3e, a3,00,33,1 3,c0,21,f4 ,
51,6c,4e,0c,96,e2,dd,ad,8a ,b6,c4,05, e8,5a,bd,9 a,e9,d4,1a ,3d,68,9d, 00,32,20
"7"=hex:58,eb,3b,8d,af,31, 32,62,22,1 b,23,79,6d ,f4,12,c1, db,b4,20,3 e,7f,80,2a ,
0f,6a,a6,22,9f,10,4c,a5,77 ,df,44,a4, 37,10,4b,b c,75,d7,98 ,0e,82,a4, 8d,85,b3,\
"8"=hex:cf,51,61,14,72,6e, 58,56,09,d f,6c,0f,74 ,8d,cf,b5, 78,65,12,a e,76,79,35 ,
e0,59,7a,c7,42,77,f4,36,78
"9"=hex:81,20,8f,ab,28,6a, 52,9c
"18"=hex:b6,dd,00,4d,9d,38 ,11,d1
"10"=hex:81,20,8f,ab,28,6a ,52,9c
"11"=hex:81,20,8f,ab,28,6a ,52,9c
"12"=hex:81,20,8f,ab,28,6a ,52,9c
"13"=hex:81,20,8f,ab,28,6a ,52,9c
"14"=hex:81,20,8f,ab,28,6a ,52,9c
"24"=hex:81,20,8f,ab,28,6a ,52,9c
"26"=hex:81,20,8f,ab,28,6a ,52,9c
"27"=hex:81,20,8f,ab,28,6a ,52,9c
"19"=hex:81,20,8f,ab,28,6a ,52,9c
"22"=hex:81,20,8f,ab,28,6a ,52,9c
[HKEY_LOCAL_MACHINE\softwa re\Microso ft\Windows \CurrentVe rsion\Inst aller\User Data\Local System\Com ponents\ð• €|ÿÿÿÿ.•€| þ»Ñw*]
"C040110900063D11C8EF10054 038389C"=" C?\\WINDOW S\\system3 2\\FM20ENU .DLL"
[HKEY_LOCAL_MACHINE\softwa re\Microso ft\Windows \CurrentVe rsion\Inst aller\User Data\Local System\Com ponents\€– €|ÿÿÿÿÀ•€| ù•9~*]
"C040710900063D11C8EF10054 038389C"=" C?\\WINDOW S\\system3 2\\FM20ENU .DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1268)
c:\windows\system32\SETUPA PI.dll
c:\windows\system32\sfc_os .dll
c:\windows\system32\COMRes .dll
c:\windows\system32\cscui. dll
- - - - - - - > 'lsass.exe'(1332)
c:\windows\system32\scecli .dll
c:\windows\system32\SETUPA PI.dll
c:\program files\Propel Accelerator\prplsf.dll
c:\windows\system32\psbase .dll
.
Heure de fin: 2010-07-02 20:10:23
ComboFix-quarantined-files .txt 2010-07-02 19:10
ComboFix2.txt 2010-01-08 23:51
Avant-CF: 4 756 992 000 octets libres
Après-CF: 5 227 560 960 octets libres
- - End Of File - - EEB46E0AA6AA13C9E926EEDA9F 762097
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.
Lancé depuis: c:\documents and settings\David\Mes documents\Téléchargements\
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-F
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F
* Un antivirus résident est actif
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((
.
c:\documents and settings\David\Application
c:\documents and settings\David\Application
c:\documents and settings\David\Application
c:\documents and settings\David\Application
c:\documents and settings\David\Application
c:\documents and settings\David\Application
c:\program files\QUAD Utilities
c:\program files\QUAD Utilities\QUAD Registry Cleaner\program.log
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner website.url
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner.exe
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner.exe.BAK
c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Scheduler.exe
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Styles\Vista.cjsty
c:\program files\QUAD Utilities\QUAD Registry Cleaner\uninst.exe
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Vista Scheduler.dll
C:\Thumbs.db
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.
c:\windows\jestertb.dll
I:\install.exe
.
((((((((((((((((((((((((((
.
2010-07-01 23:20 . 2010-07-01 23:20 -------- d-----w- C:\autorunhelp
2010-07-01 23:14 . 2010-07-01 23:14 -------- d-----w- c:\program files\Autorun Eater
2010-07-01 21:14 . 2010-07-01 21:14 501936 ----a-w- c:\documents and settings\All Users\Application Data\Google\Google Toolbar\Update\gtb18.tmp.e
2010-06-28 23:25 . 2010-06-28 23:25 -------- d-----w- c:\program files\Oracle
2010-06-15 21:29 . 2010-06-15 21:31 -------- d-----w- c:\documents and settings\David\Application
2010-06-15 20:44 . 2010-06-15 21:38 664 ----a-w- c:\windows\system32\d3d9ca
2010-06-15 18:37 . 2010-06-15 21:38 -------- d-----w- c:\documents and settings\LocalService\Appl
2010-06-15 18:28 . 2010-06-15 22:04 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
2010-06-12 00:31 . 2010-05-06 10:33 743424 -c----w- c:\windows\system32\dllcac
2010-06-08 21:02 . 2010-06-08 21:02 -------- d-----w- c:\windows\system32\ivtMob
2010-06-08 12:30 . 2010-06-08 12:30 111312 ----a-w- c:\windows\system32\driver
2010-06-08 12:30 . 2010-06-08 12:30 133648 ----a-w- c:\windows\system32\VBoxNe
2010-06-06 01:02 . 2010-06-06 01:02 61440 ----a-w- c:\documents and settings\David\Application
2010-06-06 01:02 . 2007-03-22 10:46 126976 ----a-w- c:\documents and settings\David\Application
.
((((((((((((((((((((((((((
.
2010-07-02 18:54 . 2001-08-24 12:00 81824 ----a-w- c:\windows\system32\perfc0
2010-07-02 18:54 . 2001-08-24 12:00 503894 ----a-w- c:\windows\system32\perfh0
2010-07-02 18:50 . 2010-06-02 18:24 1345 --sha-w- c:\windows\system32\mmf.sy
2010-07-02 18:48 . 2010-07-02 18:49 112640 ----a-w- c:\windows\Internet Logs\xDBB7.tmp
2010-07-02 18:35 . 2010-01-02 22:28 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-01 23:14 . 2010-01-07 23:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Autorun Eater
2010-07-01 20:19 . 2009-10-15 12:20 -------- d-----w- c:\program files\Messenger Plus! Live
2010-06-30 23:41 . 2010-06-30 23:43 22016 ----a-w- c:\windows\Internet Logs\xDBB6.tmp
2010-06-30 23:36 . 2010-01-03 22:09 -------- d-----w- c:\program files\DAEMON Tools
2010-06-30 23:33 . 2010-06-30 23:34 25088 ----a-w- c:\windows\Internet Logs\xDBB5.tmp
2010-06-30 23:32 . 2009-10-20 21:42 639224 ----a-w- c:\windows\system32\driver
2010-06-30 23:17 . 2010-06-30 23:18 35328 ----a-w- c:\windows\Internet Logs\xDBB4.tmp
2010-06-30 15:37 . 2010-06-30 15:38 24064 ----a-w- c:\windows\Internet Logs\xDBB3.tmp
2010-06-30 02:46 . 2010-06-30 15:10 28672 ----a-w- c:\windows\Internet Logs\xDBB2.tmp
2010-06-30 02:20 . 2010-01-01 14:56 -------- d-----w- c:\documents and settings\David\Application
2010-06-29 17:04 . 2010-06-29 20:37 44544 ----a-w- c:\windows\Internet Logs\xDBB1.tmp
2010-06-28 02:18 . 2010-06-28 02:18 120311 ----a-w- c:\windows\Internet Logs\vsmon_2nd_2010_06_28_
2010-06-27 20:55 . 2010-06-27 23:00 28672 ----a-w- c:\windows\Internet Logs\xDBB0.tmp
2010-06-27 19:53 . 2010-06-27 19:54 38912 ----a-w- c:\windows\Internet Logs\xDBAF.tmp
2010-06-26 02:30 . 2010-06-26 14:28 26112 ----a-w- c:\windows\Internet Logs\xDBAE.tmp
2010-06-25 02:02 . 2010-06-25 22:38 27136 ----a-w- c:\windows\Internet Logs\xDBAD.tmp
2010-06-25 01:26 . 2010-02-16 18:04 -------- d-----w- c:\documents and settings\David\Application
2010-06-24 20:26 . 2010-06-25 01:09 29696 ----a-w- c:\windows\Internet Logs\xDBAC.tmp
2010-06-24 00:52 . 2010-06-24 17:58 32256 ----a-w- c:\windows\Internet Logs\xDBAB.tmp
2010-06-23 19:16 . 2010-06-23 21:46 28160 ----a-w- c:\windows\Internet Logs\xDBAA.tmp
2010-06-23 15:54 . 2010-06-23 15:55 44032 ----a-w- c:\windows\Internet Logs\xDBA9.tmp
2010-06-23 14:27 . 2009-10-26 22:05 -------- d-----w- c:\documents and settings\David\Application
2010-06-22 02:10 . 2010-06-22 21:32 25600 ----a-w- c:\windows\Internet Logs\xDBA8.tmp
2010-06-21 23:00 . 2010-06-22 00:32 43008 ----a-w- c:\windows\Internet Logs\xDBA7.tmp
2010-06-20 22:52 . 2010-06-20 22:58 37888 ----a-w- c:\windows\Internet Logs\xDBA6.tmp
2010-06-19 18:06 . 2010-06-19 19:22 19456 ----a-w- c:\windows\Internet Logs\xDBA5.tmp
2010-06-19 01:42 . 2010-06-19 17:48 24576 ----a-w- c:\windows\Internet Logs\xDBA4.tmp
2010-06-18 14:28 . 2010-06-18 23:35 30208 ----a-w- c:\windows\Internet Logs\xDBA3.tmp
2010-06-18 00:40 . 2010-06-18 13:06 32256 ----a-w- c:\windows\Internet Logs\xDBA2.tmp
2010-06-16 19:25 . 2009-11-06 13:44 4321611 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-06-16 02:05 . 2010-06-16 19:25 27136 ----a-w- c:\windows\Internet Logs\xDBA1.tmp
2010-06-15 22:07 . 2010-06-15 22:08 43520 ----a-w- c:\windows\Internet Logs\xDBA0.tmp
2010-06-15 20:57 . 2010-06-15 20:58 36352 ----a-w- c:\windows\Internet Logs\xDB9F.tmp
2010-06-15 18:39 . 2010-06-15 18:40 31232 ----a-w- c:\windows\Internet Logs\xDB9E.tmp
2010-06-15 01:55 . 2010-06-15 18:17 62464 ----a-w- c:\windows\Internet Logs\xDB9D.tmp
2010-06-15 00:34 . 2009-10-15 12:20 -------- d-----w- c:\program files\mIRC
2010-06-14 23:39 . 2009-10-26 23:04 -------- d-----w- c:\documents and settings\David\Application
2010-06-14 23:11 . 2009-10-26 23:07 -------- d-----w- c:\documents and settings\David\Application
2010-06-14 02:17 . 2010-06-14 17:55 47616 ----a-w- c:\windows\Internet Logs\xDB9C.tmp
2010-06-13 17:52 . 2010-06-13 21:52 45056 ----a-w- c:\windows\Internet Logs\xDB9B.tmp
2010-06-13 02:36 . 2010-06-13 14:10 50176 ----a-w- c:\windows\Internet Logs\xDB9A.tmp
2010-06-12 16:56 . 2010-06-12 21:05 27648 ----a-w- c:\windows\Internet Logs\xDB99.tmp
2010-06-12 02:14 . 2010-06-12 13:11 123392 ----a-w- c:\windows\Internet Logs\xDB98.tmp
2010-06-09 20:30 . 2009-11-18 00:35 -------- d-----w- c:\documents and settings\David\Application
2010-06-09 02:31 . 2010-06-09 17:47 56320 ----a-w- c:\windows\Internet Logs\xDB97.tmp
2010-06-09 00:17 . 2009-10-15 12:18 -------- d-----w- c:\program files\FTP Commander
2010-06-08 12:30 . 2010-01-06 16:47 142928 ----a-w- c:\windows\system32\driver
2010-06-08 12:30 . 2010-01-06 16:47 31504 ----a-w- c:\windows\system32\driver
2010-06-08 12:30 . 2010-01-06 16:47 41744 ----a-w- c:\windows\system32\driver
2010-06-08 12:30 . 2009-12-17 15:02 100496 ----a-w- c:\windows\system32\driver
2010-06-08 02:05 . 2010-06-08 20:57 54784 ----a-w- c:\windows\Internet Logs\xDB96.tmp
2010-06-07 20:39 . 2010-06-07 21:12 47616 ----a-w- c:\windows\Internet Logs\xDB95.tmp
2010-06-07 02:19 . 2010-06-07 16:06 44032 ----a-w- c:\windows\Internet Logs\xDB94.tmp
2010-06-07 02:14 . 2009-10-15 09:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-06 15:46 . 2010-06-06 22:56 52736 ----a-w- c:\windows\Internet Logs\xDB93.tmp
2010-06-06 01:05 . 2010-06-06 13:14 51712 ----a-w- c:\windows\Internet Logs\xDB92.tmp
2010-06-05 02:26 . 2010-06-05 23:14 48128 ----a-w- c:\windows\Internet Logs\xDB91.tmp
2010-06-04 00:57 . 2010-06-04 22:50 30720 ----a-w- c:\windows\Internet Logs\xDB90.tmp
2010-06-03 01:57 . 2010-06-03 22:49 81920 ----a-w- c:\windows\Internet Logs\xDB8F.tmp
2010-06-02 18:24 . 2010-06-02 18:24 48640 ----a-w- c:\windows\mmfs.dll
2010-06-02 18:24 . 2010-06-02 18:24 2560 ----a-w- c:\windows\Runservice.exe
2010-06-02 11:25 . 2010-06-02 11:25 -------- d-----w- c:\program files\Apstel
2010-06-02 11:25 . 2010-06-02 11:25 -------- d--h--w- c:\program files\InstallJammer Registry
2010-06-02 01:20 . 2010-06-02 11:22 42496 ----a-w- c:\windows\Internet Logs\xDB8E.tmp
2010-06-01 01:10 . 2010-06-01 21:38 91648 ----a-w- c:\windows\Internet Logs\xDB8D.tmp
2010-05-30 23:14 . 2010-03-15 11:51 -------- d-----w- c:\program files\WinBlackJackBot V3.0
2010-05-30 23:14 . 2010-03-13 22:55 -------- d-----w- c:\program files\Vegas Magic Casino
2010-05-30 01:54 . 2010-01-07 00:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-29 02:35 . 2010-05-29 23:03 80896 ----a-w- c:\windows\Internet Logs\xDB8C.tmp
2010-05-29 00:35 . 2010-05-29 00:35 -------- d-----w- c:\documents and settings\All Users\Application Data\CounterPath
2010-05-27 00:28 . 2010-05-27 21:56 56832 ----a-w- c:\windows\Internet Logs\xDB8B.tmp
2010-05-26 22:22 . 2010-02-02 00:39 -------- d-----w- c:\program files\CounterPath
2010-05-26 22:16 . 2010-05-26 22:16 -------- d-----w- c:\documents and settings\All Users\Application Data\CounterPath Corporation
2010-05-26 22:16 . 2010-05-26 22:16 -------- d-----w- c:\documents and settings\David\Application
2010-05-26 20:51 . 2010-05-26 20:51 -------- d-----w- c:\program files\Axon Data
2010-05-26 19:36 . 2010-04-14 21:23 -------- d-----w- c:\documents and settings\David\Application
2010-05-26 11:49 . 2010-05-26 17:06 111616 ----a-w- c:\windows\Internet Logs\xDB8A.tmp
2010-05-24 01:58 . 2010-05-24 21:35 40448 ----a-w- c:\windows\Internet Logs\xDB89.tmp
2010-05-23 02:24 . 2010-05-23 20:47 50176 ----a-w- c:\windows\Internet Logs\xDB88.tmp
2010-05-22 04:07 . 2010-05-22 22:51 73216 ----a-w- c:\windows\Internet Logs\xDB86.tmp
2010-05-22 04:07 . 2010-05-22 22:51 4149760 ----a-w- c:\windows\Internet Logs\xDB87.tmp
2010-05-20 01:48 . 2010-05-20 20:46 45568 ----a-w- c:\windows\Internet Logs\xDB85.tmp
2010-05-19 18:08 . 2010-05-19 21:35 27136 ----a-w- c:\windows\Internet Logs\xDB84.tmp
2010-05-19 02:40 . 2010-05-19 17:48 92160 ----a-w- c:\windows\Internet Logs\xDB83.tmp
2010-05-18 20:15 . 2010-05-16 02:27 -------- d-----w- c:\program files\prosonsoft
2010-05-17 03:24 . 2010-05-17 12:32 49664 ----a-w- c:\windows\Internet Logs\xDB82.tmp
2010-05-16 02:52 . 2010-05-16 21:48 107008 ----a-w- c:\windows\Internet Logs\xDB81.tmp
2010-05-15 01:48 . 2009-10-15 12:16 -------- d-----w- c:\program files\Realtek
2010-05-14 23:41 . 2010-05-14 23:42 25088 ----a-w- c:\windows\Internet Logs\xDB80.tmp
2010-05-14 23:33 . 2010-05-14 23:34 26112 ----a-w- c:\windows\Internet Logs\xDB7F.tmp
2010-05-14 23:23 . 2010-05-14 23:24 25600 ----a-w- c:\windows\Internet Logs\xDB7E.tmp
2010-05-14 22:31 . 2010-05-14 23:16 62464 ----a-w- c:\windows\Internet Logs\xDB7D.tmp
2010-05-14 03:10 . 2010-05-14 19:19 56832 ----a-w- c:\windows\Internet Logs\xDB7C.tmp
2010-05-14 00:40 . 2010-05-14 00:36 -------- d-----w- c:\program files\90 Second Website Builder
2010-05-14 00:35 . 2010-05-14 00:37 737280 ----a-w- c:\windows\iun6002.exe
2009-11-25 11:33 . 2009-11-25 11:33 135680 ----a-w- c:\program files\mozilla firefox\components\GoogleD
.
------- Sigcheck -------
[-] 2008-04-14 . 917C64008889003E6EA19CF079
[-] 2008-04-14 . 917C64008889003E6EA19CF079
[7] 2008-04-14 . DD73D6B9F6B4CB630CF35B438B
[-] 2004-08-03 . BDBD27FA935D482A3D6890C699
[-] 2008-04-14 . 2176257E2D5C71B238B95D8F1C
[-] 2008-04-14 . 2176257E2D5C71B238B95D8F1C
[7] 2008-04-14 . B4AA331468315B6A174C3F0D5B
[-] 2004-08-03 . 7F5AE144A8351E605C5900C34F
[-] 2008-04-14 . 543B0B5CB3737D17FEEB7FDC20
[-] 2008-04-14 . 543B0B5CB3737D17FEEB7FDC20
[7] 2008-04-14 . E853F84D3CE2FAA2A802E33CF8
[7] 2004-08-03 . E46FB493E3B33704F0715020CF
[-] 2008-04-14 . E7F63819E78A8C4BB43657472B
[-] 2008-04-14 . E7F63819E78A8C4BB43657472B
[7] 2008-04-14 . F2317622D29F9FF0F88AEECD5F
[-] 2004-08-03 . 53F294A168AA0D3F68C1409A4D
[-] 2008-04-14 . 6F88A39FD32BF0BE9D0BC0FD40
[-] 2008-04-14 . 6F88A39FD32BF0BE9D0BC0FD40
[7] 2008-04-14 . 59DC5BB82E4C8E0B3EADCFDBC4
[-] 2004-08-03 . AF699A4A5F2FB5E3D73E931C2E
.
((((((((((((((((((((((((((
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"Z810PNP"="c:\program files\Modem Samsung SCH-U209\SamsungPnPService
"Z810SysStart"="c:\program
"DriveCrypt5"="d:\drivecry
[HKEY_LOCAL_MACHINE\SOFTWA
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.ex
"SensorsViewPro31"="c:\pro
"BtTray"="c:\program files\IVT Corporation\BlueSoleil\BtT
"eDataSecurity Loader"="c:\acer\Empowerin
"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [2010-05-06 516216]
[HKEY_USERS\.DEFAULT\Softw
"Nokia.PCSync"="c:\program
[HKEY_LOCAL_MACHINE\softwa
"ConsentPromptBehaviorAdmi
[HKEY_LOCAL_MACHINE\SYSTEM
@="Driver"
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarr
backup=c:\windows\pss\Lanc
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarr
backup=c:\windows\pss\Logi
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\David\Menu Démarrer\Programmes\Démarr
backup=c:\windows\pss\Adob
[HKLM\~\startupfolder\C:^D
path=c:\documents and settings\David\Menu Démarrer\Programmes\Démarr
backup=c:\windows\pss\Shut
[HKEY_LOCAL_MACHINE\softwa
c:\combofix\CF21825.cfxxe [X]
[HKEY_LOCAL_MACHINE\softwa
2005-06-06 23:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.
[HKEY_LOCAL_MACHINE\softwa
2006-08-16 11:20 69632 ----a-w- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\softwa
2006-08-16 11:20 2808832 ----a-w- c:\windows\alcwzrd.exe
[HKEY_LOCAL_MACHINE\softwa
2010-05-06 17:59 516216 ----a-w- c:\program files\Autorun Eater\oldmcdonald.exe
[HKEY_LOCAL_MACHINE\softwa
2006-08-16 11:20 53248 ------w- c:\program files\Realtek\InstallShiel
[HKEY_LOCAL_MACHINE\softwa
2008-04-14 02:33 25088 ------w- c:\windows\system32\ctfmon
[HKEY_LOCAL_MACHINE\softwa
2006-11-12 10:48 157592 ----a-w- c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\softwa
2009-12-02 14:55 3398616 ----a-w- d:\drivecrypt 5\DriveCrypt.exe
[HKEY_LOCAL_MACHINE\softwa
2004-01-14 01:10 409600 ----a-w- c:\program files\Canon\Easy-PrintTool
[HKEY_LOCAL_MACHINE\softwa
2009-11-25 11:33 1838592 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\softwa
2009-10-15 12:42 133104 ----atw- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleU
[HKEY_LOCAL_MACHINE\softwa
2008-12-18 15:44 1587576 ----a-w- c:\program files\iCall\iCall.exe
[HKEY_LOCAL_MACHINE\softwa
2006-03-23 10:13 77824 ------w- c:\windows\system32\hkcmd.
[HKEY_LOCAL_MACHINE\softwa
2006-03-23 10:17 118784 ------w- c:\windows\system32\igfxpe
[HKEY_LOCAL_MACHINE\softwa
2006-03-23 10:17 94208 ------w- c:\windows\system32\igfxtr
[HKEY_LOCAL_MACHINE\softwa
2009-07-13 14:03 292128 ----a-w- c:\program files\iTunes\iTunesHelper.
[HKEY_LOCAL_MACHINE\softwa
2010-04-29 14:39 437584 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\softwa
2009-11-20 01:22 190024 ----a-w- c:\program files\MessengerPlus! 3\MsgPlus.exe
[HKEY_LOCAL_MACHINE\softwa
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\softwa
2007-03-23 13:20 227328 ----a-w- c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\softwa
2009-07-29 01:49 69632 ----a-w- c:\program files\Propel Accelerator\trayctl.exe
[HKEY_LOCAL_MACHINE\softwa
2009-05-26 17:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\softwa
2006-08-16 11:23 16248320 ----a-w- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\softwa
2007-07-18 14:52 1447360 ----a-w- c:\progra~1\SafeBit\safebi
[HKEY_LOCAL_MACHINE\softwa
2006-08-16 11:21 2879488 ----a-w- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\softwa
2006-08-16 11:21 86016 ----a-w- c:\windows\SoundMan.exe
[HKEY_LOCAL_MACHINE\softwa
2009-10-21 21:12 149280 ----a-w- c:\program files\Java\jre6\bin\jusche
[HKEY_LOCAL_MACHINE\softwa
2002-07-22 16:03 53248 ----a-w- c:\windows\system32\Sxgtkb
[HKEY_LOCAL_MACHINE\softwa
2008-11-16 20:08 1234312 ----a-w- c:\program files\Trojan Remover\Trjscan.exe
[HKEY_LOCAL_MACHINE\softwa
2008-06-09 11:03 397456 ----a-w- c:\program files\Corel\Corel VideoStudio 12\uvPL.exe
[HKEY_LOCAL_MACHINE\softwa
"ose"=3 (0x3)
"MDM"=2 (0x2)
"JavaQuickStarterService"=
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"UleadBurningHelper"=2 (0x2)
"OpenVPNService"=3 (0x3)
"MyWebSearchService"=2 (0x2)
"LightScribeService"=2 (0x2)
"ESDClientService"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"a2AntiDialer"=2 (0x2)
"ServiceLayer"=3 (0x3)
"gupdate"=2 (0x2)
"wampmysqld"=3 (0x3)
"wampapache"=3 (0x3)
"TuneUp.ProgramStatisticsS
"PSI_SVC_2"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"vmwriter"=3 (0x3)
"VMwareHostd"=2 (0x2)
"VMAuthdService"=2 (0x2)
"VMnetDHCP"=2 (0x2)
"VMware NAT Service"=2 (0x2)
"VMwareServerWebAccess"=2 (0x2)
"MBAMService"=2 (0x2)
"TuneUp.Defrag"=3 (0x3)
[HKEY_LOCAL_MACHINE\softwa
"AntiVirusOverride"=dword:
"FirewallOverride"=dword:0
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedacc
"%windir%\\system32\\sessm
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\B
"%windir%\\Network Diagnostic\\xpnetdiag.exe"
"c:\\Program Files\\Bonjour\\mDNSRespon
"c:\\Program Files\\iTunes\\iTunes.exe"
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.e
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.ex
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.e
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\iCall\\iCall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.
"c:\\Program Files\\TeamViewer\\Version
"c:\\Program Files\\CounterPath\\X-Lite
"c:\\Program Files\\Skype\\Phone\\Skype
[HKLM\~\services\sharedacc
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22
"1723:TCP"= 1723:TCP:PPTP
"47:TCP"= 47:TCP:PPTP2
R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system3
R0 DCR;DCR;c:\windows\system3
R0 DCVP;DCVP;c:\windows\syste
R0 sensorsview;sensorsview;c:
R1 VBoxDrv;VirtualBox Service;c:\windows\system3
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32
R2 AntiVirSchedulerService;Av
R2 BsMobileCS;BsMobileCS;c:\p
R2 DriveCryptService;DriveCry
R2 hidedir;hidedir;c:\windows
R3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system3
R3 SOFTXG;YAMAHA XG SoftSynthesizer;c:\windows
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system3
R3 vdisk;Virtual Disk Driver;c:\windows\system32
S2 LicCtrlService;LicCtrl Service;c:\windows\Runserv
S3 MBAMProtector;MBAMProtecto
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system3
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\dr
S4 ESDClientService;ESDClient
S4 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\Google
S4 MBAMService;MBAMService;c:
S4 sptd;sptd;c:\windows\syste
HKEY_LOCAL_MACHINE\SOFTWAR
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-04-09 c:\windows\Tasks\AppleSoft
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-07-02 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
2010-07-02 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
2010-07-02 c:\windows\Tasks\GoogleUpd
- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleU
2010-07-02 c:\windows\Tasks\GoogleUpd
- c:\documents and settings\David\Local Settings\Application Data\Google\Update\GoogleU
2010-07-02 c:\windows\Tasks\User_Feed
- c:\windows\system32\msfeed
.
.
------- Examen supplémentaire -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = http=localhost:8080
uInternet Settings,ProxyOverride = <local>
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhoto
IE: Copy to &Lightning Note - c:\program files\Corel\WordPerfect Lightning\Programs\WPLight
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFIC
IE: Easy-WebPrint Ajouter à la liste d'impressions - c:\program files\Canon\Easy-WebPrint\
IE: Easy-WebPrint Impression rapide - c:\program files\Canon\Easy-WebPrint\
IE: Easy-WebPrint Imprimer - c:\program files\Canon\Easy-WebPrint\
IE: Easy-WebPrint Prévisualiser - c:\program files\Canon\Easy-WebPrint\
IE: Envoyer via Bluetooth - c:\program files\IVT Corporation\BlueSoleil\Tra
IE: Envoyer via message(&M)... - c:\program files\IVT Corporation\BlueSoleil\Tra
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleTo
IE: Open with WordPerfect - c:\program files\Corel\WordPerfect Office X4\Programs\WPLauncher.hta
IE: Refresh Pa&ge with Full Quality - c:\program files\Propel Accelerator\pac-page.html
IE: Refresh Pi&cture with Full Quality - c:\program files\Propel Accelerator\pac-image.html
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Télécharger le site avec Free Download Manager - file://c:\program files\Free Download Manager\dlpage.htm
LSP: c:\program files\Propel Accelerator\prplsf.dll
FF - ProfilePath - c:\documents and settings\David\Application
FF - component: c:\program files\Mozilla Firefox\components\GoogleD
FF - plugin: c:\documents and settings\David\Application
FF - plugin: c:\documents and settings\David\Application
FF - plugin: c:\documents and settings\David\Local Settings\Application Data\Google\Update\1.2.183
FF - plugin: c:\program files\Google\Update\1.2.18
FF - plugin: c:\program files\Opera\program\plugin
FF - plugin: c:\program files\Picasa2\npPicasa3.dl
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-0
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-a-squared - c:\program files\a-squared Anti-Dialer\a2adguard.exe
MSConfigStartUp-QUAD Scheduler - c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Scheduler.exe
MSConfigStartUp-QUAD Windows service - c:\program files\QUAD Utilities\QUAD Registry Cleaner\QUAD Registry Cleaner.exe
MSConfigStartUp-QuickFinde
MSConfigStartUp-SUPERAntiS
AddRemove-Vegas Magic Casino - c:\program files\Vegas Magic Casino\Install.exe
AddRemove-_{EAB6F4ED-B18D-
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-02 20:04
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKCU\Software\Microsoft\Wi
Z810PNP = c:\program files\Modem Samsung SCH-U209\SamsungPnPService
Z810SysStart = c:\program files\Modem Samsung SCH-U209\sysctrlU.exe??:~?
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\softwa
"jadnjijmofnlohdhjnoo"=hex
6d,70,6e,6b,68,00,00
"iadnhjdnmoacjhmmcf"=hex:6
70,6e,6b,68,00,00
[HKEY_LOCAL_MACHINE\softwa
"1"=hex:6a,0b,56,13,c1,93,
25
"2"=hex:fb,e6,50,7f,41,f4,
c3
"3"=hex:6a,0b,56,13,c1,93,
8b,38,57,44,9c,4e,8d,78,88
[HKEY_LOCAL_MACHINE\softwa
"1"=hex:df,c7,3a,96,ab,66,
2c,77,d8,5d,6a,fe,59,6e,ef
"2"=hex:14,ce,87,8d,79,74,
"3"=hex:81,20,8f,ab,28,6a,
"4"=hex:2f,ad,a2,e7,8a,bf,
"5"=hex:bf,e5,23,7b,b0,66,
1a,98,d1,47,16,02,43,61,1c
"6"=hex:bf,e5,23,7b,b0,66,
51,6c,4e,0c,96,e2,dd,ad,8a
"7"=hex:58,eb,3b,8d,af,31,
0f,6a,a6,22,9f,10,4c,a5,77
"8"=hex:cf,51,61,14,72,6e,
e0,59,7a,c7,42,77,f4,36,78
"9"=hex:81,20,8f,ab,28,6a,
"18"=hex:b6,dd,00,4d,9d,38
"10"=hex:81,20,8f,ab,28,6a
"11"=hex:81,20,8f,ab,28,6a
"12"=hex:81,20,8f,ab,28,6a
"13"=hex:81,20,8f,ab,28,6a
"14"=hex:81,20,8f,ab,28,6a
"24"=hex:81,20,8f,ab,28,6a
"26"=hex:81,20,8f,ab,28,6a
"27"=hex:81,20,8f,ab,28,6a
"19"=hex:81,20,8f,ab,28,6a
"22"=hex:81,20,8f,ab,28,6a
[HKEY_LOCAL_MACHINE\softwa
"C040110900063D11C8EF10054
[HKEY_LOCAL_MACHINE\softwa
"C040710900063D11C8EF10054
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1268)
c:\windows\system32\SETUPA
c:\windows\system32\sfc_os
c:\windows\system32\COMRes
c:\windows\system32\cscui.
- - - - - - - > 'lsass.exe'(1332)
c:\windows\system32\scecli
c:\windows\system32\SETUPA
c:\program files\Propel Accelerator\prplsf.dll
c:\windows\system32\psbase
.
Heure de fin: 2010-07-02 20:10:23
ComboFix-quarantined-files
ComboFix2.txt 2010-01-08 23:51
Avant-CF: 4 756 992 000 octets libres
Après-CF: 5 227 560 960 octets libres
- - End Of File - - EEB46E0AA6AA13C9E926EEDA9F
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Hi @rpggamergirl I must say that your last solution works perfectly and the autorun.inf files are deleted successfully, I still need help for 1 more time, i still have those folders like this way :
I:\_
|_.Trash-500
|_files
|_RECYCLER
|_S-5-3-42-2819952290-8240 758988-879 315005-366 5
All these folders are like protected and Deleting them is denied, access refused even with MS DOS, i tried the same with with ComboFix i put them in the scan file and start it, obviously ComboFix didn't delete them because they are not viruses and they have nothing inside, i just want to delete theses folders, any help?
1 more thing i paid attention to, is when i start my computer, when you see the Welcome Screen before the display of desktop, this Welcome screen freeze for like 10 seconds or more little bit before i can my desktop, any tool to resolve this problem, and thank you very much in advance
I:\_
|_.Trash-500
|_files
|_RECYCLER
|_S-5-3-42-2819952290-8240
All these folders are like protected and Deleting them is denied, access refused even with MS DOS, i tried the same with with ComboFix i put them in the scan file and start it, obviously ComboFix didn't delete them because they are not viruses and they have nothing inside, i just want to delete theses folders, any help?
1 more thing i paid attention to, is when i start my computer, when you see the Welcome Screen before the display of desktop, this Welcome screen freeze for like 10 seconds or more little bit before i can my desktop, any tool to resolve this problem, and thank you very much in advance
Glad the autorun.inf is gone.
Have you tried using Combofix script function to delete the folder and it didn't work?
Using ComboFix script below:
I'm not sure of the path of the folder, just make sure the path is correct.
Folder::
I:\_\_.Trash-500\_files\_R ECYCLER\_S -5-3-42-28 19952290-8 240758988- 879315005- 3665
If nothing works also try Kaspersky KidoKiller (kk.exe)
http://support.kaspersky.com/faq/?qid=208279973
Have you tried using Combofix script function to delete the folder and it didn't work?
Using ComboFix script below:
I'm not sure of the path of the folder, just make sure the path is correct.
Folder::
I:\_\_.Trash-500\_files\_R
If nothing works also try Kaspersky KidoKiller (kk.exe)
http://support.kaspersky.com/faq/?qid=208279973
ASKER
Hi, I tried ComboFix Script + the kk.exe but nothing, any idea?
ASKER
In addition, when i try to delete this folder .Trash-500 a Folder is generated named RECYCLER, what can generating this folder?
I'm sorry...
Did you manage to delete the RECYCLER folder?
It's normal for the default RECYCLER folder to be generated,.... but those created by nasties if they are respawned then the infection is still active.
How did you resolve the issue, may I ask.
Thanks!
Did you manage to delete the RECYCLER folder?
It's normal for the default RECYCLER folder to be generated,.... but those created by nasties if they are respawned then the infection is still active.
How did you resolve the issue, may I ask.
Thanks!
please post here the startup programs by going to
start > msconfig > startup
or before posting them try this trick to delete the file:
start > cmd
goto autorun.inf directory if the directory is e:\ for example do this
cd e:
attrib autorun.inf -s -h -a -r
del autorun.inf /f
if not ok so post here the startup programs please to check if the PC is infected