La classe la barre a disparue je te mets le log:
[10/23/2007, 21:59:10] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Adé\Bureau\VirtumundoBeGone.exe" )
[10/23/2007, 21:59:15] - Detected System Information:
[10/23/2007, 21:59:15] - Windows Version: 5.1.2600, Service Pack 2
[10/23/2007, 21:59:15] - Current Username: Adé (Admin)
[10/23/2007, 21:59:15] - Windows is in NORMAL mode.
[10/23/2007, 21:59:15] - Searching for Browser Helper Objects:
[10/23/2007, 21:59:15] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[10/23/2007, 21:59:15] - BHO 2: {163D9676-810E-11DC-8314-0800200C9A66} (SystemApp)
[10/23/2007, 21:59:15] - BHO 3: {4601D761-D53A-4508-88CA-39AFCD53FC08} ()
[10/23/2007, 21:59:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:15] - Checking for HKLM\...\Winlogon\Notify\oppmm
[10/23/2007, 21:59:15] - Key not found: HKLM\...\Winlogon\Notify\oppmm, continuing.
[10/23/2007, 21:59:15] - BHO 4: {6DB3F881-19A2-4085-ABD0-DBD56E71F4F5} ()
[10/23/2007, 21:59:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:15] - Checking for HKLM\...\Winlogon\Notify\iifefgf
[10/23/2007, 21:59:15] - Found: HKLM\...\Winlogon\Notify\iifefgf - This is probably Virtumundo.
[10/23/2007, 21:59:15] - Assigning {6DB3F881-19A2-4085-ABD0-DBD56E71F4F5} MSEvents Object
[10/23/2007, 21:59:15] - BHO list has been changed! Starting over...
[10/23/2007, 21:59:15] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[10/23/2007, 21:59:15] - BHO 2: {163D9676-810E-11DC-8314-0800200C9A66} (SystemApp)
[10/23/2007, 21:59:15] - BHO 3: {4601D761-D53A-4508-88CA-39AFCD53FC08} ()
[10/23/2007, 21:59:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:15] - Checking for HKLM\...\Winlogon\Notify\oppmm
[10/23/2007, 21:59:16] - Key not found: HKLM\...\Winlogon\Notify\oppmm, continuing.
[10/23/2007, 21:59:16] - BHO 4: {6DB3F881-19A2-4085-ABD0-DBD56E71F4F5} (MSEvents Object)
[10/23/2007, 21:59:16] - ALERT: Found MSEvents Object!
[10/23/2007, 21:59:16] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/23/2007, 21:59:16] - BHO 6: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[10/23/2007, 21:59:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:16] - No filename found. Continuing.
[10/23/2007, 21:59:16] - BHO 7: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[10/23/2007, 21:59:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:16] - Checking for HKLM\...\Winlogon\Notify\ehvdqdfy
[10/23/2007, 21:59:16] - Key not found: HKLM\...\Winlogon\Notify\ehvdqdfy, continuing.
[10/23/2007, 21:59:16] - BHO 8: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[10/23/2007, 21:59:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:16] - Checking for HKLM\...\Winlogon\Notify\bcwrwfiz
[10/23/2007, 21:59:16] - Found: HKLM\...\Winlogon\Notify\bcwrwfiz - This is probably Virtumundo.
[10/23/2007, 21:59:16] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[10/23/2007, 21:59:16] - BHO list has been changed! Starting over...
[10/23/2007, 21:59:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[10/23/2007, 21:59:16] - BHO 2: {163D9676-810E-11DC-8314-0800200C9A66} (SystemApp)
[10/23/2007, 21:59:16] - BHO 3: {4601D761-D53A-4508-88CA-39AFCD53FC08} ()
[10/23/2007, 21:59:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:16] - Checking for HKLM\...\Winlogon\Notify\oppmm
[10/23/2007, 21:59:16] - Key not found: HKLM\...\Winlogon\Notify\oppmm, continuing.
[10/23/2007, 21:59:16] - BHO 4: {6DB3F881-19A2-4085-ABD0-DBD56E71F4F5} (MSEvents Object)
[10/23/2007, 21:59:16] - ALERT: Found MSEvents Object!
[10/23/2007, 21:59:16] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/23/2007, 21:59:16] - BHO 6: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[10/23/2007, 21:59:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:16] - No filename found. Continuing.
[10/23/2007, 21:59:16] - BHO 7: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[10/23/2007, 21:59:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:16] - Checking for HKLM\...\Winlogon\Notify\ehvdqdfy
[10/23/2007, 21:59:16] - Key not found: HKLM\...\Winlogon\Notify\ehvdqdfy, continuing.
[10/23/2007, 21:59:16] - BHO 8: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[10/23/2007, 21:59:16] - ALERT: Found MSEvents Object!
[10/23/2007, 21:59:16] - Finished Searching Browser Helper Objects
[10/23/2007, 21:59:16] - *** Detected MSEvents Object
[10/23/2007, 21:59:16] - Trying to remove MSEvents Object...
[10/23/2007, 21:59:17] - Terminating Process: IEXPLORE.EXE
[10/23/2007, 21:59:18] - Terminating Process: RUNDLL32.EXE
[10/23/2007, 21:59:18] - Disabling Automatic Shell Restart
[10/23/2007, 21:59:18] - Terminating Process: EXPLORER.EXE
[10/23/2007, 21:59:19] - Suspending the NT Session Manager System Service
[10/23/2007, 21:59:19] - Terminating Windows NT Logon/Logoff Manager
[10/23/2007, 21:59:20] - Re-enabling Automatic Shell Restart
[10/23/2007, 21:59:20] - File to disable: C:\WINDOWS\system32\iifefgf.dll
[10/23/2007, 21:59:20] - Renaming C:\WINDOWS\system32\iifefgf.dll -> C:\WINDOWS\system32\iifefgf.dll.vir
[10/23/2007, 21:59:20] - File successfully renamed!
[10/23/2007, 21:59:20] - Removing HKLM\...\Browser Helper Objects\{6DB3F881-19A2-4085-ABD0-DBD56E71F4F5}
[10/23/2007, 21:59:21] - Removing HKCR\CLSID\{6DB3F881-19A2-4085-ABD0-DBD56E71F4F5}
[10/23/2007, 21:59:21] - Adding Kill Bit for ActiveX for GUID: {6DB3F881-19A2-4085-ABD0-DBD56E71F4F5}
[10/23/2007, 21:59:21] - Deleting ATLEvents/MSEvents Registry entries
[10/23/2007, 21:59:21] - Removing HKLM\...\Winlogon\Notify\iifefgf
[10/23/2007, 21:59:21] - Searching for Browser Helper Objects:
[10/23/2007, 21:59:21] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[10/23/2007, 21:59:21] - BHO 2: {163D9676-810E-11DC-8314-0800200C9A66} (SystemApp)
[10/23/2007, 21:59:21] - BHO 3: {4601D761-D53A-4508-88CA-39AFCD53FC08} ()
[10/23/2007, 21:59:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:21] - Checking for HKLM\...\Winlogon\Notify\oppmm
[10/23/2007, 21:59:21] - Key not found: HKLM\...\Winlogon\Notify\oppmm, continuing.
[10/23/2007, 21:59:21] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/23/2007, 21:59:21] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[10/23/2007, 21:59:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:21] - No filename found. Continuing.
[10/23/2007, 21:59:22] - BHO 6: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[10/23/2007, 21:59:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:22] - Checking for HKLM\...\Winlogon\Notify\ehvdqdfy
[10/23/2007, 21:59:22] - Key not found: HKLM\...\Winlogon\Notify\ehvdqdfy, continuing.
[10/23/2007, 21:59:22] - BHO 7: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[10/23/2007, 21:59:22] - ALERT: Found MSEvents Object!
[10/23/2007, 21:59:22] - Finished Searching Browser Helper Objects
[10/23/2007, 21:59:22] - *** Detected MSEvents Object
[10/23/2007, 21:59:22] - Trying to remove MSEvents Object...
[10/23/2007, 21:59:23] - Terminating Process: IEXPLORE.EXE
[10/23/2007, 21:59:23] - Terminating Process: RUNDLL32.EXE
[10/23/2007, 21:59:24] - Disabling Automatic Shell Restart
[10/23/2007, 21:59:24] - Terminating Process: EXPLORER.EXE
[10/23/2007, 21:59:24] - Suspending the NT Session Manager System Service
[10/23/2007, 21:59:24] - Terminating Windows NT Logon/Logoff Manager
[10/23/2007, 21:59:24] - Re-enabling Automatic Shell Restart
[10/23/2007, 21:59:24] - File to disable: C:\WINDOWS\system32\bcwrwfiz.dll
[10/23/2007, 21:59:25] - Renaming C:\WINDOWS\system32\bcwrwfiz.dll -> C:\WINDOWS\system32\bcwrwfiz.dll.vir
[10/23/2007, 21:59:25] - File successfully renamed!
[10/23/2007, 21:59:25] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[10/23/2007, 21:59:25] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[10/23/2007, 21:59:25] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[10/23/2007, 21:59:25] - Deleting ATLEvents/MSEvents Registry entries
[10/23/2007, 21:59:25] - Removing HKLM\...\Winlogon\Notify\bcwrwfiz
[10/23/2007, 21:59:25] - Searching for Browser Helper Objects:
[10/23/2007, 21:59:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[10/23/2007, 21:59:25] - BHO 2: {163D9676-810E-11DC-8314-0800200C9A66} (SystemApp)
[10/23/2007, 21:59:25] - BHO 3: {4601D761-D53A-4508-88CA-39AFCD53FC08} ()
[10/23/2007, 21:59:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:25] - Checking for HKLM\...\Winlogon\Notify\oppmm
[10/23/2007, 21:59:26] - Key not found: HKLM\...\Winlogon\Notify\oppmm, continuing.
[10/23/2007, 21:59:26] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[10/23/2007, 21:59:26] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[10/23/2007, 21:59:26] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:26] - No filename found. Continuing.
[10/23/2007, 21:59:26] - BHO 6: {89AD4D75-2429-462e-BD4E-443F233F6033} ()
[10/23/2007, 21:59:26] - WARNING: BHO has no default name. Checking for Winlogon reference.
[10/23/2007, 21:59:26] - Checking for HKLM\...\Winlogon\Notify\ehvdqdfy
[10/23/2007, 21:59:26] - Key not found: HKLM\...\Winlogon\Notify\ehvdqdfy, continuing.
[10/23/2007, 21:59:26] - Finished Searching Browser Helper Objects
[10/23/2007, 21:59:26] - Finishing up...
[10/23/2007, 21:59:26] - A restart is needed.
[10/23/2007, 21:59:31] - Attempting to Restart via STOP error (Blue Screen!)
Maintenant je vais passer au combofix
Ajout du 23-10-2007 à 22:41:
)))))))))))))))))))))))))))))))))))))))))))))))
<BR>.
<BR>
<BR>C:\Documents and Settings\Ad‚\Bureau\Live Safety Center.lnk
<BR>C:\Documents and Settings\Ad‚\Bureau\Online Security Guide.lnk
<BR>C:\Documents and Settings\Ad‚\Favoris\Online Security Guide.lnk
<BR>C:\Documents and Settings\Ad‚_2\Bureau\Live Safety Center.lnk
<BR>C:\Documents and Settings\Ad‚_2\Bureau\Online Security Guide.lnk
<BR>C:\Documents and Settings\Ad‚_2\Favoris\Online Security Guide.lnk
<BR>C:\WINDOWS\cookies.ini
<BR>C:\WINDOWS\system32\~.exe
<BR>C:\WINDOWS\system32\bcwrwfiz.dllbox
<BR>C:\WINDOWS\system32\ehvdqdfy.dll
<BR>C:\WINDOWS\system32\MabryObj.dll
<BR>C:\WINDOWS\system32\mmppo.bak1
<BR>C:\WINDOWS\system32\mmppo.bak2
<BR>C:\WINDOWS\system32\mmppo.ini
<BR>C:\WINDOWS\system32\mmppo.ini2
<BR>C:\WINDOWS\system32\oppmm.dll
<BR>C:\WINDOWS\system32\plugin1.dat
<BR>C:\WINDOWS\system32\ps.dat
<BR>C:\WINDOWS\system32\qirnwdae.dll
<BR>C:\WINDOWS\system32\SysPr.prx
<BR>C:\WINDOWS\system32\xrteydbq.exe
<BR>
<BR>.
<BR>((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
<BR>
<BR>.
<BR>-------\LEGACY_DOMAINSERVICE
<BR>-------\DomainService
<BR>
<BR>
<BR>((((((((((((((((((((((((((((( Fichiers créés 2007-09-23 to 2007-10-23 ))))))))))))))))))))))))))))))))))))
<BR>.
<BR>
<BR>2007-10-23 22:12 51,200 --a------ C:\WINDOWS\NirCmd.exe
<BR>2007-10-23 21:53 84,544 --a------ C:\WINDOWS\system32\iyxhnylp.dll
<BR>2007-10-23 20:49 <REP> d-------- C:\VundoFix Backups
<BR>2007-10-23 20:41 <REP> d-------- C:\Program Files\Navilog1
<BR>2007-10-23 20:31 2,464 --a------ C:\WINDOWS\system32\tmp.reg
<BR>2007-10-23 20:30 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
<BR>2007-10-23 20:30 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
<BR>2007-10-23 20:30 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
<BR>2007-10-23 20:30 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
<BR>2007-10-23 19:37 <REP> d-------- C:\Program Files\Trend Micro
<BR>2007-10-23 19:31 340,032 --a------ C:\WINDOWS\system32\bcwrwfiz.dll.vir
<BR>2007-10-23 19:30 340,032 --a------ C:\WINDOWS\system32\vnvqmxxh.dll
<BR>2007-10-23 12:51 <REP> d-------- C:\Program Files\Enlight
<BR>2007-10-23 12:25 <REP> d--h----- C:\Program Files\SystemApp
<BR>2007-10-23 12:25 145,929 --a------ C:\WINDOWS\system32\sysdl132.exe
<BR>2007-10-23 12:25 33,792 --a------ C:\WINDOWS\system32\iifefgf.dll.vir
<BR>2007-10-21 13:01 <REP> d-------- C:\Program Files\Eidos Interactive
<BR>2007-10-18 21:46 <REP> d-------- C:\Program Files\uTorrent
<BR>2007-10-18 21:46 <REP> C:\Documents and Settings\Adé\Application Data\uTorrent
<BR>2007-10-16 12:49 <REP> d-------- C:\Program Files\Gabest
<BR>2007-10-16 12:40 21,504 --a------ C:\WINDOWS\system32\TABCTFR.DLL
<BR>2007-10-13 08:59 <REP> C:\Documents and Settings\Adé\Recent
<BR>2007-10-09 10:49 <REP> C:\Documents and Settings\Adé_2\Application Data\vlc
<BR>2007-10-08 10:49 <REP> d-------- C:\Program Files\Snapshot Viewer
<BR>2007-10-08 10:42 <REP> C:\Documents and Settings\Adé_2\Application Data\Microsoft Web Folders
<BR>2007-10-07 13:35 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
<BR>2007-10-07 13:35 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
<BR>2007-10-07 13:35 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
<BR>2007-10-07 13:35 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
<BR>2007-10-07 13:35 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
<BR>2007-10-07 13:35 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
<BR>2007-10-07 13:35 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
<BR>2007-10-07 13:27 <REP> d-------- C:\Program Files\Codemasters
<BR>2007-10-06 15:29 <REP> d-------- C:\Program Files\Metin2_France
<BR>2007-10-05 16:08 <REP> C:\Documents and Settings\Adé_2\Application Data\Sonic
<BR>2007-10-05 16:08 <REP> C:\Documents and Settings\Adé_2\Application Data\Leadertech
<BR>2007-10-04 22:01 <REP> d-------- C:\WINTAB
<BR>2007-10-04 18:49 <REP> C:\Documents and Settings\Adé_2\Application Data\uTorrent
<BR>2007-10-04 18:23 1,386,496 --a------ C:\WINDOWS\system\MSVBVM60.DLL
<BR>2007-10-04 18:23 569,344 --a------ C:\WINDOWS\system\OLEAUT32.DLL
<BR>2007-10-04 18:23 262,656 --a------ C:\WINDOWS\system\COMDLG32.DLL
<BR>2007-10-04 18:23 119,568 --a------ C:\WINDOWS\system\VB6FR.DLL
<BR>2007-10-04 18:23 106,496 --a------ C:\WINDOWS\system\OLEPRO32.DLL
<BR>2007-10-04 18:23 77,824 --a------ C:\WINDOWS\system\ASYCFILT.DLL
<BR>2007-10-04 18:23 3,584 --a------ C:\WINDOWS\system\COMCAT.DLL
<BR>2007-10-03 20:44 46,256 C:\Documents and Settings\Adé\Application Data\GDIPFONTCACHEV1.DAT
<BR>2007-10-02 21:27 <REP> d-------- C:\demo esthetique
<BR>2007-10-02 21:07 <REP> d-------- C:\WsoftBeaute
<BR>2007-10-02 21:06 <REP> d-------- C:\WSOFT ARTE BEAUTE
<BR>2007-10-02 21:06 <REP> d-------- C:\Program Files\Fichiers communs\PC SOFT
<BR>2007-09-30 21:15 46,256 C:\Documents and Settings\Adé_2\Application Data\GDIPFONTCACHEV1.DAT
<BR>2007-09-28 21:04 <REP> C:\Documents and Settings\Adé_2\Application Data\OpenOffice.org2
<BR>2007-09-28 17:25 <REP> d-------- C:\Program Files\adslTV
<BR>2007-09-26 19:23 <REP> d--h----- C:\BJPrinter
<BR>2007-09-26 19:23 94,720 --a------ C:\WINDOWS\system32\CNMLM2v.DLL
<BR>2007-09-26 19:23 36,864 --a------ C:\WINDOWS\system32\CNMCP2V.EXE
<BR>2007-09-26 19:23 5,632 --a------ C:\WINDOWS\system32\CNMVS2v.DLL
<BR>2007-09-26 12:58 <REP> d-------- C:\Program Files\Neuf
<BR>2007-09-26 09:48 83,968 --a------ C:\WINDOWS\system32\CNBJMON2.DLL
<BR>2007-09-25 22:14 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
<BR>2007-09-25 22:14 25,856 --a------ C:\WINDOWS\system32\dllcache\usbprint.sys
<BR>2007-09-25 11:38 <REP> d-------- C:\Program Files\1CVPRO
<BR>
<BR>.
<BR>(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
<BR>.
<BR>2007-10-23 20:28 5,767,168 ----a-w C:\Documents and Settings\Adé\ntuser.dat
<BR>2007-10-23 17:54 2,621,440 ---ha-w C:\Documents and Settings\Adé_2\NTUSER.DAT
<BR>2007-10-23 14:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
<BR>2007-10-14 11:47 --------- d-s---w C:\Documents and Settings\Adé\Application Data\Microsoft
<BR>2007-10-08 11:12 --------- d-s---w C:\Documents and Settings\Adé_2\Application Data\Microsoft
<BR>2007-10-07 11:19 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
<BR>2007-10-07 10:26 --------- d-----w C:\Program Files\Fichiers communs\Real
<BR>2007-10-07 10:26 --------- d-----w C:\Documents and Settings\Adé\Application Data\Real
<BR>2007-10-07 07:47 --------- d-----w C:\Program Files\Wanadoo
<BR>2007-10-06 08:37 --------- d-----w C:\Program Files\Google
<BR>2007-10-05 19:49 --------- d-----w C:\Program Files\Elaborate Bytes
<BR>2007-10-05 19:48 --------- d-----w C:\Program Files\BankPerfect
<BR>2007-10-05 19:47 --------- d-----w C:\Program Files\honestech Video Editor 7.0 Trial
<BR>2007-09-30 19:04 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\Adobe
<BR>2007-09-28 15:25 --------- d-----w C:\Documents and Settings\Adé\Application Data\vlc
<BR>2007-09-25 13:58 --------- d-----w C:\Documents and Settings\Adé\Application Data\Adobe
<BR>2007-09-24 11:11 --------- d-----w C:\Program Files\IncrediMail
<BR>2007-09-18 10:06 --------- d-----w C:\Program Files\MSN Messenger
<BR>2007-09-10 19:14 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\TransRender
<BR>2007-09-10 19:14 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\Temporary
<BR>2007-09-10 19:14 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\Samsung
<BR>2007-09-10 19:14 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\ConvertTemp
<BR>2007-09-10 18:28 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\Real
<BR>2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
<BR>2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
<BR>2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
<BR>2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
<BR>2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
<BR>2007-08-28 16:25 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\CyberLink
<BR>2007-08-27 18:16 --------- d-----w C:\Program Files\BitZipper
<BR>2007-08-27 11:04 --------- d-----w C:\Program Files\Java
<BR>2007-08-27 10:09 --------- d-----w C:\Documents and Settings\Adé_2\Application Data\BitZipper
<BR>2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
<BR>2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
<BR>.
<BR>
<BR>((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
<BR>.
<BR>.
<BR>*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
<BR>
<BR>[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{163D9676-810E-11DC-8314-0800200C9A66}]
<BR>2007-10-23 12:25 95232 --a------ C:\Program Files\SystemApp\ie-improver.dll
<BR>
<BR>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
<BR>)
"PHIME2002ASync"="--C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" []
"PHIME2002A"="--C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" []
"IgfxTray"="--C:\WINDOWS\system32\igfxtray.exe" []
"SynTPLpr"="--C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" []
"SynTPEnh"="--C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" []
"avast!"="--C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-05 10:03]
"bc88e12c"="C:\WINDOWS\system32\iyxhnylp.dll" [2007-10-23 21:53]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\oppmm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\AIM6\aim6.exe" /d locale=en-US
ee://aol/imApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
C:\Program Files\IncrediMail\bin\IncMail.exe /c
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
"c:\Apps\Powercinema\PCMService.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STDSB]
C:\WINDOWS\system32\drivers\STDSB.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
C:\PROGRA~1\Wanadoo\Watch.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-10-23 18:30:00 C:\WINDOWS\Tasks\HDReg.job"
- c:\Apps\HDReg\HDRegRem.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-23 22:34:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-23 22:38:28 - machine was rebooted
.
--- E O F ---
">
Voilà notre dernier log.
EN tout cas merci encore
que dois je faire?