Je suis infecté par plusieurs trojans... malgré tou mes efforts j n'arrive pas à m'en débarrasser.
Voici le rapport HijackThis +AVG antispyware
Logfile of HijackThis v1.99.1
Scan saved at 13:07:19, on 02/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Documents and Settings\Kev\Bureau\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/webhp?sourceid=navclient&hl=fr&ie=UTF-8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1036
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [remoteholenameamen] C:\Documents and Settings\All Users\Application Data\Mfcdbindremotehole\DeadGram.exe
O4 - HKLM\..\Run: [WellPhone DirectSync - ScheduleSync] C:\PROGRA~1\WELLPH~1\SCHEDU~1.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Tons Two] C:\DOCUME~1\Kev\APPLIC~1\FLAGDE~1\Ownscamppure.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/...
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by110fd.bay110.hotmail.msn.com/resources/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: MSNim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exeConfiguration: Windows XP Firefox 1.5.0.10
[ Répondre à Beastie Toy ][ Dernière réponse ][ Autres messages de Beastie Toy ]
< 1 > Beastie Toy (vendredi 2 mars 2007 à 14:43:53)
LE RAPPORT AVG ANTI SPYWARE
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 14:42:02 02/03/2007
+ Résultat de l'analyse:
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026662.dll -> Adware.Virtumonde : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026520.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026521.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP98\A0014746.exe -> Backdoor.Bifrose.ada : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\antzom[1].exe -> Downloader.Agent.bgn : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\WVR1MZZE\new[1].htm -> Downloader.Agent.bi : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\exp2[2].htm -> Downloader.Agent.bx : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp1[1].htm -> Downloader.Agent.cd : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\xc23[1].exe -> Downloader.Tiny.fk : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0025503.exe -> Downloader.Tiny.fk : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\AFUQI322\exp3[2].htm -> Not-A-Virus.Exploit.HTML.IESlice.d : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp4[2].htm -> Not-A-Virus.Exploit.HTML.VML.d : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\exp5[2].htm -> Not-A-Virus.Exploit.JS.XMLCore.a : Aucune action entreprise.
:mozilla.8:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.128:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.129:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.130:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
:mozilla.245:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@adrevolver[2].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
:mozilla.173:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.174:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.88:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
:mozilla.131:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.142:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Com : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Aucune action entreprise.
:mozilla.63:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@doubleclick[1].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.62:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Estat : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
:mozilla.190:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.191:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@ehg-hollywoodmedia.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
:mozilla.76:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
:mozilla.198:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.199:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
:mozilla.200:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Questionmarket : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@guide.real[2].txt -> TrackingCookie.Real : Aucune action entreprise.
:mozilla.70:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.71:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.72:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.73:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
:mozilla.74:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Reliablestats : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.35:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Sexcounter : Aucune action entreprise.
:mozilla.36:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Sexcounter : Aucune action entreprise.
:mozilla.11:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.12:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.13:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.14:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.166:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Statcounter : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Aucune action entreprise.
:mozilla.141:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.181:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Tribalfusion : Aucune action entreprise.
:mozilla.18:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.19:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.20:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.21:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Aucune action entreprise.
:mozilla.236:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Yadro : Aucune action entreprise.
:mozilla.237:C:\Documents and Settings\Kev\Application Data\Mozilla\Firefox\Profiles\gmhrxbkj.default\cookies.txt -> TrackingCookie.Yadro : Aucune action entreprise.
C:\Documents and Settings\Kev\Cookies\kev@zedo[2].txt -> TrackingCookie.Zedo : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\F97V7C85\xc29[1].exe -> Trojan.Agent.qt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0023069.exe -> Trojan.Agent.qt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026724.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\Temp\mst1A3.tmp -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\Temp\mst310.tmp -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\system32\drvwuj.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\WINDOWS\system32\drvxag.dll -> Trojan.Agent.qt : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\52NAT80B\srvowd[1].exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\Documents and Settings\Kev\Local Settings\Temporary Internet Files\Content.IE5\52NAT80B\srvpxl[1].exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0024376.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0025502.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP123\A0026489.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP124\A0026519.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP125\A0026581.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026656.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026664.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026682.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP127\A0026716.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP128\A0026734.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\\__delete_on_reboot__w_i_n_3_E_9_._t_m_p_._e_x_e_ -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\win4E9.tmp.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\Temp\win4EC.tmp.exe -> Trojan.Dialer.rt : Aucune action entreprise.
C:\WINDOWS\system32\\__delete_on_reboot__u_d_i_a_l_._e_x_e_ -> Trojan.Dialer.rt : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP115\A0024394.exe -> Trojan.Inject.ba : Aucune action entreprise.
C:\Documents and Settings\Kev\Application Data\flagdebug\ribnrzoj.exe -> Trojan.Obfuscated.bk : Aucune action entreprise.
C:\System Volume Information\\_restore{D38CCCE4-BC9B-4E64-9F5F-A0E962D5F3E8}\RP126\A0026663.exe -> Trojan.Obfuscated.bk : Aucune action entreprise.
Fin du rapport