I have to say I feel quite desperate. I still have a lot of popups, outerinfo came back as well as webhancer and it seems I am not over with vundos. My computer is slow and I still have those icons on my desktop.
Fresh HJT:
Logfile of HijackThis v1.99.1
Scan saved at 20:48:46, on 2007-04-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\Command Software\dvpapi.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ps2.exe
C:\WINDOWS\system32\s3apphk.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\windows\system\hpsysdrv.exe
C:\Windows\system32\HpSrvUI.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\{B426C918-0577-1036-0320-021221200002}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\WINDOWS\system32\zstatus.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://frca4.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {34B3A234-61F0-6A54-A54F-1CE34890AA9F} - C:\WINDOWS\system32\rczxbl.dll (file missing)
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [s3apphk] s3apphk.exe
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [hp 1000 firmware] C:\Program Files\hp LaserJet 1000\fwdl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [Heth] "C:\DOCUME~1\PROPRI~1\APPLIC~1\ECURIT~1\dexplore.exe" -vt yazb
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternati.../00/alttiff.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://74747415.spac...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1100374723461
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000627 (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Fichiers communs\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
AVG:
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 20:36:13 2007-04-29
+ Résultat de l'analyse:
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036236.dll -> Adware.Lucky : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Outerinfo\OiUninstaller.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037576.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\rczxbl.dll -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temp\b116.exe -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\AR03EUWJ\116[1].net -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036237.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036238.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036239.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036240.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036241.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036242.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036243.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036244.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036245.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036246.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036247.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036248.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036249.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036250.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036251.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036252.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036253.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036254.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036255.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036256.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036257.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036258.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036259.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036260.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037400.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037401.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037404.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037405.dll -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\mljkhii.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\rqrpqpp.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\rqrsqnn.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\xxyaxut.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temp\b129.exe -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\1C7T52RY\129[1].net -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\webHancer -> Adware.Webhancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\webHancer\Programs -> Adware.Webhancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\webHancer\Programs\license.txt -> Adware.Webhancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\webHancer\Programs\readme.txt -> Adware.Webhancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\webHancer\Programs\whAgent.ini -> Adware.Webhancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\webHancer\Programs\whinstaller.exe -> Adware.Webhancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037546.exe -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037547.dll -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037548.dll -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037573.dll -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037574.exe -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037578.dll -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\snapshot\MFEX-1.DAT -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\snapshot\MFEX-2.DAT -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\snapshot\MFEX-3.DAT -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj.1 -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj\CurVer -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\webhancer -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\webhancer\CC -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\webhancer\ESO -> Adware.WebHancer : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\BALUVEOK\setar-101[1].0000 -> Adware.Yazzle : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP614\A0037575.exe -> Downloader.Age : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Fichiers communs\Yazzle1122OinAdmin.exe -> Downloader.PurityScan.eh : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temp\b104.exe -> Downloader.Small.buy : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\AR03EUWJ\104[1].net -> Downloader.Small.buy : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Propriétaire\Cookies\proprié[email protected][1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\proprié[email protected][1].txt -> TrackingCookie.Hitbox : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\proprié[email protected][1].txt -> TrackingCookie.Netflame : Nettoyé.
C:\Documents and Settings\Propriétaire\Cookies\proprié[email protected][1].txt -> TrackingCookie.Paypal : Nettoyé.
C:\Program Files\Ipwindows\UnInstall.exe -> Trojan.Rond : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP613\A0037541.exe -> Trojan.Rond : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\wnscpsv.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036231.exe -> Worm.Agent.a : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036232.exe -> Worm.Agent.a : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036233.exe -> Worm.Agent.a : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036234.exe -> Worm.Agent.a : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
Kaspersky:
Sunday, April 29, 2007 12:44:41 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 29/04/2007
Kaspersky Anti-Virus database records: 307224
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 82388
Number of viruses found 17
Number of infected objects 97 / 0
Number of suspicious objects 0
Duration of the scan process 01:56:18
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Zero Knowledge\Freedom\logs\ServiceModel04-29-2007--10-14-51.log Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Propriétaire\Application Data\Zero Knowledge\Freedom\logs\SafetyConsoleLog04-29-2007--10-14-52.log Object is locked skipped
C:\Documents and Settings\Propriétaire\Bureau\net.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\Documents and Settings\Propriétaire\Bureau\net.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Propriétaire\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Propriétaire\Local Settings\Historique\History.IE5\MSHist012007042920070430\index.dat Object is locked skipped
C:\Documents and Settings\Propriétaire\Local Settings\Temp\b122.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Propriétaire\Local Settings\Temp\b122.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.u skipped
C:\Documents and Settings\Propriétaire\Local Settings\Temp\b122.exe NSIS: infected - 2 skipped
C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Propriétaire\net.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\Documents and Settings\Propriétaire\net.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Propriétaire\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Propriétaire\ntuser.dat.LOG Object is locked skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\net.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\net.exe NSIS: infected - 1 skipped
C:\Program Files\Outerinfo\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.fk skipped
C:\Program Files\Outerinfo\OiUninstaller.exe/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\Program Files\Outerinfo\OiUninstaller.exe NSIS: infected - 2 skipped
C:\Program Files\webHancer\Programs\SET61E.tmp Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Program Files\webHancer\Programs\whagent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Program Files\webHancer\Programs\whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\Program Files\webHancer\Programs\whinstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP606\A0035093.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP606\A0035093.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP607\A0035180.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP607\A0035180.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0035195.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0035195.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0035197.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0035197.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036146.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036146.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036148.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036148.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036166.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036166.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036185.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036185.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036231.exe Infected: IM-Worm.Win32.Agent.a skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036232.exe Infected: IM-Worm.Win32.Agent.a skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036233.exe Infected: IM-Worm.Win32.Agent.a skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036234.exe Infected: IM-Worm.Win32.Agent.a skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036236.dll Infected: not-a-virus:AdWare.Win32.Softomate.ac skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036237.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036238.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036239.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036240.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036241.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036242.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036243.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036244.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036245.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036246.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036247.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036248.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036249.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036250.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036251.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036252.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036253.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036254.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036255.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036256.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036257.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036258.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036259.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP608\A0036260.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037391.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037392.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037393.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037395.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ir skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037397.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037398.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037399.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037400.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037401.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037402.dll Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037404.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP611\A0037405.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP613\A0037506.dll Infected: Trojan.Win32.BHO.g skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP613\A0037507.dll Infected: Packed.Win32.Klone.j skipped
C:\System Volume Information\_restore{429D30E1-2130-4270-A0B5-080F390EDFD0}\RP613\change.log Object is locked skipped
C:\VundoFix Backups\bevyedbs.dll.bad Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\VundoFix Backups\goyffimp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\kddimkuy.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\layayyoe.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ir skipped
C:\VundoFix Backups\mljkhii.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\VundoFix Backups\ncskkojp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\phlbddnu.dll.bad Infected: Trojan.Win32.BHO.g skipped
C:\VundoFix Backups\qblulewd.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\qnmhqjfl.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped
C:\VundoFix Backups\rqrpqpp.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\VundoFix Backups\rqrsqnn.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\VundoFix Backups\tycuhcvf.dll.bad Infected: Trojan-Spy.Win32.VBStat.h skipped
C:\VundoFix Backups\upqrtonq.dll.bad Infected: Packed.Win32.Klone.j skipped
C:\VundoFix Backups\xxyaxut.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.ib skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SYSTEM32\bfypkixi.dll Infected: Packed.Win32.Klone.j skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\SYSTEM32\mjuyqekv.dll Infected: Packed.Win32.Klone.j skipped
C:\WINDOWS\SYSTEM32\net.exe/data0003 Infected: Trojan-Downloader.Win32.Adload.jm skipped
C:\WINDOWS\SYSTEM32\net.exe NSIS: infected - 1 skipped
C:\WINDOWS\SYSTEM32\rczxbl.dll Infected: not-a-virus:AdWare.Win32.PurityScan.ak skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wnyqrjcd.dll Infected: not-a-virus:AdWare.Win32.BHO.v skipped
C:\WINDOWS\SYSTEM32\Ѕymantec\nоpdb.exe Infected: not-a-virus:AdWare.Win32.PurityScan.fn skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.