The new Combofix log:
ComboFix 08-05-27.4 - Dupong Irène 2008-05-31 8:30:50.2 -
FAT32x86
Endroit: C:\Documents and Settings\Dupong Irène\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dupong Irène\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!FILE ::
C:\WINDOWS\system32\cuialfdu.dll_old
C:\WINDOWS\system32\efcArpoP.dll_old
C:\WINDOWS\system32\htaqtpsk.dll_old
C:\WINDOWS\system32\ldknqvmv.dll_old
C:\WINDOWS\system32\ollabiwu.dll_old
C:\WINDOWS\system32\opnwqiaa.dll_old
C:\WINDOWS\system32\pgegxbnp.dll_old
C:\WINDOWS\system32\rhblfpam.dll_old
C:\WINDOWS\system32\rqRkKaBq.dll_old
C:\WINDOWS\system32\uhhpgomj.dll_old
C:\WINDOWS\system32\uncsawbq.dll_old
C:\WINDOWS\system32\upudsnbe.dll_old
C:\WINDOWS\system32\ussshwlu.dll_old
H:\LaunchU3.exe
H:\SETUP.EXE
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\b.exe
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\cuialfdu.dll_old
C:\WINDOWS\system32\efcArpoP.dll_old
C:\WINDOWS\system32\htaqtpsk.dll_old
C:\WINDOWS\system32\ollabiwu.dll_old
C:\WINDOWS\system32\pgegxbnp.dll_old
C:\WINDOWS\system32\rhblfpam.dll_old
C:\WINDOWS\system32\rqRkKaBq.dll_old
C:\WINDOWS\system32\uhhpgomj.dll_old
C:\WINDOWS\system32\upudsnbe.dll_old
C:\WINDOWS\system32\ussshwlu.dll_old
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-28 to 2008-05-31 ))))))))))))))))))))))))))))))))))))
.
2008-05-28 09:41 . 2007-03-17 18:11 675,840 -ra------ C:\WINDOWS\system32\hpowiax3.dll
2008-05-28 09:41 . 2007-03-17 18:11 569,344 -ra------ C:\WINDOWS\system32\hpotscl3.dll
2008-05-28 09:41 . 2007-03-17 18:11 303,104 -ra------ C:\WINDOWS\system32\hpovst10.dll
2008-05-28 09:38 . 2008-05-28 09:46 160,191 --a------ C:\WINDOWS\hpoins14.dat
2008-05-28 09:38 . 2007-09-20 03:14 2,000 --------- C:\WINDOWS\hpomdl14.dat
2008-05-28 09:36 . 2008-05-28 09:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-05-28 09:36 . 2007-03-30 17:07 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-05-28 09:35 . 2007-03-08 06:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-05-28 09:35 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\system32\hpzll5ha.dll
2008-05-28 01:24 . 2008-05-28 01:24 <REP> d-------- C:\Documents and Settings\Dupong IrÞne
2008-05-27 23:19 . 2008-05-27 23:19 <REP> d-------- C:\Program Files\Trend Micro
2008-05-24 23:19 . 2008-05-24 23:19 206 --a------ C:\WINDOWS\system32\MRT.INI
2008-05-18 15:04 . 2008-05-18 15:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-07 12:05 . 2008-05-28 01:49 854 --a------ C:\WINDOWS\wininit.ini
2008-05-04 18:08 . 2008-05-04 18:01 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-04 18:08 . 2008-05-04 18:08 2,552 --a------ C:\WINDOWS\unins000.dat
2008-05-03 12:04 . 2008-05-03 12:04 <REP> d-------- C:\WINDOWS\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 21:55 348,160 ----a-w C:\WINDOWS\system32\Msvcr71.dll
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 621,344 ------w C:\WINDOWS\system32\dllcache\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 04:51 194,144 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,376 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 16:28 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:57 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-29 08:56 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-26 12:00 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
2008-02-26 12:00 294,912 ------w C:\WINDOWS\system32\dllcache\msctf.dll
2008-02-22 10:00 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:35 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:35 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-05-23 10:35 324 ----a-w C:\Documents and Settings\Dupong Irène\Application Data\wklnhst.dat
2006-04-14 07:21 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
1999-07-07 00:00 6 --sh--r C:\WINDOWS\@
[email protected].
((((((((((((((((((((((((((((( snapshot@2008-05-28_ 1.24.08.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-27 23:21:08 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-30 17:09:46 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2005-04-13 13:54:22 331,184 ----a-w C:\WINDOWS\system32\difxapi.dll
+ 2007-03-08 04:20:46 309,760 ----a-r C:\WINDOWS\system32\difxapi.dll
- 2004-12-14 15:06:28 51,120 ----a-r C:\WINDOWS\system32\drivers\HPZid412.sys
+ 2007-03-08 04:20:48 49,920 ----a-r C:\WINDOWS\system32\drivers\HPZid412.sys
- 2004-12-14 15:06:28 16,496 ----a-r C:\WINDOWS\system32\drivers\HPZipr12.sys
+ 2007-03-08 04:20:50 16,496 ----a-r C:\WINDOWS\system32\drivers\HPZipr12.sys
- 2004-12-14 15:06:28 21,744 ----a-r C:\WINDOWS\system32\drivers\HPZius12.sys
+ 2007-03-08 04:20:50 21,568 ----a-r C:\WINDOWS\system32\drivers\HPZius12.sys
+ 2007-03-26 08:17:44 2,862,592 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpbcfgre.dll
+ 2006-11-30 09:14:06 671,816 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpcdmc32.dll
+ 2007-02-22 17:35:00 314,880 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpfie5ha.dll
+ 2007-02-20 09:29:02 337,920 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpfig5ha.dll
+ 2006-12-06 14:31:56 113,152 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpfrs5ha.dll
+ 2007-03-28 10:53:28 977,920 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpz3c5ha.dll
+ 2007-03-28 12:01:08 1,739,264 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpz3r5ha.dll
+ 2007-03-28 12:01:28 233,472 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzc35ha.dll
+ 2007-03-28 11:59:04 446,976 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzev5ha.dll
+ 2007-03-30 15:07:42 267,864 ----a-r C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzids01.dll
+ 2007-03-28 12:00:22 5,189,120 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzla5ha.dll
+ 2007-03-28 11:57:04 782,848 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzle5ha.dll
+ 2007-03-28 12:01:18 117,760 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzll5ha.dll
+ 2007-03-28 11:57:34 274,944 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzpp5ha.dll
+ 2007-03-28 11:59:20 299,520 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzpr5ha.dll
+ 2007-03-28 11:57:18 853,504 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzse5ha.dll
+ 2007-03-28 11:32:56 670,208 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzss5ha.dll
+ 2007-03-28 10:52:24 8,602,112 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzst5ha.dll
+ 2007-03-28 11:58:06 3,291,648 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzui5ha.dll
+ 2007-03-28 10:53:22 3,419,648 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\hpzur5ha.dll
+ 2006-12-20 10:50:04 269,824 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\UNIDRV.dll
+ 2006-12-20 10:48:34 208,384 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\UNIDRVUI.dll
+ 2006-12-20 10:48:32 620,544 ----a-w C:\WINDOWS\system32\DRVSTORE\hpodcsla_AA90739FE6CE6410E6FD075E7696EADED8A3F90D\UNIRES.dll
+ 2007-03-08 04:20:46 309,760 ----a-r C:\WINDOWS\system32\DRVSTORE\hposcu10_4FC8229DA1D7F81E72322B6F2DBB249746ABAFD7\drivers\dot4\Win2000\difxapi.dll
+ 2007-03-08 04:20:46 364,544 ----a-r C:\WINDOWS\system32\DRVSTORE\hposcu10_4FC8229DA1D7F81E72322B6F2DBB249746ABAFD7\drivers\dot4\Win2000\hppldcoi.dll
+ 2007-03-17 16:11:12 229,376 ----a-r C:\WINDOWS\system32\DRVSTORE\hposcu10_4FC8229DA1D7F81E72322B6F2DBB249746ABAFD7\drivers\scanner\x32\hpotpusd.dll
+ 2007-03-17 16:11:12 569,344 ----a-r C:\WINDOWS\system32\DRVSTORE\hposcu10_4FC8229DA1D7F81E72322B6F2DBB249746ABAFD7\drivers\scanner\x32\hpotscl3.dll
+ 2007-03-17 16:11:14 303,104 ----a-r C:\WINDOWS\system32\DRVSTORE\hposcu10_4FC8229DA1D7F81E72322B6F2DBB249746ABAFD7\drivers\scanner\x32\hpovst10.dll
+ 2007-03-17 16:11:14 675,840 ----a-r C:\WINDOWS\system32\DRVSTORE\hposcu10_4FC8229DA1D7F81E72322B6F2DBB249746ABAFD7\drivers\scanner\x32\hpowiax3.dll
+ 2007-03-08 04:20:48 49,920 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzid413_F75AD070CF6AC37359152FFE52115AEC89378C94\drivers\dot4\Win2000\HPZid412.sys
+ 2007-03-08 04:20:46 309,760 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipa13_DB40AE39DB38AD8D2AF2D8E4340ABA1C191DE2CE\drivers\dot4\Win2000\difxapi.dll
+ 2007-03-08 04:20:46 364,544 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipa13_DB40AE39DB38AD8D2AF2D8E4340ABA1C191DE2CE\drivers\dot4\Win2000\hppldcoi.dll
+ 2007-03-08 04:20:48 49,920 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipa13_DB40AE39DB38AD8D2AF2D8E4340ABA1C191DE2CE\drivers\dot4\Win2000\HPZid412.sys
+ 2007-03-08 04:20:50 16,496 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipa13_DB40AE39DB38AD8D2AF2D8E4340ABA1C191DE2CE\drivers\dot4\Win2000\HPzipr12.sys
+ 2007-03-08 04:20:50 21,568 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipa13_DB40AE39DB38AD8D2AF2D8E4340ABA1C191DE2CE\drivers\dot4\Win2000\HPZius12.sys
+ 2007-03-08 04:20:38 282,624 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipa13_DB40AE39DB38AD8D2AF2D8E4340ABA1C191DE2CE\HPZc3212.dll
+ 2007-03-08 04:20:50 16,496 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzipr13_9B62D8E7E43E761D5D4A9F1967C0FC868E8BC390\drivers\dot4\Win2000\HPZipr12.sys
+ 2007-03-08 04:20:46 309,760 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\drivers\dot4\Win2000\difxapi.dll
+ 2007-03-08 04:20:46 364,544 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\drivers\dot4\Win2000\hppldcoi.dll
+ 2007-03-08 04:20:48 49,920 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\drivers\dot4\Win2000\hpzid412.sys
+ 2007-03-08 04:20:50 16,496 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\drivers\dot4\Win2000\hpzipr12.sys
+ 2007-03-08 04:20:50 21,568 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\drivers\dot4\Win2000\HPZius12.sys
+ 2007-03-08 04:20:52 16,800 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\drivers\dot4\WinxP\Hppaufd0.sys
+ 2007-03-08 04:20:38 282,624 ----a-r C:\WINDOWS\system32\DRVSTORE\hpzius13_9B9B07948B5298EA9F9D379B539EC8677D74FF6B\HPZc3212.dll
- 2004-09-29 10:12:48 278,584 ----a-w C:\WINDOWS\system32\HPZidr12.dll
+ 2006-11-08 14:35:38 49,152 ----a-w C:\WINDOWS\system32\HPZidr12.dll
+ 2006-11-08 14:35:36 43,520 ----a-w C:\WINDOWS\system32\HPZinw12.dll
+ 2006-11-08 14:35:38 53,248 ----a-w C:\WINDOWS\system32\HPZipm12.dll
- 2004-09-29 10:15:16 204,800 ----a-w C:\WINDOWS\system32\HPZipr12.dll
+ 2006-11-08 14:35:40 33,280 ----a-w C:\WINDOWS\system32\HPZipr12.dll
- 2004-09-29 10:09:26 94,208 ----a-w C:\WINDOWS\system32\HPZipt12.dll
+ 2006-11-08 14:35:40 29,696 ----a-w C:\WINDOWS\system32\HPZipt12.dll
- 2004-09-29 10:09:32 57,344 ----a-w C:\WINDOWS\system32\HPZisn12.dll
+ 2006-11-08 14:35:40 20,480 ----a-w C:\WINDOWS\system32\HPZisn12.dll
+ 2007-03-26 08:17:44 2,862,592 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpbcfgre.dll
+ 2006-11-30 09:14:06 671,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpcdmc32.dll
+ 2007-02-22 17:35:00 314,880 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpfie5ha.dll
+ 2007-02-20 09:29:02 337,920 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpfig5ha.dll
+ 2006-12-06 14:31:56 113,152 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpfrs5ha.dll
+ 2007-03-28 10:53:28 977,920 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpz3c5ha.dll
+ 2007-03-28 12:01:08 1,739,264 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpz3r5ha.dll
+ 2007-03-28 12:01:28 233,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzc35ha.dll
+ 2007-03-28 11:59:04 446,976 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzev5ha.dll
+ 2007-03-28 12:00:22 5,189,120 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzla5ha.dll
+ 2007-03-28 11:57:04 782,848 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzle5ha.dll
+ 2007-03-28 11:59:20 299,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpr5ha.dll
+ 2007-03-28 11:57:18 853,504 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzse5ha.dll
+ 2007-03-28 11:32:56 670,208 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzss5ha.dll
+ 2007-03-28 10:52:24 8,602,112 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzst5ha.dll
+ 2007-03-28 11:58:06 3,291,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzui5ha.dll
+ 2007-03-28 10:53:22 3,419,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzur5ha.dll
+ 2007-03-26 08:17:44 2,862,592 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpbcfgre.dll
+ 2006-11-30 09:14:06 671,816 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpcdmc32.dll
+ 2007-02-22 17:35:00 314,880 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpfie5ha.dll
+ 2007-02-20 09:29:02 337,920 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpfig5ha.dll
+ 2006-12-06 14:31:56 113,152 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpfrs5ha.dll
+ 2007-03-28 10:53:28 977,920 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpz3c5ha.dll
+ 2007-03-28 12:01:08 1,739,264 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpz3r5ha.dll
+ 2007-03-28 12:01:28 233,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzc35ha.dll
+ 2007-03-28 11:59:04 446,976 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzev5ha.dll
+ 2007-03-28 12:00:22 5,189,120 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzla5ha.dll
+ 2007-03-28 11:57:04 782,848 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzle5ha.dll
+ 2007-03-28 11:59:20 299,520 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzpr5ha.dll
+ 2007-03-28 11:57:18 853,504 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzse5ha.dll
+ 2007-03-28 11:32:56 670,208 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzss5ha.dll
+ 2007-03-28 10:52:24 8,602,112 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzst5ha.dll
+ 2007-03-28 11:58:06 3,291,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzui5ha.dll
+ 2007-03-28 10:53:22 3,419,648 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\hpzur5ha.dll
+ 2006-12-20 10:50:04 269,824 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\UNIDRV.DLL
+ 2006-12-20 10:48:34 208,384 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\UNIDRVUI.DLL
+ 2006-12-20 10:48:32 620,544 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\hpdeskjet_f4100_seri8252\UNIRES.DLL
+ 2007-03-28 11:57:34 274,944 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
+ 2007-03-12 01:35:12 12,288 ----a-r C:\WINDOWS\Twunk_16.dll
+ 2007-03-12 01:35:12 12,288 ----a-r C:\WINDOWS\Twunk_32.dll
+ 2008-05-28 07:44:36 1,230,336 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
+ 2007-03-08 18:38:58 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_6e85597b\ATL80.dll
+ 2007-06-27 21:16:00 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcm80.dll
+ 2007-06-27 21:16:02 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcp80.dll
+ 2007-06-27 21:16:00 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcr80.dll
+ 2007-03-08 18:38:58 1,093,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfc80.dll
+ 2007-03-08 18:38:58 1,079,808 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfc80u.dll
+ 2007-03-08 18:38:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfcm80.dll
+ 2007-03-08 18:38:58 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_decbdf0c\mfcm80u.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51C325F2-00A5-45B2-BB69-E2863E8279E4}]
C:\WINDOWS\system32\efcArpoP.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8BAC0033-AF00-4694-B0CC-169777C79C9B}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDF2660A-891F-41F6-85C4-5D8440218114}]
C:\WINDOWS\system32\rqRkKaBq.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"Acmw"="C:\DOCUME~1\DUPONG~1\MESDOC~1\DOBE~1\dexplore.exe" [ ]
"ares"="C:\Program Files\Ares\Ares.exe" [ ]
"VoipStunt"="C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2005-06-16 15:48 86016]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-12-22 01:23 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-12-22 01:23 688218]
"Zshutdown"="c:\sysprep\patch\sysprep.cmd" [ ]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-05-31 22:46 401408]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-06-03 01:31 385024]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2005-05-31 22:50 356352]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-09-23 07:27 7286784]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2003-11-10 17:06 406016]
"Pinnacle WebUpdater"="C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" [2006-03-26 12:10 380928]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 02:36 81920]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-05-02 20:24 180269]
"StandardInstall"="" []
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-15 00:22 35328]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 22:46 624248]
"isCfgWiz"="C:\Program Files\Fichiers communs\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SYMCUW.exe" [ ]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [ ]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [ ]
"e8c34cf4"="C:\WINDOWS\system32\fwrcsjpf.dll" [ ]
"BMebf07f68"="C:\WINDOWS\system32\jbmlindy.dll" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SymLnch"="C:\Documents and Settings\Dupong Irène\Application Data\Symantec\Layouts\Norton Internet Security\15.0\SymAllLanguages\NIS_RETAIL\20070828\Support\SymLnch\SymLnch.exe" [2007-08-27 02:04 687976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
C:\Documents and Settings\Dupong IrŠne\Menu D‚marrer\Programmes\D‚marrage\
Raccourci vers YzDock.lnk - C:\Program Files\yz_dck0083\YzDock.exe [2003-06-03 22:38:40 386560]
C:\Documents and Settings\Dupong IrŠne\Menu D‚marrer\Programmes\D‚marrage\
Raccourci vers YzDock.lnk - C:\Program Files\yz_dck0083\YzDock.exe [2003-06-03 22:38:40 386560]
C:\Documents and Settings\Dupong IrŠne\Menu D‚marrer\Programmes\D‚marrage\
Raccourci vers YzDock.lnk - C:\Program Files\yz_dck0083\YzDock.exe [2003-06-03 22:38:40 386560]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
TabUserW.exe.lnk - C:\WINDOWS\system32\Wtablet\TabUserW.exe [2003-12-04 18:48:40 77824]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-11-17 19:53:32 688128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
"NoBandCustomize"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cbXnnkiG]
cbXnnkiG.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2005-05-31 22:46 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winopn32]
winopn32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HControl]
--a------ 2005-07-28 09:29 102400 C:\WINDOWS\ATK0100\HControl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2004-09-13 15:49 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NB Probe]
--a------ 2005-07-27 17:07 765952 C:\Program Files\ASUS\NB Probe\NBProbe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCRemote]
--------- 2006-04-27 15:45 94208 C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCS]
--------- 2006-04-27 15:47 65536 C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-05-15 00:22 35328 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wireless Console]
--a------ 2005-07-22 14:36 57344 C:\Program Files\ASUS\Wireless Console\wcourier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"16586:TCP"= 16586:TCP:NortonAV
"14063:TCP"= 14063:TCP:NortonAV
R0 R592;R592;C:\WINDOWS\system32\DRIVERS\R592.sys [2004-10-15 19:26]
R0 risdpntk;risdpntk;C:\WINDOWS\system32\DRIVERS\risdpntk.sys [2004-10-15 19:26]
S3 Asushwio;Asushwio;C:\WINDOWS\system32\drivers\Asushwio.sys [2000-03-29 14:17]
S3 USB28xxBGA;Pinnacle PCTV DVB-T USB Stick;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2005-11-22 19:04]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2005-11-22 19:04]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 14:00]
S3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-09 13:48:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-31 08:33:35
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-31 8:34:05
ComboFix-quarantined-files.txt 2008-05-31 06:34:04
ComboFix2.txt 2008-05-27 23:24:34
Pre-Run: 13,709,246,464 octets libres
Post-Run: 13,701,939,200 octets libres
347 --- E O F --- 2008-05-29 20:51:26
And here is the kaspersky log:
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 31, 2008 10:11:20 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 816364
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 73299
Number of viruses found: 32
Number of infected objects: 156
Number of suspicious objects: 0
Duration of the scan process: 00:52:14
Infected Object Name / Virus Name / Last Action
C:\QooBox\Quarantine\C\WINDOWS\system32\components\flx1.dll.vir Infected: not-virus:Hoax.Win32.Renos.fh skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\djqixldq.dll.vir Infected: Trojan.Win32.KillAV.rf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\scdrmfbd.dll.vir Infected: Trojan.Win32.KillAV.rf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ddhhdwdp.dll.vir Infected: Trojan.Win32.KillAV.rf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ctcnpenw.dll.vir Infected: Trojan.Win32.Monder.gz skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ejhexlyu.dll.vir Infected: Trojan.Win32.Monder.ij skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\gqkmccqf.dll.vir Infected: Trojan.Win32.Monder.kf skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\nmiujuvd.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.tsp skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\werrrtul.dll.vir Infected: Trojan.Win32.Monder.dj skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\cuialfdu.dll_old.vir Infected: Trojan.Win32.Monder.ik skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\efcArpoP.dll_old.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\htaqtpsk.dll_old.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\pgegxbnp.dll_old.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rhblfpam.dll_old.vir Infected: Trojan.Win32.Monder.ik skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\rqRkKaBq.dll_old.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.trr skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\uhhpgomj.dll_old.vir Infected: Trojan.Win32.Monder.di skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\upudsnbe.dll_old.vir Infected: Trojan.Win32.Monder.dl skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\ussshwlu.dll_old.vir Infected: Trojan.Win32.Monder.gen skipped
C:\QooBox\Quarantine\C\WINDOWS\AdobeR.exe.vir Infected: Worm.Win32.RJump.a skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{B1C5E8C3-8293-4C44-B41B-C6AAA393A5D9}.bin Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip/opnwqiaa.dll Infected: Trojan.Win32.Monder.cz skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip/ldknqvmv.dll Infected: Trojan.Win32.Monder.cy skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip/yueoaxlf.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll2.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip/uncsawbq.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll3.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll4.zip/pgegxbnp.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll4.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip/ecpvussk.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll5.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip/nrdhxble.dll Infected: Trojan.Win32.Monder.de skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll6.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll7.zip/htaqtpsk.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll7.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll8.zip/ndxjmsne.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll8.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll9.zip/qywswshg.dll Infected: Trojan.Win32.Monder.df skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll9.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll10.zip/upudsnbe.dll Infected: Trojan.Win32.Monder.dl skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll10.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll11.zip/qkovacsk.dll Infected: Trojan.Win32.Monder.dm skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll11.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll12.zip/strltgbb.dll Infected: Trojan.Win32.Monder.dk skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll12.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll13.zip/efcArpoP.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll13.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll14.zip/cuialfdu.dll Infected: Trojan.Win32.Monder.ik skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll14.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll15.zip/navqvbae.dll Infected: Trojan.Win32.Monder.ij skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll15.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll16.zip/rhblfpam.dll Infected: Trojan.Win32.Monder.ik skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll16.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll17.zip/rqRkKaBq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.trr skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll17.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll18.zip/opnwqiaa.dll_old Infected: Trojan.Win32.Monder.cz skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll18.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll22.zip/opnwqiaa.dll_old Infected: Trojan.Win32.Monder.cz skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll22.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll23.zip/ldknqvmv.dll_old Infected: Trojan.Win32.Monder.cy skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll23.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll24.zip/uncsawbq.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll24.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll25.zip/ussshwlu.dll_old Infected: Trojan.Win32.Monder.gen skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondedll25.zip ZIP: infected - 1 skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dupong Irène\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Dupong Irène\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Historique\History.IE5\MSHist012008053120080601\index.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Dupong Irène\Local Settings\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Dupong Irène\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\history.dat Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\cert8.db Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\key3.db Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\parent.lock Object is locked skipped
C:\Documents and Settings\Dupong Irène\Application Data\Mozilla\Firefox\Profiles\1wfjxx3j.default\formhistory.dat Object is locked skipped
C:\Program Files\Morpheus\morpheustoolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037275.dll Infected: not-virus:Hoax.Win32.Renos.fh skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037276.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037277.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037278.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037279.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037280.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037281.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037282.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037283.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037284.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037285.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037286.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037287.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037288.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037289.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037290.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037291.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037292.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037293.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037294.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037295.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037296.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037297.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037298.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037299.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037300.exe Infected: Trojan.Win32.Dialer.qn skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037301.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037302.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037303.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037304.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037305.exe Infected: Packed.Win32.Klone.g skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037306.exe Infected: not-virus:Hoax.Win32.Renos.fh skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037307.dll Infected: not-virus:Hoax.Win32.Renos.fh skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037308.dll Infected: Trojan-Downloader.Win32.Zlob.ant skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037309.exe Infected: Trojan-Downloader.Win32.Zlob.yt skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037310.exe Infected: Trojan-Downloader.Win32.Zlob.apm skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037312.exe Infected: Backdoor.Win32.IRCBot.dd skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037313.dll Infected: not-virus:Hoax.Win32.Renos.fh skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037314.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037315.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037316.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037317.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037318.exe Infected: Email-Worm.Win32.Rays skipped
C:\System Volume Information\_restore{596A3259-756B-4151-94C2-1D02782CCCAA}\RP411\A0037319.exe Infe