Répondre à la discussion
Affichage des résultats 1 à 4 sur 4

Virus Win32 Qandr [Rtk]



  1. #1
    DamienJuss

    Virus Win32 Qandr [Rtk]


    ------

    Bonjour,
    Je viens, à mon plus grand malheur, de contracter le virus WIN32 Qandr RTK sur mon ordinateur. J'ai suivi la procédure que vous indiquez mais je n'obtiens pas le fichier info, pas plus que je peux enregistrer le fichier log sous format txt ou format word. donc je m'excuse par avance pour le flood mais je vais le coller ici.

    Mes connaissances en info sont relativement limités donc si vous m'aidez, pouvez-vous le faire en m'indiquant avec précision les étapes. Je vais essayer de changer d'antivirus (passer de avast à antiVir ce soir, je verrais si ça fait qqc).

    Concernant des infos sur mon pc (je suppose que le fichier info renseigne là-dessus): Sony Vaio, Vista.

    Voilà, je travaille actuellement à Haïti et mon PC est mon outil de travail quotidien, j'en ai grand besoin! Merci d'avance pour toute l'aide que vous pourrez m'apporter.


    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Damien at 2010-04-23 17:10:55
    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
    System drive C: has 83 GB (28%) free of 295 GB
    Total RAM: 3038 MB (41% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:11:05, on 23/04/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v7.00 (7.00.6002.18005)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\sony\ISB Utility\ISBMgr.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\sony\Marketing Tools\MarketingTools.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor. exe
    C:\Program Files\sony\Network Utility\LANUtil.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Windows\system32\taskeng.ex e
    C:\Windows\system32\taskeng.ex e
    C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
    C:\Program Files\Apoint\ApMsgFwd.exe
    C:\Program Files\Apoint\Apvfb.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\skypePM.exe
    C:\Windows\System32\cmd.exe
    C:\Users\Damien\AppData\Local\ Temp\eacvjgey.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
    C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
    C:\Users\Damien\Desktop\RSIT.e xe
    C:\Program Files\trend micro\Damien.exe

    R1 - HKLM\Software\Microsoft\Intern et Explorer\Main,Default_Search_U RL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Intern et Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Intern et Explorer\Search,SearchAssistan t =
    R0 - HKLM\Software\Microsoft\Intern et Explorer\Search,CustomizeSearc h =
    R0 - HKCU\Software\Microsoft\Intern et Explorer\Toolbar,LinksFolderNa me =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\Ac roIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExt ensions.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVC pl.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\as hDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMSe rver /watchfiles startup
    O4 - HKLM\..\Run: [NokiaMusic FastStart] "C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe" /command:faststart
    O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel .exe
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor. exe"
    O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
    O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    O4 - HKCU\..\Run: [NortonOnlineBackupReminder] "C:\Program Files\Symantec\Norton Online Backup\Activation\NobuActivati on.exe" UNATTENDED
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: Bluetooth.lnk = ?
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.sc r/200
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\ EXCEL.EXE/3000
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\ REFIEBAR.DLL
    O9 - Extra button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O13 - Gopher Prefix:
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemSe rvices.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKY PE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GO EC62~1.DLL
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceS ervice.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.e xe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.ex e
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
    O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.ex e
    O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpda te.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.e xe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviReg Mgr.exe
    O23 - Service: NSUService - Sony Corporation - C:\Program Files\sony\Network Utility\NSUService.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\Reg Srvc.exe
    O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAud ioService.exe
    O23 - Service: ServiceLayer - Nokia - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: VAIO Media plus Content Importer (SOHCImp) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe
    O23 - Service: VAIO Media plus Database Manager (SOHDBSvr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe
    O23 - Service: VAIO Media plus Digital Media Server (SOHDms) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe
    O23 - Service: VAIO Media plus Device Searcher (SOHDs) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe
    O23 - Service: VAIO Media plus Playlist Manager (SOHPlMgr) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe
    O23 - Service: SpyHunter 4 Service - Enigma Software Group USA, LLC. - C:\PROGRA~1\ENIGMA~1\SPYHUN~1\ SH4SER~1.EXE
    O23 - Service: CamMonitor (uCamMonitor) - ArcSoft, Inc. - C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceMan ager\VzHardwareResourceManager \VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Power Management - Sony Corporation - C:\Program Files\Sony\VAIO Power Management\SPMService.exe
    O23 - Service: VAIO Content Folder Watcher (VCFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.e xe
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xa udio.exe

    -----

  2. Publicité
  3. #2
    DamienJuss

    Re : Virus Win32 Qandr [Rtk]

    End of file - 11170 bytes

    ======Scheduled tasks folder======

    C:\Windows\tasks\GoogleUpdateT askMachineCore.job
    C:\Windows\tasks\GoogleUpdateT askMachineUA.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\Ac roIEHelperShim.dll [2008-06-11 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
    Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExt ensions.dll [2009-02-12 2217848]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows\CurrentVersion \Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-03-09 41760]

    [HKEY_LOCAL_MACHINE\Software\Mi crosoft\Windows\CurrentVersion \Run]
    "Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-20 1008184]
    "RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVC pl.exe [2009-01-05 6703648]
    "Apoint"=C:\Program Files\Apoint\Apoint.exe [2009-04-13 155648]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-12-02 35184]
    "ISBMgr.exe"=C:\Program Files\Sony\ISB Utility\ISBMgr.exe [2008-12-18 317288]
    "StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-02-10 61440]
    "Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-06-17 30192]
    "MarketingTools"=C:\Progra m Files\Sony\Marketing Tools\MarketingTools.exe [2009-06-17 26624]
    "avast!"=C:\PROGRA~1\ALWILS~1\ Avast4\ashDisp.exe [2009-11-24 81000]
    "SunJavaUpdateSched"=C:\Progra m Files\Common Files\Java\Java Update\jusched.exe [2010-02-18 248040]
    "QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-11-10 417792]
    "NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMSe rver /watchfiles startup []
    "NokiaMusic FastStart"=C:\Program Files\Nokia\Ovi Player\NokiaOviPlayer.exe [2009-11-06 2090272]
    "Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel .exe [2009-01-05 1833504]
    "GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor. exe [2008-10-25 31072]

    [HKEY_CURRENT_USER\Software\Mic rosoft\Windows\CurrentVersion\ Run]
    "NSUFloatingUI"=C:\Program Files\Sony\Network Utility\LANUtil.exe [2008-12-21 274432]
    "DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
    "NortonOnlineBackupReminder"=C :\Program Files\Symantec\Norton Online Backup\Activation\NobuActivati on.exe [2009-01-16 503976]

    C:\ProgramData\Microsoft\Windo ws\Start Menu\Programs\Startup
    Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLS"="C:\PROGRA~1\Go ogle\GOOGLE~1\GOEC62~1.DLL"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows NT\CurrentVersion\Winlogon\Not ify\igfxcui]
    igfxdev.dll []

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows NT\CurrentVersion\Winlogon\Not ify\VESWinlogon]
    C:\Windows\system32\VESWinlogo n.dll [2009-01-19 98304]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Mi crosoft\Windows\CurrentVersion \Explorer\ShellExecuteHooks]
    "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExt ensions.dll [2009-02-12 2217848]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \Minimal\mcmscsvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \Minimal\MCODS]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\mcmscsvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\MCODS]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\MpfService]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\WudfPf]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\WudfRd]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\WudfSvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\Curr entControlSet\Control\SafeBoot \network\WudfUsbccidDriver]

    [HKEY_LOCAL_MACHINE\Software\Mi crosoft\Windows\CurrentVersion \Policies\System]
    "dontdisplaylastusername"= 0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1
    "EnableUIADesktopToggle"=0

    [HKEY_LOCAL_MACHINE\Software\Mi crosoft\Windows\CurrentVersion \Policies\explorer]
    "BindDirectlyToPropertySetStor age"=

    [HKEY_LOCAL_MACHINE\system\curr entcontrolset\services\shareda ccess\parameters\firewallpolic y\standardprofile\authorizedap plications\list]

    [HKEY_LOCAL_MACHINE\system\curr entcontrolset\services\shareda ccess\parameters\firewallpolic y\domainprofile\authorizedappl ications\list]

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{553102b 8-e30d-11de-9a67-002433d3b476}]
    shell\AutoRun\command - H:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{6b2e8fb 1-430e-11df-9b54-001dbaf57153}]
    shell\AutoRun\command - I:\IVANA/danilovic.exe
    shell\open\command - I:\IVANA/danilovic.exe

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{6b2e8fb 4-430e-11df-9b54-001dbaf57153}]
    shell\AutoRun\command - H:\LaunchU3.exe -a

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{7bbf6fb 9-4a97-11df-a307-001dbaf57153}]
    shell\AutoRun\command - "I:\WD SmartWare.exe" autoplay=true

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{92cbac6 0-bf1c-11de-a339-001dbaf57153}]
    shell\AutoRun\command - C:\Windows\system32\RunDLL32.E XE Shell32.DLL,ShellExec_RunDLL wscript.exe WIN31.dll.vbs

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{a44db7e e-4379-11df-9762-002433d3b476}]
    shell\AutoRun\command - H:\AUTORUN.EXE

    [HKEY_CURRENT_USER\software\mic rosoft\windows\currentversion\ explorer\mountpoints2\{d713a5d 0-b807-11de-87b8-002433d3b476}]
    shell\AutoRun\command - H:\tmp.folder/restore.exe
    shell\ExploRE\command - H:\tmp.folder/restore.exe
    shell\OPeN\command - H:\tmp.folder/restore.exe


    ======List of files/folders created in the last 1 months======

    2010-04-23 16:33:09 ----D---- C:\sh4ldr
    2010-04-23 16:33:09 ----D---- C:\Program Files\Enigma Software Group
    2010-04-23 16:31:56 ----D---- C:\Windows\61D3AAE1D5214CD7939 B37813DE8F955.TMP
    2010-04-23 16:31:50 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2010-04-23 16:31:17 ----D---- C:\Program Files\trend micro
    2010-04-23 16:31:15 ----D---- C:\rsit
    2010-04-21 16:03:46 ----D---- C:\Users\Damien\AppData\Roamin g\Intel
    2010-04-20 07:49:57 ----D---- C:\Program Files\Common Files\Skype
    2010-04-14 15:20:45 ----A---- C:\Windows\system32\iphlpsvc.d ll
    2010-04-14 14:27:57 ----A---- C:\Windows\system32\ntoskrnl.e xe
    2010-04-14 14:27:57 ----A---- C:\Windows\system32\ntkrnlpa.e xe
    2010-04-14 14:26:40 ----A---- C:\Windows\system32\vbscript.d ll
    2010-04-14 12:45:51 ----A---- C:\Windows\system32\wintrust.d ll
    2010-04-14 12:45:47 ----A---- C:\Windows\system32\cabview.dl l
    2010-04-09 16:24:47 ----A---- C:\Windows\system32\MSPGIMME.D LL
    2010-04-09 16:24:47 ----A---- C:\Windows\system32\MSPCORE.DL L
    2010-04-09 16:24:47 ----A---- C:\Windows\system32\MDIVWCTL.D LL
    2010-04-09 16:24:47 ----A---- C:\Windows\system32\ijl11.dll
    2010-04-09 16:24:46 ----D---- C:\Program Files\MDIConvertor
    2010-04-08 20:56:44 ----D---- C:\Program Files\PC Manager
    2010-04-02 09:07:27 ----D---- C:\ProgramData\Sun
    2010-04-02 09:07:26 ----D---- C:\Program Files\Common Files\Java
    2010-04-02 09:07:05 ----A---- C:\Windows\system32\javaws.exe
    2010-04-02 09:07:05 ----A---- C:\Windows\system32\javaw.exe
    2010-04-02 09:07:05 ----A---- C:\Windows\system32\java.exe
    2010-03-31 19:59:24 ----D---- C:\Program Files\Windows Portable Devices
    2010-03-31 13:43:55 ----D---- C:\Program Files\Microsoft Visual Studio
    2010-03-31 13:37:47 ----D---- C:\Program Files\Microsoft Visual Studio 8
    2010-03-31 07:43:58 ----A---- C:\Windows\system32\UIAnimatio n.dll
    2010-03-31 07:43:57 ----A---- C:\Windows\system32\UIRibbonRe s.dll
    2010-03-31 07:43:57 ----A---- C:\Windows\system32\UIRibbon.d ll
    2010-03-31 07:43:26 ----A---- C:\Windows\system32\WMPhoto.dl l
    2010-03-31 07:43:25 ----A---- C:\Windows\system32\cdd.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\XpsRasterS ervice.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\XpsGdiConv erter.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\WindowsCod ecsExt.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\WindowsCod ecs.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\printfilte rpipelinesvc.exe
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\printfilte rpipelineprxy.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\PhotoMetad ataHandler.dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\dxdiagn.dl l
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\dxdiag.exe
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\d3d10warp. dll
    2010-03-31 07:43:24 ----A---- C:\Windows\system32\d2d1.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\xpsservice s.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\XpsPrint.d ll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\OpcService s.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\FntCache.d ll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\dxgi.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\DWrite.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\d3d11.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\d3d10level 9.dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\d3d10core. dll
    2010-03-31 07:43:23 ----A---- C:\Windows\system32\d3d10_1cor e.dll
    2010-03-31 07:43:22 ----A---- C:\Windows\system32\d3d10_1.dl l
    2010-03-31 07:43:22 ----A---- C:\Windows\system32\d3d10.dll
    2010-03-31 07:42:49 ----A---- C:\Windows\system32\WPDShextAu toplay.exe
    2010-03-31 07:42:49 ----A---- C:\Windows\system32\wpdbusenum .dll
    2010-03-31 07:42:49 ----A---- C:\Windows\system32\BthMtpCont extHandler.dll
    2010-03-31 07:42:34 ----A---- C:\Windows\system32\PortableDe viceConnectApi.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\WPDSp.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\WPDShServi ceObj.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\wpdshext.d ll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\WpdMtpUS.d ll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\WpdMtp.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\WpdConns.d ll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\wpd_ci.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\PortableDe viceWMDRM.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\PortableDe viceTypes.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\PortableDe viceClassExtension.dll
    2010-03-31 07:42:31 ----A---- C:\Windows\system32\PortableDe viceApi.dll
    2010-03-31 07:41:29 ----A---- C:\Windows\system32\oleaccrc.d ll
    2010-03-31 07:41:29 ----A---- C:\Windows\system32\oleacc.dll
    2010-03-31 07:41:28 ----A---- C:\Windows\system32\UIAutomati onCore.dll
    2010-03-30 18:48:48 ----A---- C:\Windows\system32\mshtml.dll
    2010-03-30 18:48:47 ----A---- C:\Windows\system32\wininet.dl l
    2010-03-30 18:48:46 ----A---- C:\Windows\system32\urlmon.dll
    2010-03-30 18:48:45 ----A---- C:\Windows\system32\ieframe.dl l
    2010-03-30 18:48:42 ----A---- C:\Windows\system32\mshtmled.d ll
    2010-03-30 18:48:42 ----A---- C:\Windows\system32\ieui.dll
    2010-03-30 18:48:41 ----A---- C:\Windows\system32\iepeers.dl l
    2010-03-30 18:48:41 ----A---- C:\Windows\system32\ieencode.d ll
    2010-03-30 18:48:39 ----A---- C:\Windows\system32\ieapfltr.d ll
    2010-03-30 18:45:39 ----A---- C:\Windows\system32\gameux.dll
    2010-03-30 18:45:38 ----A---- C:\Windows\system32\Apphlpdm.d ll
    2010-03-30 18:45:37 ----A---- C:\Windows\system32\GameUXLega cyGDFs.dll
    2010-03-29 15:35:43 ----D---- C:\Windows\system32\eu-ES
    2010-03-29 15:35:43 ----D---- C:\Windows\system32\ca-ES
    2010-03-29 15:35:42 ----D---- C:\Windows\system32\vi-VN
    2010-03-29 15:13:17 ----D---- C:\Windows\system32\EventProvi ders
    2010-03-29 12:44:03 ----D---- C:\ProgramData\Office Genuine Advantage

  4. #3
    DamienJuss

    Re : Virus Win32 Qandr [Rtk]

    ======List of files/folders modified in the last 1 months======

    2010-04-23 17:11:02 ----D---- C:\Windows\Temp
    2010-04-23 17:11:02 ----D---- C:\Windows\Prefetch
    2010-04-23 17:09:32 ----D---- C:\Windows\System32
    2010-04-23 17:09:32 ----A---- C:\Windows\system32\PerfString Backup.INI
    2010-04-23 17:09:31 ----D---- C:\Windows\inf
    2010-04-23 16:52:11 ----D---- C:\bureau
    2010-04-23 16:40:49 ----D---- C:\Users\Damien\AppData\Roamin g\Skype
    2010-04-23 16:33:26 ----SHD---- C:\Windows\Installer
    2010-04-23 16:33:20 ----D---- C:\Windows\system32\Tasks
    2010-04-23 16:33:09 ----RD---- C:\Program Files
    2010-04-23 16:32:24 ----SHD---- C:\System Volume Information
    2010-04-23 16:31:56 ----D---- C:\Windows
    2010-04-23 16:31:50 ----D---- C:\Program Files\Common Files
    2010-04-23 16:03:06 ----D---- C:\Users\Damien\AppData\Roamin g\skypePM
    2010-04-23 15:53:14 ----D---- C:\Windows\system32\drivers
    2010-04-22 21:33:52 ----D---- C:\Users\Damien\AppData\Roamin g\vlc
    2010-04-19 07:57:39 ----D---- C:\Users\Damien\AppData\Roamin g\U3
    2010-04-18 13:58:59 ----D---- C:\Users\Damien\AppData\Roamin g\dvdcss
    2010-04-15 13:14:52 ----D---- C:\Windows\winsxs
    2010-04-15 13:04:39 ----D---- C:\Windows\system32\catroot
    2010-04-15 13:01:35 ----D---- C:\Program Files\Windows Mail
    2010-04-15 12:57:15 ----D---- C:\Users\Damien\AppData\Roamin g\Winamp
    2010-04-15 12:43:24 ----D---- C:\Program Files\Winamp
    2010-04-15 11:15:49 ----D---- C:\Windows\system32\catroot2
    2010-04-15 07:40:29 ----D---- C:\ProgramData\Microsoft Help
    2010-04-11 19:54:54 ----D---- C:\Windows\ModemLogs
    2010-04-09 21:14:48 ----D---- C:\Program Files\Google
    2010-04-09 16:27:50 ----HD---- C:\ProgramData
    2010-04-09 15:55:27 ----SD---- C:\Users\Damien\AppData\Roamin g\Microsoft
    2010-04-08 08:04:39 ----RSD---- C:\Windows\assembly
    2010-04-07 07:51:11 ----D---- C:\Program Files\Common Files\microsoft shared
    2010-04-07 07:47:59 ----A---- C:\Windows\win.ini
    2010-04-07 07:47:57 ----D---- C:\Program Files\Common Files\System
    2010-04-06 12:52:54 ----A---- C:\Windows\system32\mrt.exe
    2010-04-02 09:07:00 ----D---- C:\Program Files\Java
    2010-04-02 08:12:14 ----D---- C:\Program Files\Mozilla Firefox
    2010-03-31 22:37:25 ----D---- C:\Windows\rescache
    2010-03-31 20:06:27 ----D---- C:\Windows\Microsoft.NET
    2010-03-31 19:59:24 ----D---- C:\Windows\system32\fr-FR
    2010-03-31 19:59:23 ----D---- C:\Windows\system32\wbem
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\uk-UA
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\sl-SI
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\pt-PT
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\pt-BR
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\pl-PL
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\ko-KR
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\it-IT
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\hu-HU
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\hr-HR
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\he-IL
    2010-03-31 19:59:22 ----D---- C:\Windows\system32\bg-BG
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\zh-TW
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\zh-HK
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\zh-CN
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\tr-TR
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\th-TH
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\sv-SE
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\sr-Latn-CS
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\sk-SK
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\ru-RU
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\ro-RO
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\nl-NL
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\nb-NO
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\lv-LV
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\lt-LT
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\ja-JP
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\fi-FI
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\et-EE
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\es-ES
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\en-US
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\el-GR
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\de-DE
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\da-DK
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\cs-CZ
    2010-03-31 19:59:21 ----D---- C:\Windows\system32\ar-SA
    2010-03-31 13:50:22 ----D---- C:\Windows\ShellNew
    2010-03-31 13:44:27 ----D---- C:\Program Files\MSBuild
    2010-03-31 13:43:18 ----D---- C:\Program Files\Microsoft Office
    2010-03-31 13:43:16 ----RSD---- C:\Windows\Fonts
    2010-03-31 13:43:03 ----SD---- C:\ProgramData\Microsoft
    2010-03-31 07:39:48 ----D---- C:\Windows\AppPatch
    2010-03-29 15:43:23 ----SHD---- C:\Boot
    2010-03-29 15:36:09 ----D---- C:\Program Files\Windows Sidebar
    2010-03-29 15:36:09 ----D---- C:\Program Files\Windows Media Player
    2010-03-29 15:36:09 ----D---- C:\Program Files\Windows Calendar
    2010-03-29 15:36:09 ----D---- C:\Program Files\Movie Maker
    2010-03-29 15:36:09 ----D---- C:\Program Files\Internet Explorer
    2010-03-29 15:36:08 ----D---- C:\Program Files\Windows Photo Gallery
    2010-03-29 15:36:08 ----D---- C:\Program Files\Windows Journal
    2010-03-29 15:36:08 ----D---- C:\Program Files\Windows Collaboration
    2010-03-29 15:36:07 ----D---- C:\Windows\servicing
    2010-03-29 15:36:07 ----D---- C:\Windows\ehome
    2010-03-29 15:36:07 ----D---- C:\Program Files\Windows Defender
    2010-03-29 15:36:04 ----D---- C:\Windows\system32\XPSViewer
    2010-03-29 15:36:04 ----D---- C:\Windows\system32\oobe
    2010-03-29 15:36:04 ----D---- C:\Windows\system32\migration
    2010-03-29 15:36:04 ----D---- C:\Windows\system32\fr
    2010-03-29 15:36:04 ----D---- C:\Windows\IME
    2010-03-29 15:36:03 ----D---- C:\Windows\system32\AdvancedIn stallers
    2010-03-29 15:36:01 ----D---- C:\Windows\system32\SLUI
    2010-03-29 15:36:01 ----D---- C:\Windows\system32\setup
    2010-03-29 15:36:00 ----D---- C:\Windows\system32\manifestst ore
    2010-03-29 15:35:59 ----D---- C:\Windows\system32\migwiz
    2010-03-29 15:35:42 ----D---- C:\Windows\system32\Boot
    2010-03-29 15:33:28 ----D---- C:\Windows\system32\RTCOM
    2010-03-24 18:02:43 ----HD---- C:\Program Files\InstallShield Installation Information

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 aswRdr;aswRdr; C:\Windows\system32\drivers\as wRdr.sys [2009-11-24 23120]
    R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\as wSP.sys [2009-11-24 114768]
    R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\as wTdi.sys [2009-11-24 48560]
    R1 DMICall;Sony DMI Call service; C:\Windows\system32\DRIVERS\DM ICall.sys [2008-11-24 10216]
    R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\as wFsBlk.sys [2009-11-24 20560]
    R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\as wMonFlt.sys [2009-11-24 53328]
    R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\md mxsdk.sys [2008-01-24 12672]
    R2 regi;regi; C:\Windows\system32\drivers\re gi.sys [2007-04-17 11032]
    R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\ri msptsk.sys [2008-10-22 68608]
    R2 risdptsk;risdptsk; C:\Windows\system32\DRIVERS\ri sdptsk.sys [2008-10-22 46592]
    R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xa udio.sys [2008-01-24 8192]
    R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Ap filtr.sys [2009-04-13 173616]
    R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect; C:\Windows\system32\DRIVERS\Ar cSoftKsUFilter.sys [2008-04-24 17920]
    R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\at ikmdag.sys [2009-03-02 4303872]
    R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\Cm Batt.sys [2008-01-20 14208]
    R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HS X_DPV.sys [2008-01-24 985600]
    R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HS XHWAZL.sys [2008-01-24 207360]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RT KVHDA.sys [2009-01-05 2254880]
    R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NE Tw5v32.sys [2008-08-28 3664384]
    R3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\Rt HDMIV.sys [2009-02-23 155808]
    R3 SFEP;Sony Firmware Extension Parser; C:\Windows\system32\DRIVERS\SF EP.sys [2008-11-18 9344]
    R3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\us bvideo.sys [2008-01-20 134016]
    R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HS X_CNXT.sys [2008-01-24 659968]
    R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WU DFRd.sys [2008-01-20 83328]
    R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk 60x86.sys [2009-02-10 311808]
    S3 agt0s997;agt0s997; C:\Windows\system32\drivers\ag t0s997.sys []
    S3 BthEnum;Service d'énumérateur Bluetooth; C:\Windows\system32\DRIVERS\Bt hEnum.sys [2009-04-10 22528]
    S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bt hpan.sys [2008-01-20 92160]
    S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BT Hport.sys [2009-04-10 507904]
    S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BT HUSB.sys [2009-04-10 29696]
    S3 btwaudio;Périphérique audio Bluetooth; C:\Windows\system32\drivers\bt waudio.sys [2009-04-10 84008]
    S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\bt wavdt.sys [2009-04-10 109608]
    S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\bt wl2cap.sys [2009-04-10 29736]
    S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\bt wrchid.sys [2009-04-10 18344]
    S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\dr mkaud.sys [2008-01-20 5632]
    S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\Hd Audio.sys [2006-11-02 235520]
    S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VS TAZL3.SYS [2008-01-20 200704]
    S3 igfx;igfx; C:\Windows\system32\DRIVERS\ig dkmd32.sys []
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\In tcHdmi.sys []
    S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MS KSSRV.sys [2008-01-20 8192]
    S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MS PCLOCK.sys [2008-01-20 5888]
    S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MS PQM.sys [2008-01-20 5504]
    S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MS TEE.sys [2008-01-20 6016]
    S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pc csmcfd.sys [2008-08-26 18816]
    S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rf comm.sys [2009-04-10 148992]
    S3 taphss;Anchorfree HSS Adapter; C:\Windows\system32\DRIVERS\ta phss.sys [2010-01-08 32768]
    S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\md musbser.sys [2008-03-28 25600]
    S3 WimFltr;WimFltr; C:\Windows\system32\DRIVERS\wi mfltr.sys [2008-06-06 131000]
    S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wp dusb.sys [2009-09-30 40448]
    S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\er rdev.sys [2008-01-20 6656]
    S4 MegaSR;MegaSR; C:\Windows\system32\drivers\me gasr.sys [2008-01-20 386616]
    S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sd bus.sys [2008-01-20 88576]
    S4 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UI USYS.SYS []
    S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wm iacpi.sys [2008-01-20 11264]

  5. #4
    DamienJuss

    Re : Virus Win32 Qandr [Rtk]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceS ervice.exe [2009-08-28 144672]
    R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-24 18752]
    R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.e xe [2009-03-02 729088]
    R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-24 138680]
    R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.ex e [2008-12-12 238888]
    R2 BthServ;@%SystemRoot%\System32 \bthserv.dll,-101; C:\Windows\system32\svchost.ex e [2008-01-20 21504]
    R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-03-01 567848]
    R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.ex e [2008-08-20 860160]
    R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviReg Mgr.exe [2007-01-04 112152]
    R2 NSUService;NSUService; C:\Program Files\sony\Network Utility\NSUService.exe [2008-12-21 303104]
    R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\Reg Srvc.exe [2008-08-20 466944]
    R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAud ioService.exe [2009-01-05 109088]
    R2 SpyHunter 4 Service;SpyHunter 4 Service; C:\PROGRA~1\ENIGMA~1\SPYHUN~1\ SH4SER~1.EXE [2010-03-24 323992]
    R2 uCamMonitor;CamMonitor; C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
    R2 VAIO Event Service;VAIO Event Service; C:\Program Files\sony\VAIO Event Service\VESMgr.exe [2009-01-19 203624]
    R2 VAIO Power Management;VAIO Power Management; C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2008-12-19 415592]
    R2 VCFw;VAIO Content Folder Watcher; C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-01-14 5184872]
    R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager; C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-01-19 394536]
    R2 VzCdbSvc;VAIO Entertainment Database Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe [2009-01-21 192512]
    R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xa udio.exe [2008-01-24 386560]
    R2 yksvc;Marvell Yukon Service; C:\Windows\System32\svchost.ex e [2008-01-20 21504]
    R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-24 254040]
    R3 Vcsw;VAIO Entertainment UPnP Client Adapter; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe [2009-01-21 313264]
    S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpda te.exe [2009-12-26 135664]
    S3 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2010-03-18 113152]
    S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-24 352920]
    S3 FontCache;@%systemroot%\system 32\FntCache.dll,-100; C:\Windows\system32\svchost.ex e [2008-01-20 21504]
    S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2009-06-17 30192]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.e xe [2009-06-17 137200]
    S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditSer vice.exe [2008-10-25 65888]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-03 441712]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2009-01-07 114688]
    S3 ServiceLayer;ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [2009-09-17 651776]
    S3 SOHCImp;VAIO Media plus Content Importer; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-02-05 120104]
    S3 SOHDBSvr;VAIO Media plus Database Manager; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-02-05 70952]
    S3 SOHDms;VAIO Media plus Digital Media Server; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-02-05 390440]
    S3 SOHDs;VAIO Media plus Device Searcher; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-02-05 75048]
    S3 SOHPlMgr;VAIO Media plus Playlist Manager; C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-02-05 91432]
    S3 VAIO Entertainment TV Device Arbitration Service;VAIO Entertainment TV Device Arbitration Service; C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceMan ager\VzHardwareResourceManager \VzHardwareResourceManager.exe [2009-01-21 69632]
    S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.e xe [2009-01-16 83240]

    -----------------EOF-----------------

  6. A voir en vidéo sur Futura

Discussions similaires

  1. Win32 Qandr [Rtk]
    Par sebb62 dans le forum Sécurité et malwares : désinfectez votre machine
    Réponses: 26
    Dernier message: 21/05/2010, 19h49
  2. AIDEZ Moi !! Win32:Qandr[Rtk]
    Par chon069 dans le forum Sécurité et malwares : désinfectez votre machine
    Réponses: 1
    Dernier message: 23/04/2010, 17h07
  3. Win32:Qandr[rtk]
    Par louise25 dans le forum Sécurité et malwares : désinfectez votre machine
    Réponses: 1
    Dernier message: 22/04/2010, 14h33
  4. Win32 Qandr [Rtk]
    Par sebb62 dans le forum Sécurité et malwares : désinfectez votre machine
    Réponses: 1
    Dernier message: 21/04/2010, 19h05
  5. Virus Win32 Qandr (Rtk)
    Par cora3066 dans le forum Sécurité et malwares : désinfectez votre machine
    Réponses: 14
    Dernier message: 18/04/2010, 20h38
Découvrez nos comparatifs produits sur l'informatique et les technologies.