Analyse Hijackthis virus
Résolu/Fermé
aripou
Messages postés
25
Date d'inscription
lundi 17 novembre 2008
Statut
Membre
Dernière intervention
5 août 2009
-
24 déc. 2008 à 05:36
sherred Messages postés 8345 Date d'inscription samedi 26 janvier 2008 Statut Membre Dernière intervention 4 avril 2019 - 25 déc. 2008 à 07:24
sherred Messages postés 8345 Date d'inscription samedi 26 janvier 2008 Statut Membre Dernière intervention 4 avril 2019 - 25 déc. 2008 à 07:24
A voir également:
- Analyse Hijackthis virus
- Tinyurl virus - Forum Virus / Sécurité
- Svchost.exe virus - Guide
- Analyse et reparation du lecteur c ✓ - Forum Windows 10
- Tlauncher virus ✓ - Forum Jeux vidéo
- 6 proccesus svchost.exe Virus? ✓ - Forum Virus / Sécurité
3 réponses
sherred
Messages postés
8345
Date d'inscription
samedi 26 janvier 2008
Statut
Membre
Dernière intervention
4 avril 2019
350
24 déc. 2008 à 09:55
24 déc. 2008 à 09:55
Télécharge combofix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
clique combofix.exe.
touche 1 (Yes) pour démarrer le scan.
une fois fini un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
Le rapport se trouve également ici : C:\Combofix.txt
Déconnecte toi d'internet ferme les fenêtres de tous les programmes en cours.et provisoirement
arrete les anti virus et autres protection pendand l'analyse
Pendant la durée de l'analyse ne te sert pas de ton pc
une fois l'analyse terminé ,remet toute tes protections antivirus et antispywares
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
clique combofix.exe.
touche 1 (Yes) pour démarrer le scan.
une fois fini un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
Le rapport se trouve également ici : C:\Combofix.txt
Déconnecte toi d'internet ferme les fenêtres de tous les programmes en cours.et provisoirement
arrete les anti virus et autres protection pendand l'analyse
Pendant la durée de l'analyse ne te sert pas de ton pc
une fois l'analyse terminé ,remet toute tes protections antivirus et antispywares
aripou
Messages postés
25
Date d'inscription
lundi 17 novembre 2008
Statut
Membre
Dernière intervention
5 août 2009
1
24 déc. 2008 à 21:47
24 déc. 2008 à 21:47
Bonjour,
J'ai peut-être fait une erreur en ouvrant combofix, mais il ne m'A pas donné d'option 1 ou 2... Il a commencé èa scanner tout de suite... J'espère qu'Il n'a pas effacé quelque chose qu'il ne fallait pas...
Je vous mets quand même le rapport.
Merci
ComboFix 08-12-24.01 - computer 2008-12-24 15:36:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.641 [GMT -5:00]
Running from: c:\downloads\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common\helper.sig
c:\windows\system32\aginodut.ini
c:\windows\system32\ajokawen.ini
c:\windows\system32\ekiyedat.ini
c:\windows\system32\etobibef.ini
c:\windows\system32\ipurihib.ini
c:\windows\system32\onazedet.ini
c:\windows\system32\onulavur.ini
c:\windows\system32\uzebusaw.ini
.
((((((((((((((((((((((((( Files Created from 2008-11-24 to 2008-12-24 )))))))))))))))))))))))))))))))
.
2008-12-24 15:34 . 2008-12-24 15:35 <DIR> d-------- C:\32788R22FWJFW
2008-12-23 23:30 . 2008-12-23 23:30 <DIR> d-------- c:\program files\Trend Micro
2008-12-23 23:11 . 2008-12-23 23:11 <DIR> d-------- c:\program files\CCleaner
2008-12-23 21:19 . 2008-12-23 21:19 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Webroot
2008-12-23 21:19 . 2008-12-23 21:20 <DIR> d-------- c:\documents and settings\Administrator
2008-12-15 14:30 . 2008-12-23 21:16 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-15 14:28 . 2008-12-24 10:12 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-12-15 14:28 . 2008-12-15 14:28 <DIR> d-------- c:\program files\AVG
2008-12-15 14:28 . 2008-12-15 14:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-12-15 14:28 . 2008-12-15 14:28 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-12-15 14:28 . 2008-12-15 14:28 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-12-15 14:02 . 2008-12-15 14:02 268 --ah----- C:\sqmdata17.sqm
2008-12-15 14:02 . 2008-12-15 14:02 244 --ah----- C:\sqmnoopt17.sqm
2008-12-12 17:53 . 2008-12-12 17:53 <DIR> d-------- C:\HEROES
2008-12-12 11:59 . 2008-12-12 11:59 <DIR> d-------- c:\documents and settings\computer\Application Data\Apple Computer
2008-12-11 21:39 . 2008-12-12 11:09 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-11 21:39 . 2008-12-11 21:39 1,409 --a------ c:\windows\QTFont.for
2008-12-11 21:38 . 2008-12-24 15:40 6,265 --a------ C:\logfile
2008-12-11 21:36 . 2008-12-11 21:37 <DIR> d-------- c:\program files\QuickTime
2008-12-11 21:36 . 2008-12-11 21:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-11 21:35 . 2008-12-11 21:35 <DIR> d-------- c:\program files\Common Files\Kodak
2008-12-11 21:35 . 2004-08-04 03:56 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-11 21:35 . 2004-08-04 01:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-11 21:35 . 2004-08-04 01:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-12-11 21:35 . 2001-08-18 01:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-11 21:34 . 2008-12-11 21:36 <DIR> d-------- c:\program files\Kodak
2008-12-11 21:31 . 2008-12-11 21:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kodak
2008-12-04 19:15 . 2008-12-04 19:16 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-02 13:31 . 2008-12-02 13:31 <DIR> d-------- c:\windows\system32\IOSUBSYS
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\SHOUTcast Source
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\OpenSource Flash Video Splitter
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\MONOGRAM AMR SplitterDecoder
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\DScaler5
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\CD Audio Reader Filter
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\Haali
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\ffdshow
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\DSP-worx
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\DirectVobSub
2008-11-30 15:01 . 2007-11-29 15:52 60,273 --a------ c:\windows\system32\pthreadGC2.dll
2008-11-30 15:01 . 2007-12-03 19:34 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-11-30 15:01 . 2007-11-29 15:52 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-11-30 15:00 . 2008-11-30 18:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Zoom Player
2008-11-30 14:00 . 2008-11-30 14:00 244 --ah----- C:\sqmnoopt16.sqm
2008-11-30 14:00 . 2008-11-30 14:00 232 --ah----- C:\sqmdata16.sqm
2008-11-25 15:24 . 2008-12-24 15:36 <DIR> d-------- c:\program files\Common
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-24 20:35 --------- d-----w c:\program files\BitComet
2008-12-02 18:31 --------- d-----w c:\program files\Google
2008-11-26 20:37 --------- d-----w c:\documents and settings\computer\Application Data\LimeWire
2008-11-19 19:16 --------- d-----w c:\documents and settings\computer\Application Data\LANCITE
2008-11-17 20:04 2,306,113 ----a-w c:\windows\system32\GPhotos.scr
2008-11-09 01:14 --------- d-----w c:\program files\Atheros
2008-11-09 01:14 --------- d-----w c:\documents and settings\All Users\Application Data\Atheros
2008-11-09 01:13 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-09 01:13 --------- d-----w c:\documents and settings\computer\Application Data\InstallShield
2008-11-09 01:08 --------- d-----w c:\program files\Intel
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2006-11-10 417792]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-19 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2008-12-03 2514744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-29 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-29 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-29 118784]
"ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2006-08-03 639040]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2005-07-07 135168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-15 1261336]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 5367664]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2008-02-15 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2006-08-03 06:20 188482 c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\computer\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\computer\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^Outil de détection de support de Cyber-shot Viewer.lnk]
path=c:\documents and settings\computer\Start Menu\Programs\Startup\Outil de détection de support de Cyber-shot Viewer.lnk
backup=c:\windows\pss\Outil de détection de support de Cyber-shot Viewer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2008-12-03 05:11 2514744 c:\program files\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a--c--- 2006-10-27 03:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 14:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2008-01-04 23:56 5367664 c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-04-19 22:25 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
-ra--c--- 2006-11-07 01:50 3772416 c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"ERSvc"=2 (0x2)
"usnjsvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9565:TCP"= 9565:TCP:BitComet 9565 TCP
"9565:UDP"= 9565:UDP:BitComet 9565 UDP
"9709:TCP"= 9709:TCP:BitComet 9709 TCP
"9709:UDP"= 9709:UDP:BitComet 9709 UDP
"23530:TCP"= 23530:TCP:BitComet 23530 TCP
"23530:UDP"= 23530:UDP:BitComet 23530 UDP
"8360:TCP"= 8360:TCP:BitComet 8360 TCP
"8360:UDP"= 8360:UDP:BitComet 8360 UDP
"21450:TCP"= 21450:TCP:BitComet 21450 TCP
"21450:UDP"= 21450:UDP:BitComet 21450 UDP
"24273:TCP"= 24273:TCP:BitComet 24273 TCP
"24273:UDP"= 24273:UDP:BitComet 24273 UDP
"20227:TCP"= 20227:TCP:BitComet 20227 TCP
"20227:UDP"= 20227:UDP:BitComet 20227 UDP
"8002:TCP"= 8002:TCP:BitComet 8002 TCP
"8002:UDP"= 8002:UDP:BitComet 8002 UDP
"15088:TCP"= 15088:TCP:BitComet 15088 TCP
"15088:UDP"= 15088:UDP:BitComet 15088 UDP
"27081:TCP"= 27081:TCP:BitComet 27081 TCP
"27081:UDP"= 27081:UDP:BitComet 27081 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-15 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-15 231704]
R3 WSIMD;wsimd Service;c:\windows\system32\DRIVERS\wsimd.sys [2008-11-08 57408]
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\EasyShare Registration RunOnce Task.job
- c:\windows\system32\rundll32.exe [2004-08-03 19:56]
2008-12-12 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\rundll32.exe [2004-08-03 19:56]
2008-12-24 c:\windows\Tasks\RegCure Program Check.job
- c:\documents and settings\computer\Desktop\RegCure\RegCure.exe []
2008-11-20 c:\windows\Tasks\RegCure.job
- c:\documents and settings\computer\Desktop\RegCure\RegCure.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{bce00324-24b8-4f33-a573-466f7564713b} - c:\windows\system32\lilofati.dll
HKLM-Run-nuwivayuse - c:\windows\system32\wonizaki.dll
HKLM-Run-CPMbf365421 - c:\windows\system32\batujuko.dll
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://fr.canoe.ca/accueil.html
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-24 15:39:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\WRLogonNTF.dll
c:\windows\system32\LgNotify.dll
- - - - - - - > 'explorer.exe'(940)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\agrsmsvc.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\windows\system32\wscntfy.exe
c:\program files\Webroot\Spy Sweeper\ssu.exe
.
**************************************************************************
.
Completion time: 2008-12-24 15:42:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-24 20:42:10
Pre-Run: 23 998 451 712 bytes free
Post-Run: 23,925,256,192 bytes free
241
J'ai peut-être fait une erreur en ouvrant combofix, mais il ne m'A pas donné d'option 1 ou 2... Il a commencé èa scanner tout de suite... J'espère qu'Il n'a pas effacé quelque chose qu'il ne fallait pas...
Je vous mets quand même le rapport.
Merci
ComboFix 08-12-24.01 - computer 2008-12-24 15:36:22.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.641 [GMT -5:00]
Running from: c:\downloads\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common\helper.sig
c:\windows\system32\aginodut.ini
c:\windows\system32\ajokawen.ini
c:\windows\system32\ekiyedat.ini
c:\windows\system32\etobibef.ini
c:\windows\system32\ipurihib.ini
c:\windows\system32\onazedet.ini
c:\windows\system32\onulavur.ini
c:\windows\system32\uzebusaw.ini
.
((((((((((((((((((((((((( Files Created from 2008-11-24 to 2008-12-24 )))))))))))))))))))))))))))))))
.
2008-12-24 15:34 . 2008-12-24 15:35 <DIR> d-------- C:\32788R22FWJFW
2008-12-23 23:30 . 2008-12-23 23:30 <DIR> d-------- c:\program files\Trend Micro
2008-12-23 23:11 . 2008-12-23 23:11 <DIR> d-------- c:\program files\CCleaner
2008-12-23 21:19 . 2008-12-23 21:19 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Webroot
2008-12-23 21:19 . 2008-12-23 21:20 <DIR> d-------- c:\documents and settings\Administrator
2008-12-15 14:30 . 2008-12-23 21:16 <DIR> d--h----- C:\$AVG8.VAULT$
2008-12-15 14:28 . 2008-12-24 10:12 <DIR> d-------- c:\windows\system32\drivers\Avg
2008-12-15 14:28 . 2008-12-15 14:28 <DIR> d-------- c:\program files\AVG
2008-12-15 14:28 . 2008-12-15 14:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2008-12-15 14:28 . 2008-12-15 14:28 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2008-12-15 14:28 . 2008-12-15 14:28 10,520 --a------ c:\windows\system32\avgrsstx.dll
2008-12-15 14:02 . 2008-12-15 14:02 268 --ah----- C:\sqmdata17.sqm
2008-12-15 14:02 . 2008-12-15 14:02 244 --ah----- C:\sqmnoopt17.sqm
2008-12-12 17:53 . 2008-12-12 17:53 <DIR> d-------- C:\HEROES
2008-12-12 11:59 . 2008-12-12 11:59 <DIR> d-------- c:\documents and settings\computer\Application Data\Apple Computer
2008-12-11 21:39 . 2008-12-12 11:09 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-11 21:39 . 2008-12-11 21:39 1,409 --a------ c:\windows\QTFont.for
2008-12-11 21:38 . 2008-12-24 15:40 6,265 --a------ C:\logfile
2008-12-11 21:36 . 2008-12-11 21:37 <DIR> d-------- c:\program files\QuickTime
2008-12-11 21:36 . 2008-12-11 21:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-11 21:35 . 2008-12-11 21:35 <DIR> d-------- c:\program files\Common Files\Kodak
2008-12-11 21:35 . 2004-08-04 03:56 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-11 21:35 . 2004-08-04 01:58 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-11 21:35 . 2004-08-04 01:58 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-12-11 21:35 . 2001-08-18 01:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-11 21:34 . 2008-12-11 21:36 <DIR> d-------- c:\program files\Kodak
2008-12-11 21:31 . 2008-12-11 21:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kodak
2008-12-04 19:15 . 2008-12-04 19:16 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-02 13:31 . 2008-12-02 13:31 <DIR> d-------- c:\windows\system32\IOSUBSYS
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\SHOUTcast Source
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\OpenSource Flash Video Splitter
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\MONOGRAM AMR SplitterDecoder
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\DScaler5
2008-11-30 15:02 . 2008-11-30 15:02 <DIR> d-------- c:\program files\CD Audio Reader Filter
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\Haali
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\ffdshow
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\DSP-worx
2008-11-30 15:01 . 2008-11-30 15:01 <DIR> d-------- c:\program files\DirectVobSub
2008-11-30 15:01 . 2007-11-29 15:52 60,273 --a------ c:\windows\system32\pthreadGC2.dll
2008-11-30 15:01 . 2007-12-03 19:34 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-11-30 15:01 . 2007-11-29 15:52 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-11-30 15:00 . 2008-11-30 18:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Zoom Player
2008-11-30 14:00 . 2008-11-30 14:00 244 --ah----- C:\sqmnoopt16.sqm
2008-11-30 14:00 . 2008-11-30 14:00 232 --ah----- C:\sqmdata16.sqm
2008-11-25 15:24 . 2008-12-24 15:36 <DIR> d-------- c:\program files\Common
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-24 20:35 --------- d-----w c:\program files\BitComet
2008-12-02 18:31 --------- d-----w c:\program files\Google
2008-11-26 20:37 --------- d-----w c:\documents and settings\computer\Application Data\LimeWire
2008-11-19 19:16 --------- d-----w c:\documents and settings\computer\Application Data\LANCITE
2008-11-17 20:04 2,306,113 ----a-w c:\windows\system32\GPhotos.scr
2008-11-09 01:14 --------- d-----w c:\program files\Atheros
2008-11-09 01:14 --------- d-----w c:\documents and settings\All Users\Application Data\Atheros
2008-11-09 01:13 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-09 01:13 --------- d-----w c:\documents and settings\computer\Application Data\InstallShield
2008-11-09 01:08 --------- d-----w c:\program files\Intel
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2006-11-10 417792]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-19 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2008-12-03 2514744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-29 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-29 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-29 118784]
"ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2006-08-03 639040]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2005-07-07 135168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-15 1261336]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2008-01-04 5367664]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logiciel Kodak EasyShare.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 282624]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2008-02-15 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2006-08-03 06:20 188482 c:\windows\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\computer\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\computer\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^Outil de détection de support de Cyber-shot Viewer.lnk]
path=c:\documents and settings\computer\Start Menu\Programs\Startup\Outil de détection de support de Cyber-shot Viewer.lnk
backup=c:\windows\pss\Outil de détection de support de Cyber-shot Viewer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
--a------ 2008-12-03 05:11 2514744 c:\program files\BitComet\BitComet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a--c--- 2006-10-27 03:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 14:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
--a------ 2008-01-04 23:56 5367664 c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-04-19 22:25 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
-ra--c--- 2006-11-07 01:50 3772416 c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
"ERSvc"=2 (0x2)
"usnjsvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Webroot\\Spy Sweeper\\SpySweeper.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9565:TCP"= 9565:TCP:BitComet 9565 TCP
"9565:UDP"= 9565:UDP:BitComet 9565 UDP
"9709:TCP"= 9709:TCP:BitComet 9709 TCP
"9709:UDP"= 9709:UDP:BitComet 9709 UDP
"23530:TCP"= 23530:TCP:BitComet 23530 TCP
"23530:UDP"= 23530:UDP:BitComet 23530 UDP
"8360:TCP"= 8360:TCP:BitComet 8360 TCP
"8360:UDP"= 8360:UDP:BitComet 8360 UDP
"21450:TCP"= 21450:TCP:BitComet 21450 TCP
"21450:UDP"= 21450:UDP:BitComet 21450 UDP
"24273:TCP"= 24273:TCP:BitComet 24273 TCP
"24273:UDP"= 24273:UDP:BitComet 24273 UDP
"20227:TCP"= 20227:TCP:BitComet 20227 TCP
"20227:UDP"= 20227:UDP:BitComet 20227 UDP
"8002:TCP"= 8002:TCP:BitComet 8002 TCP
"8002:UDP"= 8002:UDP:BitComet 8002 UDP
"15088:TCP"= 15088:TCP:BitComet 15088 TCP
"15088:UDP"= 15088:UDP:BitComet 15088 UDP
"27081:TCP"= 27081:TCP:BitComet 27081 TCP
"27081:UDP"= 27081:UDP:BitComet 27081 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-15 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-15 231704]
R3 WSIMD;wsimd Service;c:\windows\system32\DRIVERS\wsimd.sys [2008-11-08 57408]
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\EasyShare Registration RunOnce Task.job
- c:\windows\system32\rundll32.exe [2004-08-03 19:56]
2008-12-12 c:\windows\Tasks\EasyShare Registration Task.job
- c:\windows\system32\rundll32.exe [2004-08-03 19:56]
2008-12-24 c:\windows\Tasks\RegCure Program Check.job
- c:\documents and settings\computer\Desktop\RegCure\RegCure.exe []
2008-11-20 c:\windows\Tasks\RegCure.job
- c:\documents and settings\computer\Desktop\RegCure\RegCure.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{bce00324-24b8-4f33-a573-466f7564713b} - c:\windows\system32\lilofati.dll
HKLM-Run-nuwivayuse - c:\windows\system32\wonizaki.dll
HKLM-Run-CPMbf365421 - c:\windows\system32\batujuko.dll
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://fr.canoe.ca/accueil.html
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearch Bar = hxxp://www.google.com/ie
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-24 15:39:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\WRLogonNTF.dll
c:\windows\system32\LgNotify.dll
- - - - - - - > 'explorer.exe'(940)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\agrsmsvc.exe
c:\windows\system32\DVDRAMSV.exe
c:\windows\system32\TODDSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\windows\system32\wscntfy.exe
c:\program files\Webroot\Spy Sweeper\ssu.exe
.
**************************************************************************
.
Completion time: 2008-12-24 15:42:16 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-24 20:42:10
Pre-Run: 23 998 451 712 bytes free
Post-Run: 23,925,256,192 bytes free
241
sherred
Messages postés
8345
Date d'inscription
samedi 26 janvier 2008
Statut
Membre
Dernière intervention
4 avril 2019
350
25 déc. 2008 à 07:24
25 déc. 2008 à 07:24
télechargez Malwarebyte's ici http://www.malwarebytes.org/mbam/program/mbam-setup.exe
le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log
le programme va se mettre automatiquement a jour.
Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".
Click maintenant sur l´onglet recherche et coche la case : "executer un examen rapide".
Puis click sur "rechercher".
Laisse le scanner le pc...
Si des elements on ete trouvés > click sur supprimer la selection.
si il t´es demandé de redemarrer > click sur "yes".
A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.
PS : les rapport sont aussi rangé dans l onglet rapport/log