Pourriez-vous me verifier ceci?
Résolu
ttfab
Messages postés
98
Statut
Membre
-
ttfab Messages postés 98 Statut Membre -
ttfab Messages postés 98 Statut Membre -
Bonjour,
tout d'abord bonne et heureuse année a toute votre equipe qui mettez nos pc en liesse apres chacune de nos erreures de novice et surtout bonne sante a vous tous car cela reste quand meme le principal.
voila je trouve que mon pc bugg souvent en ce moment et mes antivirus ne detecte rien donc ca me turlupine un peu
merci d'avance.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:52:17, on 05/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1225201271906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: dexyao.dll
O20 - Winlogon Notify: byXNfEww - byXNfEww.dll (file missing)
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
tout d'abord bonne et heureuse année a toute votre equipe qui mettez nos pc en liesse apres chacune de nos erreures de novice et surtout bonne sante a vous tous car cela reste quand meme le principal.
voila je trouve que mon pc bugg souvent en ce moment et mes antivirus ne detecte rien donc ca me turlupine un peu
merci d'avance.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:52:17, on 05/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Nero\Nero 7\Core\nero.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1225201271906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: dexyao.dll
O20 - Winlogon Notify: byXNfEww - byXNfEww.dll (file missing)
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
A voir également:
- Pourriez-vous me verifier ceci?
- Verifier compatibilite windows 11 - Guide
- Vérifier température pc - Guide
- Vérifier version windows - Guide
- Vérifier si mot de passe piraté - Guide
- Site pour verifier un lien - Guide
30 réponses
ComboFix 09-01-05.03 - Fabien 2009-01-06 1:11:19.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1534.892 [GMT 1:00]
Lancé depuis: d:\documents\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Il y a peut-être des sites infectés -----
hxxp://premium.virginmega.fr
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:38 . 2009-01-06 00:51 <REP> d-------- c:\program files\Ad-remover
2009-01-05 23:43 . 2009-01-05 23:43 <REP> d-------- c:\program files\Trend Micro
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\program files\VirginMega
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-12-24 19:32 . 2008-12-24 19:36 16,574 --a------ c:\windows\EPISMF00.SWB
2008-12-24 12:37 . 2008-12-24 12:37 <REP> d-------- c:\documents and settings\All Users\Application Data\InterAction studios
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Oberon Media
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\GamesBar
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Gamenext
2008-12-21 20:47 . 2008-12-21 20:48 <REP> d-------- c:\program files\EasyBox
2008-12-21 14:32 . 2008-12-21 14:32 <REP> d-------- c:\documents and settings\Fabien\Application Data\Gaijin Ent
2008-12-21 14:24 . 2008-12-21 14:26 <REP> d-------- c:\program files\Mushroom Age
2008-12-21 14:09 . 2008-12-21 14:09 <REP> d-------- c:\documents and settings\Fabien\Application Data\GameInvest
2008-12-20 17:49 . 2008-12-20 17:49 <REP> d-------- C:\EH_Soft
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d-------- c:\program files\Microsoft IntelliPoint
2008-12-20 15:15 . 2008-06-09 13:12 1,421,384 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-12-20 15:15 . 2008-12-04 11:34 27,784 --a------ c:\windows\system32\drivers\point32.sys
2008-12-20 15:15 . 2008-04-13 19:33 21,504 --a------ c:\windows\system32\drivers\hidserv.dll
2008-12-20 15:15 . 2008-06-09 13:12 18,504 --a------ c:\windows\system32\drivers\nuidfltr.sys
2008-12-20 12:29 . 2008-12-20 12:37 <REP> d-------- c:\documents and settings\Fabien\Application Data\Ancient Quest of Saqqarah__bfg
2008-12-20 12:20 . 2008-12-20 12:20 <REP> d-------- c:\documents and settings\Fabien\Application Data\EleFun Games
2008-12-18 20:50 . 2008-12-18 20:51 <REP> d-------- c:\program files\Freeplayer
2008-12-14 19:31 . 2008-12-14 19:31 <REP> d-------- c:\documents and settings\Fabien\Application Data\Artogon
2008-12-14 17:53 . 2008-12-14 17:53 <REP> d-------- c:\documents and settings\Fabien\Application Data\Games
2008-12-14 14:16 . 2008-12-14 14:16 <REP> d-------- c:\windows\SoftR
2008-12-13 15:34 . 2009-01-04 22:44 <REP> d-------- c:\program files\PokerStars.NET
2008-12-13 14:02 . 2008-12-13 14:03 <REP> d-------- c:\program files\Les Explorateurs - Le Tresor du Pirate
2008-12-13 13:46 . 2008-12-13 13:47 <REP> d-------- c:\program files\Missions Secretes - Mata Hari et les Sous-Marins du Kaiser
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\ReflexiveArcade
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\MSXML 4.0
2008-12-13 12:38 . 2009-01-05 21:51 <REP> d-------- c:\program files\eMule
2008-12-07 15:29 . 2008-12-13 12:38 <REP> d-------- c:\program files\Magic Farm
2008-12-07 15:03 . 2008-12-07 15:03 86,016 --a------ c:\windows\system32\rqgpinqd(2).dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:13 --------- d-----w c:\program files\SuperCopier2
2009-01-06 00:12 --------- d-----w c:\program files\PeerGuardian2
2009-01-05 23:51 --------- d-----w c:\documents and settings\All Users\Application Data\Escape From Paradise
2009-01-05 23:34 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 20:01 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:07 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-20 11:18 --------- d-----w c:\documents and settings\Fabien\Application Data\PlayFirst
2008-12-20 11:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-20 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-18 19:51 --------- d-----w c:\documents and settings\Fabien\Application Data\vlc
2008-12-13 12:22 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-11-23 23:37 --------- d-----w c:\documents and settings\Fabien\Application Data\Zylom
2008-11-23 17:43 --------- d-----w c:\documents and settings\Fabien\Application Data\Gamelab
2008-11-23 16:35 --------- d-----w c:\documents and settings\All Users\Application Data\FreshGames
2008-11-23 15:16 --------- d-----w c:\documents and settings\Fabien\Application Data\Babylon
2008-11-23 15:16 --------- d-----w c:\documents and settings\All Users\Application Data\Babylon
2008-11-23 13:33 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-22 19:11 --------- d-----w c:\documents and settings\Fabien\Application Data\PetShowCraze
2008-11-22 13:18 --------- d-----w c:\documents and settings\Fabien\Application Data\Dragon Altar Games
2008-11-22 09:27 --------- d-----w c:\documents and settings\Fabien\Application Data\Malwarebytes
2008-11-22 09:27 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 23:57 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-20 18:15 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-16 18:19 --------- d-----w c:\program files\PointSoft
2008-11-16 18:19 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-11-15 12:47 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-11-14 22:52 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel Family Hero
2008-11-14 21:50 --------- d-----w c:\documents and settings\All Users\Application Data\Intenium
2008-11-14 19:45 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-14 19:41 --------- d--h--r c:\documents and settings\Fabien\Application Data\SecuROM
2008-11-11 00:14 --------- d-----w c:\documents and settings\Fabien\Application Data\Oberon Games
2008-11-11 00:14 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Games
2008-11-10 23:50 --------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-11-10 21:53 --------- d-----w c:\documents and settings\Fabien\Application Data\Magic Seeds
2008-11-10 21:00 --------- d-----w c:\documents and settings\All Users\Application Data\Astar Games
2008-11-09 13:21 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-11-09 13:09 --------- d-----w c:\program files\BFG
2008-11-09 12:08 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel
2008-11-08 23:45 --------- d-----w c:\documents and settings\Fabien\Application Data\Chicken Chase
2008-11-08 20:59 --------- d-----w c:\documents and settings\Fabien\Application Data\Turtle Odyssey II
2008-11-08 18:58 --------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2008-11-08 18:22 --------- d-----w c:\documents and settings\Fabien\Application Data\FarmerJane
2008-11-08 16:52 --------- d-----w c:\documents and settings\Fabien\Application Data\SulusGames
2008-11-07 22:55 --------- d-----w c:\documents and settings\Fabien\Application Data\Pi Eye Games
2008-11-07 21:16 --------- d-----w c:\program files\bfgclient
2008-11-07 21:01 --------- d-----w c:\documents and settings\Fabien\Application Data\Flood Light Games
2008-11-07 21:01 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-11-07 19:47 --------- d-----w c:\program files\WinAce
2008-10-24 15:46 65,536 ----a-w c:\windows\system32\a3d.dll
2008-10-24 15:46 23,552 ----a-w c:\windows\system32\PostProc.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-24 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe c:\windows\Cursors\lsass.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\EasyBox\\apache\\apache.exe"=
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-09-02 191656]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 01:14:24
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\Fabien\LOCALS~1\Temp\mc21.tmp"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Heure de fin: 2009-01-06 1:15:51 - La machine a redémarré [Fabien]
ComboFix-quarantined-files.txt 2009-01-06 00:15:48
Avant-CF: 74 608 459 776 octets libres
Après-CF: 74,494,988,288 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
195 --- E O F --- 2008-12-18 11:00:37
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1534.892 [GMT 1:00]
Lancé depuis: d:\documents\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Il y a peut-être des sites infectés -----
hxxp://premium.virginmega.fr
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:38 . 2009-01-06 00:51 <REP> d-------- c:\program files\Ad-remover
2009-01-05 23:43 . 2009-01-05 23:43 <REP> d-------- c:\program files\Trend Micro
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\program files\VirginMega
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-12-24 19:32 . 2008-12-24 19:36 16,574 --a------ c:\windows\EPISMF00.SWB
2008-12-24 12:37 . 2008-12-24 12:37 <REP> d-------- c:\documents and settings\All Users\Application Data\InterAction studios
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Oberon Media
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\GamesBar
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Gamenext
2008-12-21 20:47 . 2008-12-21 20:48 <REP> d-------- c:\program files\EasyBox
2008-12-21 14:32 . 2008-12-21 14:32 <REP> d-------- c:\documents and settings\Fabien\Application Data\Gaijin Ent
2008-12-21 14:24 . 2008-12-21 14:26 <REP> d-------- c:\program files\Mushroom Age
2008-12-21 14:09 . 2008-12-21 14:09 <REP> d-------- c:\documents and settings\Fabien\Application Data\GameInvest
2008-12-20 17:49 . 2008-12-20 17:49 <REP> d-------- C:\EH_Soft
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d-------- c:\program files\Microsoft IntelliPoint
2008-12-20 15:15 . 2008-06-09 13:12 1,421,384 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-12-20 15:15 . 2008-12-04 11:34 27,784 --a------ c:\windows\system32\drivers\point32.sys
2008-12-20 15:15 . 2008-04-13 19:33 21,504 --a------ c:\windows\system32\drivers\hidserv.dll
2008-12-20 15:15 . 2008-06-09 13:12 18,504 --a------ c:\windows\system32\drivers\nuidfltr.sys
2008-12-20 12:29 . 2008-12-20 12:37 <REP> d-------- c:\documents and settings\Fabien\Application Data\Ancient Quest of Saqqarah__bfg
2008-12-20 12:20 . 2008-12-20 12:20 <REP> d-------- c:\documents and settings\Fabien\Application Data\EleFun Games
2008-12-18 20:50 . 2008-12-18 20:51 <REP> d-------- c:\program files\Freeplayer
2008-12-14 19:31 . 2008-12-14 19:31 <REP> d-------- c:\documents and settings\Fabien\Application Data\Artogon
2008-12-14 17:53 . 2008-12-14 17:53 <REP> d-------- c:\documents and settings\Fabien\Application Data\Games
2008-12-14 14:16 . 2008-12-14 14:16 <REP> d-------- c:\windows\SoftR
2008-12-13 15:34 . 2009-01-04 22:44 <REP> d-------- c:\program files\PokerStars.NET
2008-12-13 14:02 . 2008-12-13 14:03 <REP> d-------- c:\program files\Les Explorateurs - Le Tresor du Pirate
2008-12-13 13:46 . 2008-12-13 13:47 <REP> d-------- c:\program files\Missions Secretes - Mata Hari et les Sous-Marins du Kaiser
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\ReflexiveArcade
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\MSXML 4.0
2008-12-13 12:38 . 2009-01-05 21:51 <REP> d-------- c:\program files\eMule
2008-12-07 15:29 . 2008-12-13 12:38 <REP> d-------- c:\program files\Magic Farm
2008-12-07 15:03 . 2008-12-07 15:03 86,016 --a------ c:\windows\system32\rqgpinqd(2).dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:13 --------- d-----w c:\program files\SuperCopier2
2009-01-06 00:12 --------- d-----w c:\program files\PeerGuardian2
2009-01-05 23:51 --------- d-----w c:\documents and settings\All Users\Application Data\Escape From Paradise
2009-01-05 23:34 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 20:01 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:07 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-20 11:18 --------- d-----w c:\documents and settings\Fabien\Application Data\PlayFirst
2008-12-20 11:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-20 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-18 19:51 --------- d-----w c:\documents and settings\Fabien\Application Data\vlc
2008-12-13 12:22 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-11-23 23:37 --------- d-----w c:\documents and settings\Fabien\Application Data\Zylom
2008-11-23 17:43 --------- d-----w c:\documents and settings\Fabien\Application Data\Gamelab
2008-11-23 16:35 --------- d-----w c:\documents and settings\All Users\Application Data\FreshGames
2008-11-23 15:16 --------- d-----w c:\documents and settings\Fabien\Application Data\Babylon
2008-11-23 15:16 --------- d-----w c:\documents and settings\All Users\Application Data\Babylon
2008-11-23 13:33 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-22 19:11 --------- d-----w c:\documents and settings\Fabien\Application Data\PetShowCraze
2008-11-22 13:18 --------- d-----w c:\documents and settings\Fabien\Application Data\Dragon Altar Games
2008-11-22 09:27 --------- d-----w c:\documents and settings\Fabien\Application Data\Malwarebytes
2008-11-22 09:27 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 23:57 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-20 18:15 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-16 18:19 --------- d-----w c:\program files\PointSoft
2008-11-16 18:19 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-11-15 12:47 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-11-14 22:52 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel Family Hero
2008-11-14 21:50 --------- d-----w c:\documents and settings\All Users\Application Data\Intenium
2008-11-14 19:45 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-14 19:41 --------- d--h--r c:\documents and settings\Fabien\Application Data\SecuROM
2008-11-11 00:14 --------- d-----w c:\documents and settings\Fabien\Application Data\Oberon Games
2008-11-11 00:14 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Games
2008-11-10 23:50 --------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-11-10 21:53 --------- d-----w c:\documents and settings\Fabien\Application Data\Magic Seeds
2008-11-10 21:00 --------- d-----w c:\documents and settings\All Users\Application Data\Astar Games
2008-11-09 13:21 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-11-09 13:09 --------- d-----w c:\program files\BFG
2008-11-09 12:08 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel
2008-11-08 23:45 --------- d-----w c:\documents and settings\Fabien\Application Data\Chicken Chase
2008-11-08 20:59 --------- d-----w c:\documents and settings\Fabien\Application Data\Turtle Odyssey II
2008-11-08 18:58 --------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2008-11-08 18:22 --------- d-----w c:\documents and settings\Fabien\Application Data\FarmerJane
2008-11-08 16:52 --------- d-----w c:\documents and settings\Fabien\Application Data\SulusGames
2008-11-07 22:55 --------- d-----w c:\documents and settings\Fabien\Application Data\Pi Eye Games
2008-11-07 21:16 --------- d-----w c:\program files\bfgclient
2008-11-07 21:01 --------- d-----w c:\documents and settings\Fabien\Application Data\Flood Light Games
2008-11-07 21:01 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-11-07 19:47 --------- d-----w c:\program files\WinAce
2008-10-24 15:46 65,536 ----a-w c:\windows\system32\a3d.dll
2008-10-24 15:46 23,552 ----a-w c:\windows\system32\PostProc.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-24 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe c:\windows\Cursors\lsass.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\EasyBox\\apache\\apache.exe"=
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-09-02 191656]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 01:14:24
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\Fabien\LOCALS~1\Temp\mc21.tmp"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Heure de fin: 2009-01-06 1:15:51 - La machine a redémarré [Fabien]
ComboFix-quarantined-files.txt 2009-01-06 00:15:48
Avant-CF: 74 608 459 776 octets libres
Après-CF: 74,494,988,288 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
195 --- E O F --- 2008-12-18 11:00:37
Copie le texte ci-dessous :
File::
c:\windows\EPISMF00.SWB
c:\windows\system32\rqgpinqd(2).dll
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
File::
c:\windows\EPISMF00.SWB
c:\windows\system32\rqgpinqd(2).dll
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
bonjou chimay
ComboFix 09-01-05.05 - Fabien 2009-01-06 11:19:12.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1534.1082 [GMT 1:00]
Lancé depuis: d:\documents\ComboFix.exe
Commutateurs utilisés :: d:\documents\CFScript.txt
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:38 . 2009-01-06 00:51 <REP> d-------- c:\program files\Ad-remover
2009-01-05 23:43 . 2009-01-05 23:43 <REP> d-------- c:\program files\Trend Micro
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\program files\VirginMega
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-12-24 19:32 . 2008-12-24 19:36 16,574 --a------ c:\windows\EPISMF00.SWB
2008-12-24 12:37 . 2008-12-24 12:37 <REP> d-------- c:\documents and settings\All Users\Application Data\InterAction studios
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Oberon Media
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\GamesBar
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Gamenext
2008-12-21 20:47 . 2008-12-21 20:48 <REP> d-------- c:\program files\EasyBox
2008-12-21 14:32 . 2008-12-21 14:32 <REP> d-------- c:\documents and settings\Fabien\Application Data\Gaijin Ent
2008-12-21 14:24 . 2008-12-21 14:26 <REP> d-------- c:\program files\Mushroom Age
2008-12-21 14:09 . 2008-12-21 14:09 <REP> d-------- c:\documents and settings\Fabien\Application Data\GameInvest
2008-12-20 17:49 . 2008-12-20 17:49 <REP> d-------- C:\EH_Soft
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d-------- c:\program files\Microsoft IntelliPoint
2008-12-20 15:15 . 2008-06-09 13:12 1,421,384 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-12-20 15:15 . 2008-12-04 11:34 27,784 --a------ c:\windows\system32\drivers\point32.sys
2008-12-20 15:15 . 2008-04-13 19:33 21,504 --a------ c:\windows\system32\drivers\hidserv.dll
2008-12-20 15:15 . 2008-06-09 13:12 18,504 --a------ c:\windows\system32\drivers\nuidfltr.sys
2008-12-20 12:29 . 2008-12-20 12:37 <REP> d-------- c:\documents and settings\Fabien\Application Data\Ancient Quest of Saqqarah__bfg
2008-12-20 12:20 . 2008-12-20 12:20 <REP> d-------- c:\documents and settings\Fabien\Application Data\EleFun Games
2008-12-18 20:50 . 2008-12-18 20:51 <REP> d-------- c:\program files\Freeplayer
2008-12-14 19:31 . 2008-12-14 19:31 <REP> d-------- c:\documents and settings\Fabien\Application Data\Artogon
2008-12-14 17:53 . 2008-12-14 17:53 <REP> d-------- c:\documents and settings\Fabien\Application Data\Games
2008-12-14 14:16 . 2008-12-14 14:16 <REP> d-------- c:\windows\SoftR
2008-12-13 15:34 . 2009-01-04 22:44 <REP> d-------- c:\program files\PokerStars.NET
2008-12-13 14:02 . 2008-12-13 14:03 <REP> d-------- c:\program files\Les Explorateurs - Le Tresor du Pirate
2008-12-13 13:46 . 2008-12-13 13:47 <REP> d-------- c:\program files\Missions Secretes - Mata Hari et les Sous-Marins du Kaiser
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\ReflexiveArcade
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\MSXML 4.0
2008-12-13 12:38 . 2009-01-06 11:13 <REP> d-------- c:\program files\eMule
2008-12-07 15:29 . 2008-12-13 12:38 <REP> d-------- c:\program files\Magic Farm
2008-12-07 15:03 . 2008-12-07 15:03 86,016 --a------ c:\windows\system32\rqgpinqd(2).dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 10:20 --------- d-----w c:\program files\PeerGuardian2
2009-01-06 10:17 --------- d-----w c:\program files\SuperCopier2
2009-01-05 23:51 --------- d-----w c:\documents and settings\All Users\Application Data\Escape From Paradise
2009-01-05 23:34 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 20:01 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:07 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-20 11:18 --------- d-----w c:\documents and settings\Fabien\Application Data\PlayFirst
2008-12-20 11:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-20 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-18 19:51 --------- d-----w c:\documents and settings\Fabien\Application Data\vlc
2008-12-13 12:22 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-11-23 23:37 --------- d-----w c:\documents and settings\Fabien\Application Data\Zylom
2008-11-23 17:43 --------- d-----w c:\documents and settings\Fabien\Application Data\Gamelab
2008-11-23 16:35 --------- d-----w c:\documents and settings\All Users\Application Data\FreshGames
2008-11-23 15:16 --------- d-----w c:\documents and settings\Fabien\Application Data\Babylon
2008-11-23 15:16 --------- d-----w c:\documents and settings\All Users\Application Data\Babylon
2008-11-23 13:33 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-22 19:11 --------- d-----w c:\documents and settings\Fabien\Application Data\PetShowCraze
2008-11-22 13:18 --------- d-----w c:\documents and settings\Fabien\Application Data\Dragon Altar Games
2008-11-22 09:27 --------- d-----w c:\documents and settings\Fabien\Application Data\Malwarebytes
2008-11-22 09:27 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 23:57 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-20 18:15 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-16 18:19 --------- d-----w c:\program files\PointSoft
2008-11-16 18:19 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-11-15 12:47 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-11-14 22:52 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel Family Hero
2008-11-14 21:50 --------- d-----w c:\documents and settings\All Users\Application Data\Intenium
2008-11-14 19:45 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-14 19:41 --------- d--h--r c:\documents and settings\Fabien\Application Data\SecuROM
2008-11-11 00:14 --------- d-----w c:\documents and settings\Fabien\Application Data\Oberon Games
2008-11-11 00:14 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Games
2008-11-10 23:50 --------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-11-10 21:53 --------- d-----w c:\documents and settings\Fabien\Application Data\Magic Seeds
2008-11-10 21:00 --------- d-----w c:\documents and settings\All Users\Application Data\Astar Games
2008-11-09 13:21 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-11-09 13:09 --------- d-----w c:\program files\BFG
2008-11-09 12:08 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel
2008-11-08 23:45 --------- d-----w c:\documents and settings\Fabien\Application Data\Chicken Chase
2008-11-08 20:59 --------- d-----w c:\documents and settings\Fabien\Application Data\Turtle Odyssey II
2008-11-08 18:58 --------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2008-11-08 18:22 --------- d-----w c:\documents and settings\Fabien\Application Data\FarmerJane
2008-11-08 16:52 --------- d-----w c:\documents and settings\Fabien\Application Data\SulusGames
2008-11-07 22:55 --------- d-----w c:\documents and settings\Fabien\Application Data\Pi Eye Games
2008-11-07 21:16 --------- d-----w c:\program files\bfgclient
2008-11-07 21:01 --------- d-----w c:\documents and settings\Fabien\Application Data\Flood Light Games
2008-11-07 21:01 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-11-07 19:47 --------- d-----w c:\program files\WinAce
2008-10-24 15:46 65,536 ----a-w c:\windows\system32\a3d.dll
2008-10-24 15:46 23,552 ----a-w c:\windows\system32\PostProc.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-24 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe c:\windows\Cursors\lsass.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\EasyBox\\apache\\apache.exe"=
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-09-02 191656]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 11:20:34
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\Fabien\LOCALS~1\Temp\mc21.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-861567501-515967899-839522115-1004\Software\SecuROM\License information*NULL*]
"datasecu"=hex:5e,5a,a9,67,16,24,4b,73,ed,77,67,ff,2e,83,46,09,69,55,d4,25,70,\
4b,09,0c,77,d7,dc,85,a2,cb,d8,ca,00,ce,bf,56,27,6e,34,19,3c,9f,5c,e6,6e,be,\
a0,c6,ad,31,78,3c,35,df,67,04,22,7e,7c,6f,54,22,bd,93,db,7a,a4,be,9d,bc,ab,\
ea,2c,4f,ad,c1,b5,cf,dc,e0,05,53,d2,f2,e8,aa,46,a4,d0,a1,65,52,93,4a,87,a0,\
8b,70,0f,96,56,12,51,0b,9f,66,77,72,10,e9,c1,27,d2,f4,87,85,ec,90,15,fb,68,\
91,22,8e,66,ca,0b,c4,0a,a6,d8,2f,6a,26,6b,b4,5b,3e,50,b6,62,fa,7b,c3,30,10,\
12,33,3b,28,89,9d,99,65,81,e5,fb,44,02,9e,ea,49,06,ec,c3,c7,dd,f7,6a,50,a9,\
5c,be,c1,b3,73,ed,39,62,de,49,f5,72,cf,30,f5,f7,5b,43,59,b5,c8,ea,e3,12,e8,\
22,2c,4c,2c,7f,f5,25,09,bf,be,96,2c,92,00,f3,1c,e6,4b,45,12,39,44,49,4f,77,\
26,69,0f,ae,ac,b0,52,51,54,3d,9d,57,1e,e1,ab,14,ce,76,29,1c,19,45,fa,69,61,\
e6,bd,41,a2,92,8a,a1,22,a6,bd,f8,17,59,b3,4d,bb,ee,7a,f0,26,f7,06,2b,ed,56,\
15,49,4b,00,50,03,98,84,46,83,ab,55,76,58,80,08,fc,4e,80,35,73,42,f9,d3,a4,\
db,7c,95,93,10,65,05,80,0a,f8,53,57,92,86,04,86,c8,a3,26,db,43,d0,f2,38,c0,\
be,32,51,ad,fa,92,a2,b3,d2,8d,aa,a9,51,cd,6b,95,d4,76,00,63,df,36,ce,f0,fe,\
03,bf,56,41,5c,0f,bf,a8,38,d7,73,5f,4b,af,ef,1a,56,c1,cb,a9,f9,9c,b6,39,30,\
03,7e,84,1e,26,93,ee,e7,1c,7e,93,d3,49,82,12,2c,4e,08,99,0b,ca,ba,60,70,16,\
20,02,8e,6a,d3,b9,39,17,d8,e9,ba,ee,ab,43,f4,5d,9a,98,78,2e,6f,c4,04,16,35,\
13,fc,e4,4b,73,9f,91,9e,99,aa,fc,9a,2c,9b,70,df,da,7f,80,49,9a,23,42,00,1b,\
05,40,6f,3b,26,6a,ee,64,e4,b7,7b,0f,69,41,25,56,1b,bc,23,62,6f,8a,0d,b6,d1,\
a5,98,05,c1,4c,96,30,ba,95,ee,88,a2,a6,7c,91,75,af,75,59,5d,17,8f,47,65,7b,\
30,60,05,d6,a7,a9,a4,85,e5,e0,47,70,bd,e0,3f,3d,da,f0,74,d1,80,15,91,e7,10,\
1a,50,88,7c,0c,e7,c0,84,cb,38,72,b6,82,21,19,33,b2,7d,6a,07,49,8e,df,23,ad,\
83,38,65,ed,a3,eb,41,34,12,78,09,81,61,77,23,11,88,8e,9b,a9,86,02,62,89,b1,\
96,2d,dc,87,d8,46,1b,49,ff,34,6a,36,48,12,ed,42,9b,9c,70,15,fc,01,12,33,07,\
03,8b,ea,6c,45,cd,0f,31,1d,8c,10,56,9d,31,34,ab,15,52,ee,79,ed,e6,c0,9c,80,\
6d,a0,f5,52,81,ae,96,69,ff,cd,cd,af,a2,ca,08,d4,ea,d0,a9,db,da,26,58,b6,b3,\
6f,32,fa,94,f7,da,e2,d8,c0,56,92,31,ab,26,68,70,75,19,db,ed,15,3a,92,63,27,\
8d,92,0e,23,a6,19,d1,ff,e0,ac,23,ef,89,2e,c3,ab,21,ad,44,8a,26,3f,97,17,f5,\
36,0a,86,67,ac,a4,c6,47,2e,5a,b0,72,b2,65,6d,a1,06,5b,b4,82,13,06,d3,77,2d,\
56,2e,a5,5b,e6,ec,8e,e9,f0,e3,cc,12,84,09,32,00,2f,a1,18,e5,d9,d9,48,da,dd,\
49,72,6f,55,f8,1d,56,4a,98,17,95,a4,f6,51,af,ac,a5,85,67,e1,2c,3e,04,61,54,\
35,1b,ea,a9,ec,96,0c,7f,38,6b,17,1d,3e,96,d0,6f,30,1f,cd,db,3e,44,be,77,30,\
83,e2,17,6b,4d,d7,3d,d2,ed,e5,7a,fc,6f,c1,62,92,fd,d6,e5,60,16,55,6c,54,59,\
f2,04,bf,6c,51,7d,03,48,63,00,02,08,94,c5,66,21,ec,f3,81,bb,c1,02,49,50,4e,\
c1,b9,7d,8a,1c,96,bf,0b,ef,e8,90,dc,7f,05,34,aa,17,53,12,51,9e,d0,fa,fa,27,\
e8,00,1b,19,e8,c2,4b,d3,03,38,98,cb,61,9f,3b,32,40,65,77,c3,88,90,e9,ad,4d,\
0e,98,a3,83,0a,34,85,25,60,70,77,89,90,83,49,5b,67,23,31,ae,4e,69,75,29,f0,\
8e,64,a7,3e,44,78,97,81,66,70,78,e4,14,9f,cb,50,a7,81,bb,9b,0f,65,8d,2f,c3,\
b1,a7,db,df,5b,38,62,50,15,07,81,e3,1a,aa,f1,04,64,4b,11,fc,b1,a6,74,1c,5b,\
5e,b5,57,09,18,45,54,0c,2a,73,51,3d,19,5e,01,fc,f8,73,9a,65,8b,b1,52,25,7b,\
8a,6c,0f,1d,ec,ff,60,a2,93,e7,2a,80,d6,40,7c,ea,3d,a8,5e,94,cb,58,69,db,5d,\
7f,de,1a,db,e3,b6,e4,01,38,63,12,ed,55,c3,e8,30,ba,2f,c0,8d,e5,c9,7b,f0,02,\
22,63,be,f3,1b,26,1b,aa,bd,e5,44,b7,2b,df,c9,16,52,cf,a5,c9,89,24,7c,5a,fa,\
14,b0,67,54,77,c3,b2,da,ef,37,8b,48,60,72,c1,d2,e7,e3,c8,6e,1b,5b,39,e3,99,\
64,74,54,40,ba,8c,bb,c4,d2,05,3c,18,92,89,0a,ad,78,6b,73,b3,23,78,bd,c1,7d,\
4b,3e,77,b9,fb,b6,a2,89,82,70,29,50,c3,6c,1f,a1,e3,33,38,8d,89,a9,14,69,25,\
bf,ee,3a,d8,2c,3d,55,d0,e6,26,e2,9c,7c,cd,7b,d6,e7,9a,b6,15,c5,ca,85,17,48,\
60,ad,25,6e,6e,d5,08,7c,cd,eb,40,99,ea,e5,1a,0c,87,86,4d,0e,6a,df,c0,ab,ab,\
14,c2,82,44,81,bc,c5,22,14,a7,9a,05,75,e0,48,c9,65,0e,d3,c9,92,12,4e,c2,a7,\
0c,9a,b2,ac,4b,cd,cb,41,a9,9c,6d,7b,fb,8d,75,3d,99,8e,67,2e,e3,17,03,b5,7f,\
3e,d0,47,a2,c2,9c,ef,df,0f,83,95,3d,d8,66,35,55,f2,94,4d,06,25,c9,c8,09,e2,\
37,8c,02,a3,3a,34,b5,fc,13,43,03,d9,40,5f,f0,26,9b,d3,44,72,1a,5d,7b,0f,6d,\
05,d2,0c,19,05,7f,52,cc,7a,23,87,71,f9,39,93,3d,da,4b,07,df,10,5b,62,30,9e,\
2f,c4,49,ce,25,f0,47,6d,2f,12,e4,4b,88,78,d9,9f,69,78,7b,c5,20,bc,f2,3c,42,\
44,a9,d2,46,07,17,58,74,b9,86,e0,92,36,e9,d9,63,ea,ae,28,40,fc,7b,70,41,da,\
aa,02,5c,4b,75,a7,66,bf,7f,a9,51,86,87,ed,4a,6c,92,f5,af,ba,e5,0e,8f,ef,8a,\
a3,ae,f6,fa,1f,3f,8d,8c,86,ad,93,22,32,2d,f7,f6,d8,30,11,44,af,53,b0,69,71,\
0c,3b,8d,1a,dd,c7,ad,79,bf,50,25,20,1a,1c,4b,f7,2c,d9,9c,87,76,99,07,8f,52,\
b2,31,e5,37,f3,69,19,f2,e8,b4,6e,35,63,cd,9a,a9,77,fa,4a,fe,16,47,d4,db,e6,\
a9,15,b2,35,f4,d5,59,a8,37,11,44,f2,16,42,6e,0f,0a,53,5f,5f,f2,cf,8f,e9,4b,\
14,1e,63,05,61,a7,0b,49,1a,40,37,c1,2e,4c,df,b0,c7,6a,29,c5,e1,c4,a6,80,d0,\
fb,a0,67,94,a6,a8,9e,a7,09,0f,41,ed,d6,fe,52,12,a5,37,fc,88,e5,30,9b,11,a4,\
02,5d,6b,ef,2d,28,3f,3d,f8,3e,ea,61,4a,4a,35,f9,cc,d6,74,fd,4c,59,ae,7b,d2,\
45,61,82,03,41,0c,d4,aa,9a,26,3e,91,0d,b9,ea,26,b7,8f,75,6a,40,bd,19,43,7e,\
ca,60,67,6a,cb,2f,02,b7,85,3d,fb,1e,1e,78,a2,25,cc,ab,bb,52,65,19,d1,15,47,\
fc,8e,fc,28,af,0d,f4,11,be,c7,03,ba,42,59,91,7f,17,65,17,9e,cb,26,75,92,d5,\
8e,1e,7e,5d,0c,3d,84,fc,7d,ff,d7,b4,ab,69,b1,c5,53,54,6a,08,37,cd,fe,90,74,\
b2,64,a2,35,38,bb,06,4b,c4,d9,cd,45,16,c0,fb,5f,f9,11,31,af,87,d5,f6,19,60,\
64,c8,75,07,50,e9,78,3c,40,2b,4f,e5,0a,6c,99,3b,01,ac,c2,17,66,af,f1,f5,18,\
ba,06,f2,bc,ca,2b,b4,82,84,0b,08,d8,33,db,fb,23,72,fe,35,a4,c5,e6,06,be,3b,\
fb,6b,07,58,ba,80,a2,8f,94,0a,12,74,30,a3,af,99,aa,c7,4e,f6,90,f2,fc,a3,bc,\
3b,b0,0c,74,50,1d,e1,f8,a0,aa,a2,87,ba,35,a7,61,5b,4b,6d,44,82,ac,54,7a,40,\
33,ff,5c,7c,5e,53,64,34,b8,12,cf,c2,e4,a8,5e,64,e6,8e,91,ae,a0,fc,0c,c9,21,\
28,28,ce,f7,e0,da,75,87,73,47,e9,fc,ad,38,ac,1d,e2,72,35,69,2a,22,9c,53,3a,\
87,bb,f3,8a,b6,98,6b,6f,05,bf,9b,15,39,3f,f0,98,e2,3d,d5,e7,1f,8d,1b,8f,5e,\
72,72,c0,8d,bd,fb,67,2e,8e,39,39,91,4d,60,bd,5a,2d,06,85,7e,d9,3a,66,9b,33,\
8e,fe,aa,f0,21,bb,55,43,56,f2,c4,88,d3,37,3f,fd,78,a5,04,e2,8d,dd,eb,2f,ab,\
4d,d1,4a,d4,0c,32,05,8c,81,c6,f1,d3,c8,98,69,a6,bc,7d,4d,11,77,c3,2e,d2,79,\
33,5c,58,56,09,4f,ea,89,dd,50,d1,9f,26,b8,38,c4,14,38,cd,f6,b5,78,b4,4f,f1,\
05,88,ef,9a,47,b0,5a,42,82,8d,7b,af,9c,2f,6e,80,39,07,7f,cf,59,be,99,1e,5d,\
a0,fd,5b,c7,84,8a,65,9d,5d,c7,7c,76,12,c6,da,fb,be,85,11,de,d4,fc,cc,57,2c,\
59,f5,46,50,fa,5e,64,41,42,d7,5e,d2,f4,51,41,c5,de,95,58,6e,e7,f6,fb,5e,a2,\
85,4b,fb,8b,4a,97,f6,47,3e,93,38,8c,1c,b1,06,ca,19,e4,8f,e7,eb,20,41,0c,db,\
8b,2b,7e,e1,00,72,c1,73,15,ba,68,a0,72,1b,fc,ee,5d,d5,03,ca,13,3a,a3,c3,c5,\
0b,96,f7,f3,24,bf,ed,75,57,bd,79,4a,75,4c,36,3d,83,2c,db,55,f5,db,86,fd,e4,\
78,08,32,3f,e3,90,cc,aa,54,07,39,ee,3e,2c,37,0a,05,50,7c,73,3a,14,d7,7f,f6,\
c5,06,de,a4,0a,9e,21,13,f0,79,e1,a4,32,97,0e,d7,59,33,9b,2f,06,3d,b0,e1,08,\
70,f5,8b,1d,0c,22,03,52,68,aa,1d,b0,c3,ae,9b,15,fb,5a,68,22,19,76,48,66,b9,\
f9,11,61,78,2b,cb,cc,41,26,ff,f3,df,c2,d3,a6,40,c2,d3,ae,40,c2,d3,a6,c0
"rkeysecu"=hex:33,60,df,fe,c0,4f,93,a4,c7,8d,21,61,9b,30,19,15
.
Heure de fin: 2009-01-06 11:21:40
ComboFix-quarantined-files.txt 2009-01-06 10:21:36
ComboFix2.txt 2009-01-06 00:15:52
Avant-CF: 76 760 920 064 octets libres
Après-CF: 76,749,733,888 octets libres
266 --- E O F --- 2008-12-18 11:00:37
ComboFix 09-01-05.05 - Fabien 2009-01-06 11:19:12.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1534.1082 [GMT 1:00]
Lancé depuis: d:\documents\ComboFix.exe
Commutateurs utilisés :: d:\documents\CFScript.txt
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-06 au 2009-01-06 ))))))))))))))))))))))))))))))))))))
.
2009-01-06 00:38 . 2009-01-06 00:51 <REP> d-------- c:\program files\Ad-remover
2009-01-05 23:43 . 2009-01-05 23:43 <REP> d-------- c:\program files\Trend Micro
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\program files\VirginMega
2009-01-04 08:45 . 2009-01-04 08:45 <REP> d-------- c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-12-24 19:32 . 2008-12-24 19:36 16,574 --a------ c:\windows\EPISMF00.SWB
2008-12-24 12:37 . 2008-12-24 12:37 <REP> d-------- c:\documents and settings\All Users\Application Data\InterAction studios
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Oberon Media
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\GamesBar
2008-12-24 12:36 . 2008-12-24 12:36 <REP> d-------- c:\program files\Gamenext
2008-12-21 20:47 . 2008-12-21 20:48 <REP> d-------- c:\program files\EasyBox
2008-12-21 14:32 . 2008-12-21 14:32 <REP> d-------- c:\documents and settings\Fabien\Application Data\Gaijin Ent
2008-12-21 14:24 . 2008-12-21 14:26 <REP> d-------- c:\program files\Mushroom Age
2008-12-21 14:09 . 2008-12-21 14:09 <REP> d-------- c:\documents and settings\Fabien\Application Data\GameInvest
2008-12-20 17:49 . 2008-12-20 17:49 <REP> d-------- C:\EH_Soft
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-12-20 15:16 . 2008-12-20 15:16 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-12-20 15:15 . 2008-12-20 15:15 <REP> d-------- c:\program files\Microsoft IntelliPoint
2008-12-20 15:15 . 2008-06-09 13:12 1,421,384 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-12-20 15:15 . 2008-12-04 11:34 27,784 --a------ c:\windows\system32\drivers\point32.sys
2008-12-20 15:15 . 2008-04-13 19:33 21,504 --a------ c:\windows\system32\drivers\hidserv.dll
2008-12-20 15:15 . 2008-06-09 13:12 18,504 --a------ c:\windows\system32\drivers\nuidfltr.sys
2008-12-20 12:29 . 2008-12-20 12:37 <REP> d-------- c:\documents and settings\Fabien\Application Data\Ancient Quest of Saqqarah__bfg
2008-12-20 12:20 . 2008-12-20 12:20 <REP> d-------- c:\documents and settings\Fabien\Application Data\EleFun Games
2008-12-18 20:50 . 2008-12-18 20:51 <REP> d-------- c:\program files\Freeplayer
2008-12-14 19:31 . 2008-12-14 19:31 <REP> d-------- c:\documents and settings\Fabien\Application Data\Artogon
2008-12-14 17:53 . 2008-12-14 17:53 <REP> d-------- c:\documents and settings\Fabien\Application Data\Games
2008-12-14 14:16 . 2008-12-14 14:16 <REP> d-------- c:\windows\SoftR
2008-12-13 15:34 . 2009-01-04 22:44 <REP> d-------- c:\program files\PokerStars.NET
2008-12-13 14:02 . 2008-12-13 14:03 <REP> d-------- c:\program files\Les Explorateurs - Le Tresor du Pirate
2008-12-13 13:46 . 2008-12-13 13:47 <REP> d-------- c:\program files\Missions Secretes - Mata Hari et les Sous-Marins du Kaiser
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\ReflexiveArcade
2008-12-13 12:38 . 2008-12-13 12:38 <REP> d-------- c:\program files\MSXML 4.0
2008-12-13 12:38 . 2009-01-06 11:13 <REP> d-------- c:\program files\eMule
2008-12-07 15:29 . 2008-12-13 12:38 <REP> d-------- c:\program files\Magic Farm
2008-12-07 15:03 . 2008-12-07 15:03 86,016 --a------ c:\windows\system32\rqgpinqd(2).dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 10:20 --------- d-----w c:\program files\PeerGuardian2
2009-01-06 10:17 --------- d-----w c:\program files\SuperCopier2
2009-01-05 23:51 --------- d-----w c:\documents and settings\All Users\Application Data\Escape From Paradise
2009-01-05 23:34 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 20:01 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 17:07 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-12-20 11:18 --------- d-----w c:\documents and settings\Fabien\Application Data\PlayFirst
2008-12-20 11:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-20 11:06 --------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-18 19:51 --------- d-----w c:\documents and settings\Fabien\Application Data\vlc
2008-12-13 12:22 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-03 18:52 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-03 18:52 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-11-23 23:37 --------- d-----w c:\documents and settings\Fabien\Application Data\Zylom
2008-11-23 17:43 --------- d-----w c:\documents and settings\Fabien\Application Data\Gamelab
2008-11-23 16:35 --------- d-----w c:\documents and settings\All Users\Application Data\FreshGames
2008-11-23 15:16 --------- d-----w c:\documents and settings\Fabien\Application Data\Babylon
2008-11-23 15:16 --------- d-----w c:\documents and settings\All Users\Application Data\Babylon
2008-11-23 13:33 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-22 19:11 --------- d-----w c:\documents and settings\Fabien\Application Data\PetShowCraze
2008-11-22 13:18 --------- d-----w c:\documents and settings\Fabien\Application Data\Dragon Altar Games
2008-11-22 09:27 --------- d-----w c:\documents and settings\Fabien\Application Data\Malwarebytes
2008-11-22 09:27 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 23:57 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-20 18:15 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-16 18:19 --------- d-----w c:\program files\PointSoft
2008-11-16 18:19 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-11-15 12:47 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-11-14 22:52 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel Family Hero
2008-11-14 21:50 --------- d-----w c:\documents and settings\All Users\Application Data\Intenium
2008-11-14 19:45 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-14 19:41 --------- d--h--r c:\documents and settings\Fabien\Application Data\SecuROM
2008-11-11 00:14 --------- d-----w c:\documents and settings\Fabien\Application Data\Oberon Games
2008-11-11 00:14 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Games
2008-11-10 23:50 --------- d-----w c:\documents and settings\All Users\Application Data\Sandlot Games
2008-11-10 21:53 --------- d-----w c:\documents and settings\Fabien\Application Data\Magic Seeds
2008-11-10 21:00 --------- d-----w c:\documents and settings\All Users\Application Data\Astar Games
2008-11-09 13:21 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-11-09 13:09 --------- d-----w c:\program files\BFG
2008-11-09 12:08 --------- d-----w c:\documents and settings\Fabien\Application Data\Jane s Hotel
2008-11-08 23:45 --------- d-----w c:\documents and settings\Fabien\Application Data\Chicken Chase
2008-11-08 20:59 --------- d-----w c:\documents and settings\Fabien\Application Data\Turtle Odyssey II
2008-11-08 18:58 --------- d-----w c:\documents and settings\All Users\Application Data\PopCap
2008-11-08 18:22 --------- d-----w c:\documents and settings\Fabien\Application Data\FarmerJane
2008-11-08 16:52 --------- d-----w c:\documents and settings\Fabien\Application Data\SulusGames
2008-11-07 22:55 --------- d-----w c:\documents and settings\Fabien\Application Data\Pi Eye Games
2008-11-07 21:16 --------- d-----w c:\program files\bfgclient
2008-11-07 21:01 --------- d-----w c:\documents and settings\Fabien\Application Data\Flood Light Games
2008-11-07 21:01 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-11-07 19:47 --------- d-----w c:\program files\WinAce
2008-10-24 15:46 65,536 ----a-w c:\windows\system32\a3d.dll
2008-10-24 15:46 23,552 ----a-w c:\windows\system32\PostProc.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 153136]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-24 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe c:\windows\Cursors\lsass.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"c:\\Program Files\\EasyBox\\apache\\apache.exe"=
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2008-09-02 191656]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 11:20:34
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\Fabien\LOCALS~1\Temp\mc21.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-861567501-515967899-839522115-1004\Software\SecuROM\License information*NULL*]
"datasecu"=hex:5e,5a,a9,67,16,24,4b,73,ed,77,67,ff,2e,83,46,09,69,55,d4,25,70,\
4b,09,0c,77,d7,dc,85,a2,cb,d8,ca,00,ce,bf,56,27,6e,34,19,3c,9f,5c,e6,6e,be,\
a0,c6,ad,31,78,3c,35,df,67,04,22,7e,7c,6f,54,22,bd,93,db,7a,a4,be,9d,bc,ab,\
ea,2c,4f,ad,c1,b5,cf,dc,e0,05,53,d2,f2,e8,aa,46,a4,d0,a1,65,52,93,4a,87,a0,\
8b,70,0f,96,56,12,51,0b,9f,66,77,72,10,e9,c1,27,d2,f4,87,85,ec,90,15,fb,68,\
91,22,8e,66,ca,0b,c4,0a,a6,d8,2f,6a,26,6b,b4,5b,3e,50,b6,62,fa,7b,c3,30,10,\
12,33,3b,28,89,9d,99,65,81,e5,fb,44,02,9e,ea,49,06,ec,c3,c7,dd,f7,6a,50,a9,\
5c,be,c1,b3,73,ed,39,62,de,49,f5,72,cf,30,f5,f7,5b,43,59,b5,c8,ea,e3,12,e8,\
22,2c,4c,2c,7f,f5,25,09,bf,be,96,2c,92,00,f3,1c,e6,4b,45,12,39,44,49,4f,77,\
26,69,0f,ae,ac,b0,52,51,54,3d,9d,57,1e,e1,ab,14,ce,76,29,1c,19,45,fa,69,61,\
e6,bd,41,a2,92,8a,a1,22,a6,bd,f8,17,59,b3,4d,bb,ee,7a,f0,26,f7,06,2b,ed,56,\
15,49,4b,00,50,03,98,84,46,83,ab,55,76,58,80,08,fc,4e,80,35,73,42,f9,d3,a4,\
db,7c,95,93,10,65,05,80,0a,f8,53,57,92,86,04,86,c8,a3,26,db,43,d0,f2,38,c0,\
be,32,51,ad,fa,92,a2,b3,d2,8d,aa,a9,51,cd,6b,95,d4,76,00,63,df,36,ce,f0,fe,\
03,bf,56,41,5c,0f,bf,a8,38,d7,73,5f,4b,af,ef,1a,56,c1,cb,a9,f9,9c,b6,39,30,\
03,7e,84,1e,26,93,ee,e7,1c,7e,93,d3,49,82,12,2c,4e,08,99,0b,ca,ba,60,70,16,\
20,02,8e,6a,d3,b9,39,17,d8,e9,ba,ee,ab,43,f4,5d,9a,98,78,2e,6f,c4,04,16,35,\
13,fc,e4,4b,73,9f,91,9e,99,aa,fc,9a,2c,9b,70,df,da,7f,80,49,9a,23,42,00,1b,\
05,40,6f,3b,26,6a,ee,64,e4,b7,7b,0f,69,41,25,56,1b,bc,23,62,6f,8a,0d,b6,d1,\
a5,98,05,c1,4c,96,30,ba,95,ee,88,a2,a6,7c,91,75,af,75,59,5d,17,8f,47,65,7b,\
30,60,05,d6,a7,a9,a4,85,e5,e0,47,70,bd,e0,3f,3d,da,f0,74,d1,80,15,91,e7,10,\
1a,50,88,7c,0c,e7,c0,84,cb,38,72,b6,82,21,19,33,b2,7d,6a,07,49,8e,df,23,ad,\
83,38,65,ed,a3,eb,41,34,12,78,09,81,61,77,23,11,88,8e,9b,a9,86,02,62,89,b1,\
96,2d,dc,87,d8,46,1b,49,ff,34,6a,36,48,12,ed,42,9b,9c,70,15,fc,01,12,33,07,\
03,8b,ea,6c,45,cd,0f,31,1d,8c,10,56,9d,31,34,ab,15,52,ee,79,ed,e6,c0,9c,80,\
6d,a0,f5,52,81,ae,96,69,ff,cd,cd,af,a2,ca,08,d4,ea,d0,a9,db,da,26,58,b6,b3,\
6f,32,fa,94,f7,da,e2,d8,c0,56,92,31,ab,26,68,70,75,19,db,ed,15,3a,92,63,27,\
8d,92,0e,23,a6,19,d1,ff,e0,ac,23,ef,89,2e,c3,ab,21,ad,44,8a,26,3f,97,17,f5,\
36,0a,86,67,ac,a4,c6,47,2e,5a,b0,72,b2,65,6d,a1,06,5b,b4,82,13,06,d3,77,2d,\
56,2e,a5,5b,e6,ec,8e,e9,f0,e3,cc,12,84,09,32,00,2f,a1,18,e5,d9,d9,48,da,dd,\
49,72,6f,55,f8,1d,56,4a,98,17,95,a4,f6,51,af,ac,a5,85,67,e1,2c,3e,04,61,54,\
35,1b,ea,a9,ec,96,0c,7f,38,6b,17,1d,3e,96,d0,6f,30,1f,cd,db,3e,44,be,77,30,\
83,e2,17,6b,4d,d7,3d,d2,ed,e5,7a,fc,6f,c1,62,92,fd,d6,e5,60,16,55,6c,54,59,\
f2,04,bf,6c,51,7d,03,48,63,00,02,08,94,c5,66,21,ec,f3,81,bb,c1,02,49,50,4e,\
c1,b9,7d,8a,1c,96,bf,0b,ef,e8,90,dc,7f,05,34,aa,17,53,12,51,9e,d0,fa,fa,27,\
e8,00,1b,19,e8,c2,4b,d3,03,38,98,cb,61,9f,3b,32,40,65,77,c3,88,90,e9,ad,4d,\
0e,98,a3,83,0a,34,85,25,60,70,77,89,90,83,49,5b,67,23,31,ae,4e,69,75,29,f0,\
8e,64,a7,3e,44,78,97,81,66,70,78,e4,14,9f,cb,50,a7,81,bb,9b,0f,65,8d,2f,c3,\
b1,a7,db,df,5b,38,62,50,15,07,81,e3,1a,aa,f1,04,64,4b,11,fc,b1,a6,74,1c,5b,\
5e,b5,57,09,18,45,54,0c,2a,73,51,3d,19,5e,01,fc,f8,73,9a,65,8b,b1,52,25,7b,\
8a,6c,0f,1d,ec,ff,60,a2,93,e7,2a,80,d6,40,7c,ea,3d,a8,5e,94,cb,58,69,db,5d,\
7f,de,1a,db,e3,b6,e4,01,38,63,12,ed,55,c3,e8,30,ba,2f,c0,8d,e5,c9,7b,f0,02,\
22,63,be,f3,1b,26,1b,aa,bd,e5,44,b7,2b,df,c9,16,52,cf,a5,c9,89,24,7c,5a,fa,\
14,b0,67,54,77,c3,b2,da,ef,37,8b,48,60,72,c1,d2,e7,e3,c8,6e,1b,5b,39,e3,99,\
64,74,54,40,ba,8c,bb,c4,d2,05,3c,18,92,89,0a,ad,78,6b,73,b3,23,78,bd,c1,7d,\
4b,3e,77,b9,fb,b6,a2,89,82,70,29,50,c3,6c,1f,a1,e3,33,38,8d,89,a9,14,69,25,\
bf,ee,3a,d8,2c,3d,55,d0,e6,26,e2,9c,7c,cd,7b,d6,e7,9a,b6,15,c5,ca,85,17,48,\
60,ad,25,6e,6e,d5,08,7c,cd,eb,40,99,ea,e5,1a,0c,87,86,4d,0e,6a,df,c0,ab,ab,\
14,c2,82,44,81,bc,c5,22,14,a7,9a,05,75,e0,48,c9,65,0e,d3,c9,92,12,4e,c2,a7,\
0c,9a,b2,ac,4b,cd,cb,41,a9,9c,6d,7b,fb,8d,75,3d,99,8e,67,2e,e3,17,03,b5,7f,\
3e,d0,47,a2,c2,9c,ef,df,0f,83,95,3d,d8,66,35,55,f2,94,4d,06,25,c9,c8,09,e2,\
37,8c,02,a3,3a,34,b5,fc,13,43,03,d9,40,5f,f0,26,9b,d3,44,72,1a,5d,7b,0f,6d,\
05,d2,0c,19,05,7f,52,cc,7a,23,87,71,f9,39,93,3d,da,4b,07,df,10,5b,62,30,9e,\
2f,c4,49,ce,25,f0,47,6d,2f,12,e4,4b,88,78,d9,9f,69,78,7b,c5,20,bc,f2,3c,42,\
44,a9,d2,46,07,17,58,74,b9,86,e0,92,36,e9,d9,63,ea,ae,28,40,fc,7b,70,41,da,\
aa,02,5c,4b,75,a7,66,bf,7f,a9,51,86,87,ed,4a,6c,92,f5,af,ba,e5,0e,8f,ef,8a,\
a3,ae,f6,fa,1f,3f,8d,8c,86,ad,93,22,32,2d,f7,f6,d8,30,11,44,af,53,b0,69,71,\
0c,3b,8d,1a,dd,c7,ad,79,bf,50,25,20,1a,1c,4b,f7,2c,d9,9c,87,76,99,07,8f,52,\
b2,31,e5,37,f3,69,19,f2,e8,b4,6e,35,63,cd,9a,a9,77,fa,4a,fe,16,47,d4,db,e6,\
a9,15,b2,35,f4,d5,59,a8,37,11,44,f2,16,42,6e,0f,0a,53,5f,5f,f2,cf,8f,e9,4b,\
14,1e,63,05,61,a7,0b,49,1a,40,37,c1,2e,4c,df,b0,c7,6a,29,c5,e1,c4,a6,80,d0,\
fb,a0,67,94,a6,a8,9e,a7,09,0f,41,ed,d6,fe,52,12,a5,37,fc,88,e5,30,9b,11,a4,\
02,5d,6b,ef,2d,28,3f,3d,f8,3e,ea,61,4a,4a,35,f9,cc,d6,74,fd,4c,59,ae,7b,d2,\
45,61,82,03,41,0c,d4,aa,9a,26,3e,91,0d,b9,ea,26,b7,8f,75,6a,40,bd,19,43,7e,\
ca,60,67,6a,cb,2f,02,b7,85,3d,fb,1e,1e,78,a2,25,cc,ab,bb,52,65,19,d1,15,47,\
fc,8e,fc,28,af,0d,f4,11,be,c7,03,ba,42,59,91,7f,17,65,17,9e,cb,26,75,92,d5,\
8e,1e,7e,5d,0c,3d,84,fc,7d,ff,d7,b4,ab,69,b1,c5,53,54,6a,08,37,cd,fe,90,74,\
b2,64,a2,35,38,bb,06,4b,c4,d9,cd,45,16,c0,fb,5f,f9,11,31,af,87,d5,f6,19,60,\
64,c8,75,07,50,e9,78,3c,40,2b,4f,e5,0a,6c,99,3b,01,ac,c2,17,66,af,f1,f5,18,\
ba,06,f2,bc,ca,2b,b4,82,84,0b,08,d8,33,db,fb,23,72,fe,35,a4,c5,e6,06,be,3b,\
fb,6b,07,58,ba,80,a2,8f,94,0a,12,74,30,a3,af,99,aa,c7,4e,f6,90,f2,fc,a3,bc,\
3b,b0,0c,74,50,1d,e1,f8,a0,aa,a2,87,ba,35,a7,61,5b,4b,6d,44,82,ac,54,7a,40,\
33,ff,5c,7c,5e,53,64,34,b8,12,cf,c2,e4,a8,5e,64,e6,8e,91,ae,a0,fc,0c,c9,21,\
28,28,ce,f7,e0,da,75,87,73,47,e9,fc,ad,38,ac,1d,e2,72,35,69,2a,22,9c,53,3a,\
87,bb,f3,8a,b6,98,6b,6f,05,bf,9b,15,39,3f,f0,98,e2,3d,d5,e7,1f,8d,1b,8f,5e,\
72,72,c0,8d,bd,fb,67,2e,8e,39,39,91,4d,60,bd,5a,2d,06,85,7e,d9,3a,66,9b,33,\
8e,fe,aa,f0,21,bb,55,43,56,f2,c4,88,d3,37,3f,fd,78,a5,04,e2,8d,dd,eb,2f,ab,\
4d,d1,4a,d4,0c,32,05,8c,81,c6,f1,d3,c8,98,69,a6,bc,7d,4d,11,77,c3,2e,d2,79,\
33,5c,58,56,09,4f,ea,89,dd,50,d1,9f,26,b8,38,c4,14,38,cd,f6,b5,78,b4,4f,f1,\
05,88,ef,9a,47,b0,5a,42,82,8d,7b,af,9c,2f,6e,80,39,07,7f,cf,59,be,99,1e,5d,\
a0,fd,5b,c7,84,8a,65,9d,5d,c7,7c,76,12,c6,da,fb,be,85,11,de,d4,fc,cc,57,2c,\
59,f5,46,50,fa,5e,64,41,42,d7,5e,d2,f4,51,41,c5,de,95,58,6e,e7,f6,fb,5e,a2,\
85,4b,fb,8b,4a,97,f6,47,3e,93,38,8c,1c,b1,06,ca,19,e4,8f,e7,eb,20,41,0c,db,\
8b,2b,7e,e1,00,72,c1,73,15,ba,68,a0,72,1b,fc,ee,5d,d5,03,ca,13,3a,a3,c3,c5,\
0b,96,f7,f3,24,bf,ed,75,57,bd,79,4a,75,4c,36,3d,83,2c,db,55,f5,db,86,fd,e4,\
78,08,32,3f,e3,90,cc,aa,54,07,39,ee,3e,2c,37,0a,05,50,7c,73,3a,14,d7,7f,f6,\
c5,06,de,a4,0a,9e,21,13,f0,79,e1,a4,32,97,0e,d7,59,33,9b,2f,06,3d,b0,e1,08,\
70,f5,8b,1d,0c,22,03,52,68,aa,1d,b0,c3,ae,9b,15,fb,5a,68,22,19,76,48,66,b9,\
f9,11,61,78,2b,cb,cc,41,26,ff,f3,df,c2,d3,a6,40,c2,d3,ae,40,c2,d3,a6,c0
"rkeysecu"=hex:33,60,df,fe,c0,4f,93,a4,c7,8d,21,61,9b,30,19,15
.
Heure de fin: 2009-01-06 11:21:40
ComboFix-quarantined-files.txt 2009-01-06 10:21:36
ComboFix2.txt 2009-01-06 00:15:52
Avant-CF: 76 760 920 064 octets libres
Après-CF: 76,749,733,888 octets libres
266 --- E O F --- 2008-12-18 11:00:37
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:26, on 06/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1225201271906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Scan saved at 11:32:26, on 06/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1225201271906
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
non,c'est cool ellle sont dégommée
fais ceci pour terminer
tu peux faire un scan de vulnérabilités afin de vérifier que tes logiciels soit bien à jour et sans failles de sécurités.
https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
ou ici:
http://alt-shift-return.org/Info/Update_Checker.html
ensuite
Télécharge ToolsCleaner sur ton bureau.
-->
http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner
# Clique sur "Recherche" et laisse le scan agir ...
# Clique sur "Suppression" pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
ensuite
Télécharges : - CCleaner (n'installe pas la barre d'outil Yahoo)
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).
Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
---> Utilisation:
! déconnectes toi et fermes toutes applications en cours !
* vas dans "nettoyeur" : fait analyse puis nettoyage
* vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )
***très important***
Suppression des points de restauration :
1.Ouvre le Menu Démarrer
2.Clique-droit sur Poste de travail
3.Clique sur Propriétés
4.Positionne-toi dans l'onglet Restauration du système
5.Coche "Désactiver la restauration système"
6.Valide par Ok
7.Redémarre ton pc
8.Reproduis les manipulations 1 à 3
9.Décoche "Désactiver la restauration système"
10.Valide par Ok
sous vista
https://www.01net.com/actualites/
http://www.commentcamarche.net/faq/sujet 13214 desactiver reactiver la restauration systeme de vista
Ne pas oublier de créer un nouveau point de restauration en procédant comme indiqué sur le lien ci dessous
https://www.vulgarisation-informatique.com/creer-point-restauration.php
si tu n as pas d autres soucis change le statut du sujet en resolu stp
fais ceci pour terminer
tu peux faire un scan de vulnérabilités afin de vérifier que tes logiciels soit bien à jour et sans failles de sécurités.
https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
ou ici:
http://alt-shift-return.org/Info/Update_Checker.html
ensuite
Télécharge ToolsCleaner sur ton bureau.
-->
http://www.commentcamarche.net/telecharger/telechargement 34055291 toolscleaner
# Clique sur "Recherche" et laisse le scan agir ...
# Clique sur "Suppression" pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
ensuite
Télécharges : - CCleaner (n'installe pas la barre d'outil Yahoo)
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).
Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
---> Utilisation:
! déconnectes toi et fermes toutes applications en cours !
* vas dans "nettoyeur" : fait analyse puis nettoyage
* vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )
***très important***
Suppression des points de restauration :
1.Ouvre le Menu Démarrer
2.Clique-droit sur Poste de travail
3.Clique sur Propriétés
4.Positionne-toi dans l'onglet Restauration du système
5.Coche "Désactiver la restauration système"
6.Valide par Ok
7.Redémarre ton pc
8.Reproduis les manipulations 1 à 3
9.Décoche "Désactiver la restauration système"
10.Valide par Ok
sous vista
https://www.01net.com/actualites/
http://www.commentcamarche.net/faq/sujet 13214 desactiver reactiver la restauration systeme de vista
Ne pas oublier de créer un nouveau point de restauration en procédant comme indiqué sur le lien ci dessous
https://www.vulgarisation-informatique.com/creer-point-restauration.php
si tu n as pas d autres soucis change le statut du sujet en resolu stp
merci beaucoup chimay mais je dois partir travailler je termine vers 21h et te tiens au courant des que je rentre
merci encore a ce soir si ca te derange pas. biz
merci encore a ce soir si ca te derange pas. biz