A l'aide!! jai des virus impossible a enlevé
Fermé
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
-
29 janv. 2009 à 08:27
djslimd Messages postés 35 Date d'inscription lundi 3 novembre 2008 Statut Membre Dernière intervention 29 mars 2009 - 23 févr. 2009 à 21:28
djslimd Messages postés 35 Date d'inscription lundi 3 novembre 2008 Statut Membre Dernière intervention 29 mars 2009 - 23 févr. 2009 à 21:28
A voir également:
- A l'aide!! jai des virus impossible a enlevé
- Youtu.be virus - Accueil - Guide virus
- Svchost.exe virus - Guide
- Faux message virus ordinateur - Accueil - Arnaque
- Virus mcafee - Accueil - Piratage
- Softonic virus ✓ - Forum Virus
36 réponses
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
30 janv. 2009 à 18:11
30 janv. 2009 à 18:11
OUI je l'ai bien désinstaller , jai dalleur mon ordi qui me le signal a chaque démarrage que je n'ai plus d'antivirus.
VOICI LE NOUVEAU RAPPORT HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:25, on 26/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\vVX1000.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MONET\AppData\Local\ajeojs.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchg.symantec.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WMBoot] C:\Program Files\Logitech\WingMan Profiler\ChekList.exe -L:E:\WS\FRA\Setup.exe -CD -CL4 -LP:" reboot"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUpldfr-fr.cab
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IntelDHSvcConf - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
VOICI LE NOUVEAU RAPPORT HijackThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:25, on 26/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\vVX1000.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MONET\AppData\Local\ajeojs.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchg.symantec.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WMBoot] C:\Program Files\Logitech\WingMan Profiler\ChekList.exe -L:E:\WS\FRA\Setup.exe -CD -CL4 -LP:" reboot"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUpldfr-fr.cab
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IntelDHSvcConf - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
30 janv. 2009 à 18:13
30 janv. 2009 à 18:13
PS : je n'ai pas yahoo sur mon ordinateur pourtant il apparait dans le rapport , et je n'arrive pas a le supprimer.
chimay8
Messages postés
7720
Date d'inscription
jeudi 1 mai 2008
Statut
Contributeur sécurité
Dernière intervention
3 janvier 2014
60
30 janv. 2009 à 18:28
30 janv. 2009 à 18:28
bon,
c'est encore bourré de saloperie
relance hijack(scan only) et coche ces lignes
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Empowering Technology Launcher.lnk =
clic sur fix checked
ensuite
Télécharge OTMoveIt3( de Old Timer )
http://oldtimer.geekstogo.com/OTMoveIt3.exe
Une fois téléchargé double-clique sur OTMoveIt3.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" est cochée
Copie les lignes(qui sont en gras) qui se trouvent en dessous :
:Processes
explorer.exe
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E015787-B1E3-404a-95DE-3E71E1FA0305}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E015787-B1E3-404a-95DE-3E71E1FA0305}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"winlogon"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"spa_start"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ajeojs"=-
:Files
c:\users\monet\appdata\local\ajeojs.exe
c:\windows\system32\mysidesearch_sidebar.dll
c:\windows\system32\nspcf6b.dll
c:\windows\system32\sprt_ads.dll
c:\windows\system32\spads.dll
c:\windows\winlogon.exe
c:\windows\system32\rundll32.exe
:Commands
[emptytemp]
[start explorer]
[Reboot]
et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
-Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )
/!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître, dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi sur l'onglet "Processus". Clique en haut à gauche sur "Fichiers" et choisis "Exécuter"
Tape "explorer.exe"(sans les guillemèts) et valide. Cela fera réapparaître le Bureau.
*************************************
ensuite
Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
**Désactive les logiciels de protection** (Antivirus, Antispywares) puis :
deconnecte toi d'internet,ferme tout les programmes
Double-clique sur combofix,si il te demande d'installer la console,fais le(voir plus bas)
ensuite,
il va te poser une question, réponds par la touche 1 et entrée pour valider.
ne touche plus à rien, même pas ta souris!!
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
c'est encore bourré de saloperie
relance hijack(scan only) et coche ces lignes
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Global Startup: Empowering Technology Launcher.lnk =
clic sur fix checked
ensuite
Télécharge OTMoveIt3( de Old Timer )
http://oldtimer.geekstogo.com/OTMoveIt3.exe
Une fois téléchargé double-clique sur OTMoveIt3.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" est cochée
Copie les lignes(qui sont en gras) qui se trouvent en dessous :
:Processes
explorer.exe
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E015787-B1E3-404a-95DE-3E71E1FA0305}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E015787-B1E3-404a-95DE-3E71E1FA0305}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"winlogon"=-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"spa_start"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ajeojs"=-
:Files
c:\users\monet\appdata\local\ajeojs.exe
c:\windows\system32\mysidesearch_sidebar.dll
c:\windows\system32\nspcf6b.dll
c:\windows\system32\sprt_ads.dll
c:\windows\system32\spads.dll
c:\windows\winlogon.exe
c:\windows\system32\rundll32.exe
:Commands
[emptytemp]
[start explorer]
[Reboot]
et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
-Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )
/!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître, dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi sur l'onglet "Processus". Clique en haut à gauche sur "Fichiers" et choisis "Exécuter"
Tape "explorer.exe"(sans les guillemèts) et valide. Cela fera réapparaître le Bureau.
*************************************
ensuite
Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
**Désactive les logiciels de protection** (Antivirus, Antispywares) puis :
deconnecte toi d'internet,ferme tout les programmes
Double-clique sur combofix,si il te demande d'installer la console,fais le(voir plus bas)
ensuite,
il va te poser une question, réponds par la touche 1 et entrée pour valider.
ne touche plus à rien, même pas ta souris!!
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
31 janv. 2009 à 16:00
31 janv. 2009 à 16:00
VOICI LE RAPPORT , PAR CONTRE MAINTENANT ,QUAND JE FAIT UNE RECHERCHE GOOGLE, , ET QUE J'AI VOULUE ALLEZ SUR CE SITE , JAI EU UNE PAGE D'AVERTISSEMENT ? QUI DISAIT QUE :
Avertissement- Attention, l'accès à ce site risque d'endommager votre ordinateur.
Suggestions :
* Accédez à la page précédente et sélectionnez un autre résultat.
* Modifiez votre recherche pour trouver ce que vous cherchez.
Vous pouvez également accéder à https://www.commentcamarche.net/ à vos propres risques. Pour obtenir des informations détaillées sur les problèmes que nous avons rencontrés, consultez la page de diagnostic de la Navigation sécurisée de Google concernant ce site.
Pour plus d'informations sur la façon de vous protéger contre les logiciels nuisibles lorsque vous surfez, consultez le site StopBadware.org.
Si vous êtes le propriétaire de ce site, vous pouvez en demander l'examen à l'aide des Outils pour les webmasters. Pour plus d'informations sur le processus de révision, consultez le Centre d'aide des webmasters de Google.
Avertissement fourni par Google
COMMENT L'ENLEVER?
LE RAPPORT :
ComboFix 09-01-21.04 - MONET 2009-01-31 15:30:43.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2046.1032 [GMT 1:00]
Lancé depuis: c:\users\MONET\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *disabled*
* Un nouveau point de restauration a été créé
.
- Mode FONCTIONNALITES REDUITES -
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\EV02
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-31 ))))))))))))))))))))))))))))))))))))
.
2009-01-31 14:02 . 2009-01-31 14:02 <REP> d-------- C:\_OTMoveIt
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\MONET\AppData\Roaming\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\programdata\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-29 15:56 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-29 15:56 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-29 10:49 . 2009-01-29 15:45 <REP> d-------- C:\ToolBar SD
2009-01-29 09:02 . 2009-01-29 11:38 <REP> d-------- c:\program files\Navilog1
2009-01-29 09:00 . 2009-01-29 09:00 2 --a------ C:\542985663
2009-01-28 11:34 . 2009-01-28 11:35 <REP> d-------- c:\program files\Common Files\Adobe
2009-01-28 11:34 . 2009-01-28 11:34 <REP> d-------- c:\program files\Adobe(0)
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\users\All Users\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\programdata\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\program files\NOS
2009-01-02 11:53 . 2009-01-02 11:53 20,224 --a------ c:\users\MONET\HAesIhwnEI.exe
2009-01-02 11:44 . 2009-01-02 11:44 17,792 --a------ c:\users\MONET\u1a0dq7MoX.exe
2008-12-30 19:58 . 2008-12-30 19:58 138,368 --a------ c:\windows\System32\drivers\sp_rsdrv2.sys
2008-12-30 17:42 . 2008-12-30 17:42 <REP> d-------- c:\users\All Users\Lavasoft
2008-12-30 17:42 . 2008-12-30 17:42 <REP> d-------- c:\programdata\Lavasoft
2008-12-30 17:42 . 2008-12-30 17:42 <REP> d-------- c:\program files\Lavasoft
2008-12-30 17:40 . 2008-12-30 17:40 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-30 17:37 . 2008-12-30 17:37 <REP> d-------- c:\users\MONET\AppData\Roaming\Application Data
2008-12-30 17:37 . 2009-01-29 09:21 <REP> d-------- c:\users\All Users\Spyware Terminator
2008-12-30 17:37 . 2009-01-29 09:21 <REP> d-------- c:\programdata\Spyware Terminator
2008-12-30 17:37 . 2009-01-29 18:32 <REP> d-------- c:\program files\Spyware Terminator
2008-12-16 17:35 . 2008-12-16 17:35 <REP> d-------- c:\program files\CCleaner
2008-12-14 19:00 . 2008-12-14 19:00 <REP> d-------- c:\windows\System32\whSLD02
2008-12-14 19:00 . 2008-12-14 19:00 <REP> d-------- c:\temp\REX81
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-31 13:10 28,714,496 ----a-w c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
2009-01-31 13:04 352,614 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2009-01-30 14:42 19,182,459 ----a-w c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
2009-01-29 17:32 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-01-29 17:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-29 17:19 --------- d-----w c:\programdata\Symantec
2009-01-26 16:35 --------- d-----w c:\program files\Google
2009-01-17 22:00 1,893,376 ----a-w c:\windows\Internet Logs\xDBD273.tmp
2009-01-02 17:02 --------- d-----w c:\program files\SniffPass
2009-01-02 15:56 22 ----a-w c:\users\MONET\a.zip
2008-12-30 11:32 7,077,095 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-12-22 10:02 584,192 ----a-w c:\windows\Internet Logs\xDBBA57.tmp
2008-12-22 10:02 1,838,080 ----a-w c:\windows\Internet Logs\xDBBDE2.tmp
2008-12-19 20:01 1,835,008 ----a-w c:\windows\Internet Logs\xDBEA7F.tmp
2008-12-19 17:08 1,834,496 ----a-w c:\windows\Internet Logs\xDBBA76.tmp
2008-12-17 17:47 1,831,424 ----a-w c:\windows\Internet Logs\xDBC69B.tmp
2008-12-16 22:58 59,392 ----a-w c:\windows\Internet Logs\xDBCBAC.tmp
2008-12-16 16:28 2,646,016 ----a-w c:\windows\Internet Logs\xDBAA3A.tmp
2008-12-16 13:15 --------- d-----w c:\users\MONET\AppData\Roaming\LimeWire
2008-12-09 20:47 3,752 ----a-w c:\users\MONET\AppData\Roaming\wklnhst.dat
2008-12-04 10:59 --------- d-----w c:\programdata\Microsoft Help
2008-12-01 13:56 --------- d-----w c:\program files\Yahoo!
2008-11-30 11:07 --------- d-----w c:\programdata\Yahoo!
2008-11-20 16:01 83,456 ----a-w c:\windows\System32\wudriver.dll
2008-11-20 16:01 561,688 ----a-w c:\windows\System32\wuapi.dll
2008-11-20 16:01 51,224 ----a-w c:\windows\System32\wuauclt.exe
2008-11-20 16:01 43,544 ----a-w c:\windows\System32\wups2.dll
2008-11-20 16:01 34,328 ----a-w c:\windows\System32\wups.dll
2008-11-20 16:01 1,809,944 ----a-w c:\windows\System32\wuaueng.dll
2008-11-20 16:01 1,524,736 ----a-w c:\windows\System32\wucltux.dll
2008-11-20 16:00 31,232 ----a-w c:\windows\System32\wuapp.exe
2008-11-20 16:00 162,064 ----a-w c:\windows\System32\wuwebv.dll
2008-11-08 12:39 2,621,440 ----a-w c:\windows\Internet Logs\xDBF184.tmp
2008-10-19 17:23 147,456 ----a-w c:\users\MONET\vbzip10.dll
2008-10-19 17:21 511 ----a-w c:\users\MONET\899.bat
2008-10-19 17:20 68 ----a-w c:\users\MONET\z.bat
2007-10-28 11:00 174 --sha-w c:\program files\desktop.ini
2006-05-03 09:06 163,328 --sh--r c:\windows\System32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\System32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-03-22 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-22 8425472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-22 81920]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-06 707360]
"MaxBlastMonitor.exe"="c:\program files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-08-08 1169440]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"AcronisTimounterMonitor"="c:\program files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 1945448]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-11-15 151552]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 148760]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-12-30 2735616]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-04-20 528384]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
PCM Media Sharing.lnk - c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-04-20 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
"msacm.fraunhoferacm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ ?ü??ü???\[u]0/ulsdelete\[u]0/u
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"ajeojs"=c:\users\monet\appdata\local\ajeojs.exe ajeojs
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
"205d4d10"=rundll32.exe "c:\users\MONET\AppData\Local\Temp\lsvalhff.dll",b
"cmds"=rundll32.exe c:\users\MONET\AppData\Local\Temp\tuvSkLcY.dll,c
"MSServer"=rundll32.exe c:\users\MONET\AppData\Local\Temp\nnnmlKCT.dll,#1
"LSA Shellu"=c:\users\MONET\lsass.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ALUAlert"=c:\program files\Symantec\LiveUpdate\ALuNotify.exe
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe"
"WarReg_PopUp"=c:\acer\WR_PopUp\WarReg_PopUp.exe
"Acer Empowering Technology Monitor"=c:\acer\Empowering Technology\SysMonitor.exe
"MSServer"=rundll32.exe c:\windows\system32\ddcYqrpM.dll,#1
"RtHDVCpl"=RtHDVCpl.exe
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe"
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BB82DE3E-0D30-4A0E-A4DE-24FEE90A20B8}"= Profile=Private|c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{30C66B97-5348-432C-8C8D-FDC5D53398A8}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{1E17540B-C6F2-4603-B6BB-FCF18E577BD7}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{FABD7FB2-EB66-446D-B88F-9BBF64D3EC89}"= c:\program files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{94D99930-8327-4375-9044-66379D3E2AB6}"= c:\program files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{6195F082-0459-41EC-98AD-25E7EDDB9082}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{EAE4E69B-2B6D-4112-AE38-9A20F6A4089C}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{DC6AA3C5-B182-4B2C-A647-820993D94A25}"= c:\program files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{F9EEAD95-DBAD-4A39-AE68-07DD01DE7DD5}"= c:\program files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{3E4CEE3D-74AD-4AE3-9930-49A16845202C}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{19940BEA-3D80-457B-B109-2ED69152588B}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FDCF21D8-3960-41C2-AF8B-9B11173EAB65}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{854C3A2B-6210-4FE2-9739-BE62A579896E}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{F71AB188-A47C-4163-86DE-446E70AE531D}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{1D76D64F-1929-46A7-A8E0-1CE511E95F33}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{EA2F1D41-8B9C-4000-BD64-593A114963A6}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{45555AA4-68D7-45C5-8383-CA0E19C9C1ED}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{CA43BADD-AE70-4138-993F-E2F6F8E350A9}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{1616121A-0B41-4070-A213-3CD9859457B2}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{F71FF062-43F6-4F5E-8B62-EF6408958206}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{08835A44-3D31-4545-92AE-88629986867D}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{2390B826-08FC-477E-AC9A-E5B79D04A6D3}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{8F6291EC-6803-41B7-B8A6-FA37415D1F6C}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{7FA3D92F-D4EA-411C-8081-8F38DFA8249A}"= UDP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{1199F163-9C05-4F93-8B6F-ADCDD867D93B}"= TCP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{F8E85458-EDBA-4B4B-AECC-D2CD1C97478C}"= UDP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"{B9FC6A35-2ECA-4035-A649-5E8C7B069323}"= TCP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"TCP Query User{B5BA147C-A6A8-47F4-8FCE-BB70E1816A45}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"UDP Query User{11FB6107-55D6-4113-8E9D-F49AF248BA06}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"TCP Query User{2CC372CC-A817-40AD-B36D-94D78135DC32}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"UDP Query User{D38265CC-ACDE-41B9-997B-2EB76D5576A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"TCP Query User{0FF6B665-943E-4F39-90B9-BAF9BC4A630E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"UDP Query User{DB50AF0B-6575-4BFD-95B1-7F2E50D24656}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"TCP Query User{7A4D10CC-2EE6-4E88-9304-A725FDD48573}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"UDP Query User{C7F78B6F-D4CF-4915-9A69-CE7376B4BF12}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"TCP Query User{FC87378F-96F8-4CB3-9CA1-2EC2CBB6E4AF}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"UDP Query User{009A94A2-27D4-4684-BE6D-520BC29E8CD9}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"TCP Query User{EC98FAC6-624F-42F1-B1F4-69AE2BB45D82}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"UDP Query User{E61928B4-A41E-41E1-918C-13CFFACF4B02}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"TCP Query User{27947143-2540-4752-B82F-CF61E3D6247F}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"UDP Query User{0B2E734B-4146-4594-BC69-2811BD2F09F8}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"TCP Query User{FF9E006B-F93B-4F2A-A4DB-FA09B26F5BA0}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"UDP Query User{30E149FD-EAF0-4546-962B-2D8CAEE4F632}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"TCP Query User{1CCF575B-BA1B-43BA-8DC9-18248B30D8E7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"UDP Query User{8C8A4410-5058-49B2-A967-6DBA3BA45105}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"TCP Query User{53C58EFE-7452-49DB-B75C-7C75782C5C6A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"UDP Query User{F6F7C8AE-58B5-4B31-96F1-1253DB6CDDB2}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"TCP Query User{263F051A-6642-49C1-BD81-B9735D9E0CFB}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"UDP Query User{5EC39034-5A0C-4E91-9789-AB4656F082F5}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"TCP Query User{AC1AD9B1-8464-4A7C-8B38-773D70BABD46}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"UDP Query User{D8257A5C-5ED6-47C6-AC48-297DC8ED30BD}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"TCP Query User{FC74C1C4-8C09-44F3-AA57-1F4F9090008A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"UDP Query User{68D1899D-88C3-4385-B8DF-A6ED49BBF172}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"TCP Query User{98FCE685-2D95-45D2-B6CB-5A477DB6B9A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"UDP Query User{8061A454-4D88-4FC7-8073-CFE5E0BB6B7E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"TCP Query User{51D46E30-41D3-415B-A79B-DDD4E9FD8161}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8F2ABA34-40E4-4A1C-879E-13C5C9DB446A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{E55EF3BB-309C-4FDD-9F21-2E86F7EA632D}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"UDP Query User{718238A3-7245-48E5-A510-75131F5A122E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"TCP Query User{D53090B0-977F-4C97-9713-9BA0D2D7A036}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"UDP Query User{72F64873-372A-45D6-92CB-97D59522023E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"{A9B38984-92D2-4581-96DB-B45A931E0641}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{BC3F088F-247E-4671-81D5-CEE0EE63AFF0}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4E44F572-C3C4-47F4-BC3C-49F52057B5DA}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A225D047-5E4E-4EEE-9631-8ED889B824AA}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{BA2265CC-9472-4F41-A318-C8F786F5425B}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8B948B46-4EFB-419D-8D00-D3C1B75D771D}"= Disabled:c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{3EB26DA4-763A-4683-92A3-A71120090234}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CB2BB86F-271A-46B8-B21B-6CF1BC62FF62}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AD2D0A66-BF37-434A-8E3E-6815AC75E9DC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A2BC7ACF-78A5-40FD-BAF4-D0616BEF345D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FE91996D-586F-445B-AFAE-DB83F567B113}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{3B3B9A4F-11CB-4ED3-BFAA-A5D060168422}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{B66FA882-9689-443E-8EDE-AA4ADBD7E93C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{DF5CD41B-22EF-456C-B1D1-675235E6742B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1C9849AF-BACE-4AD4-B155-42E332973342}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DEEBE6BD-E5FA-4D01-BE38-57E7CE70F454}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E7C84905-617F-40B5-B156-629CDE1F244E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CEAE3139-1D98-4E8C-8C90-F4BFB3890B4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [2008-12-30 138368]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [2007-08-14 5504]
R4 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-20 266343]
R4 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R4 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [2006-09-27 28672]
R4 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [2006-10-19 7424]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-05-24 810320]
S3 BthAvrcp;Profil AVRCP Bluetooth;c:\windows\System32\drivers\BthAvrcp.sys [2007-08-24 15872]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-28 33752]
S3 IntelDHSvcConf;IntelDHSvcConf;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [2006-11-18 36312]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;c:\windows\System32\drivers\usbiad.sys [2005-06-13 31579]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
\shell\AutoRun\command - E:\Startup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-14 c:\windows\Tasks\ahkavddq.job
- c:\users\MONET\AppData\Local\Temp\khfdcCTn.dll []
2009-01-30 c:\windows\Tasks\Norton Internet Security - Analyse système complète - MONET.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
2009-01-31 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Acer Tour Reminder - (no file)
HKLM-Run-SSBkgdUpdate - c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
HKLM-Run-WMBoot - c:\program files\Logitech\WingMan Profiler\ChekList.exe -L:e:\ws\FRA\Setup.exe
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sfr.fr/kit/adsl/
mWindow Title =
uInternet Settings,ProxyServer = <local>
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\MONET\AppData\Roaming\Mozilla\Firefox\Profiles\p2pk2ktf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://fr-fr.facebook.com/
.
.
------- Associations de fichier -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-31 15:31:02
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'Explorer.exe'(4528)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Heure de fin: 2009-01-31 15:33:00
ComboFix-quarantined-files.txt 2009-01-31 14:32:57
Avant-CF: 105 318 973 440 octets libres
Après-CF: 105,287,651,328 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
334 --- E O F --- 2008-02-14 17:29:42
Avertissement- Attention, l'accès à ce site risque d'endommager votre ordinateur.
Suggestions :
* Accédez à la page précédente et sélectionnez un autre résultat.
* Modifiez votre recherche pour trouver ce que vous cherchez.
Vous pouvez également accéder à https://www.commentcamarche.net/ à vos propres risques. Pour obtenir des informations détaillées sur les problèmes que nous avons rencontrés, consultez la page de diagnostic de la Navigation sécurisée de Google concernant ce site.
Pour plus d'informations sur la façon de vous protéger contre les logiciels nuisibles lorsque vous surfez, consultez le site StopBadware.org.
Si vous êtes le propriétaire de ce site, vous pouvez en demander l'examen à l'aide des Outils pour les webmasters. Pour plus d'informations sur le processus de révision, consultez le Centre d'aide des webmasters de Google.
Avertissement fourni par Google
COMMENT L'ENLEVER?
LE RAPPORT :
ComboFix 09-01-21.04 - MONET 2009-01-31 15:30:43.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2046.1032 [GMT 1:00]
Lancé depuis: c:\users\MONET\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *disabled*
* Un nouveau point de restauration a été créé
.
- Mode FONCTIONNALITES REDUITES -
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\EV02
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-31 ))))))))))))))))))))))))))))))))))))
.
2009-01-31 14:02 . 2009-01-31 14:02 <REP> d-------- C:\_OTMoveIt
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\MONET\AppData\Roaming\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\programdata\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-29 15:56 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-29 15:56 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-29 10:49 . 2009-01-29 15:45 <REP> d-------- C:\ToolBar SD
2009-01-29 09:02 . 2009-01-29 11:38 <REP> d-------- c:\program files\Navilog1
2009-01-29 09:00 . 2009-01-29 09:00 2 --a------ C:\542985663
2009-01-28 11:34 . 2009-01-28 11:35 <REP> d-------- c:\program files\Common Files\Adobe
2009-01-28 11:34 . 2009-01-28 11:34 <REP> d-------- c:\program files\Adobe(0)
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\users\All Users\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\programdata\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\program files\NOS
2009-01-02 11:53 . 2009-01-02 11:53 20,224 --a------ c:\users\MONET\HAesIhwnEI.exe
2009-01-02 11:44 . 2009-01-02 11:44 17,792 --a------ c:\users\MONET\u1a0dq7MoX.exe
2008-12-30 19:58 . 2008-12-30 19:58 138,368 --a------ c:\windows\System32\drivers\sp_rsdrv2.sys
2008-12-30 17:42 . 2008-12-30 17:42 <REP> d-------- c:\users\All Users\Lavasoft
2008-12-30 17:42 . 2008-12-30 17:42 <REP> d-------- c:\programdata\Lavasoft
2008-12-30 17:42 . 2008-12-30 17:42 <REP> d-------- c:\program files\Lavasoft
2008-12-30 17:40 . 2008-12-30 17:40 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-30 17:37 . 2008-12-30 17:37 <REP> d-------- c:\users\MONET\AppData\Roaming\Application Data
2008-12-30 17:37 . 2009-01-29 09:21 <REP> d-------- c:\users\All Users\Spyware Terminator
2008-12-30 17:37 . 2009-01-29 09:21 <REP> d-------- c:\programdata\Spyware Terminator
2008-12-30 17:37 . 2009-01-29 18:32 <REP> d-------- c:\program files\Spyware Terminator
2008-12-16 17:35 . 2008-12-16 17:35 <REP> d-------- c:\program files\CCleaner
2008-12-14 19:00 . 2008-12-14 19:00 <REP> d-------- c:\windows\System32\whSLD02
2008-12-14 19:00 . 2008-12-14 19:00 <REP> d-------- c:\temp\REX81
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-31 13:10 28,714,496 ----a-w c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
2009-01-31 13:04 352,614 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2009-01-30 14:42 19,182,459 ----a-w c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
2009-01-29 17:32 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-01-29 17:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-29 17:19 --------- d-----w c:\programdata\Symantec
2009-01-26 16:35 --------- d-----w c:\program files\Google
2009-01-17 22:00 1,893,376 ----a-w c:\windows\Internet Logs\xDBD273.tmp
2009-01-02 17:02 --------- d-----w c:\program files\SniffPass
2009-01-02 15:56 22 ----a-w c:\users\MONET\a.zip
2008-12-30 11:32 7,077,095 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-12-22 10:02 584,192 ----a-w c:\windows\Internet Logs\xDBBA57.tmp
2008-12-22 10:02 1,838,080 ----a-w c:\windows\Internet Logs\xDBBDE2.tmp
2008-12-19 20:01 1,835,008 ----a-w c:\windows\Internet Logs\xDBEA7F.tmp
2008-12-19 17:08 1,834,496 ----a-w c:\windows\Internet Logs\xDBBA76.tmp
2008-12-17 17:47 1,831,424 ----a-w c:\windows\Internet Logs\xDBC69B.tmp
2008-12-16 22:58 59,392 ----a-w c:\windows\Internet Logs\xDBCBAC.tmp
2008-12-16 16:28 2,646,016 ----a-w c:\windows\Internet Logs\xDBAA3A.tmp
2008-12-16 13:15 --------- d-----w c:\users\MONET\AppData\Roaming\LimeWire
2008-12-09 20:47 3,752 ----a-w c:\users\MONET\AppData\Roaming\wklnhst.dat
2008-12-04 10:59 --------- d-----w c:\programdata\Microsoft Help
2008-12-01 13:56 --------- d-----w c:\program files\Yahoo!
2008-11-30 11:07 --------- d-----w c:\programdata\Yahoo!
2008-11-20 16:01 83,456 ----a-w c:\windows\System32\wudriver.dll
2008-11-20 16:01 561,688 ----a-w c:\windows\System32\wuapi.dll
2008-11-20 16:01 51,224 ----a-w c:\windows\System32\wuauclt.exe
2008-11-20 16:01 43,544 ----a-w c:\windows\System32\wups2.dll
2008-11-20 16:01 34,328 ----a-w c:\windows\System32\wups.dll
2008-11-20 16:01 1,809,944 ----a-w c:\windows\System32\wuaueng.dll
2008-11-20 16:01 1,524,736 ----a-w c:\windows\System32\wucltux.dll
2008-11-20 16:00 31,232 ----a-w c:\windows\System32\wuapp.exe
2008-11-20 16:00 162,064 ----a-w c:\windows\System32\wuwebv.dll
2008-11-08 12:39 2,621,440 ----a-w c:\windows\Internet Logs\xDBF184.tmp
2008-10-19 17:23 147,456 ----a-w c:\users\MONET\vbzip10.dll
2008-10-19 17:21 511 ----a-w c:\users\MONET\899.bat
2008-10-19 17:20 68 ----a-w c:\users\MONET\z.bat
2007-10-28 11:00 174 --sha-w c:\program files\desktop.ini
2006-05-03 09:06 163,328 --sh--r c:\windows\System32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\System32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-03-22 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-22 8425472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-22 81920]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-06 707360]
"MaxBlastMonitor.exe"="c:\program files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-08-08 1169440]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"AcronisTimounterMonitor"="c:\program files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 1945448]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-11-15 151552]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 148760]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-12-30 2735616]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-04-20 528384]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
PCM Media Sharing.lnk - c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-04-20 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
"msacm.fraunhoferacm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ ?ü??ü???\[u]0/ulsdelete\[u]0/u
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"ajeojs"=c:\users\monet\appdata\local\ajeojs.exe ajeojs
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
"205d4d10"=rundll32.exe "c:\users\MONET\AppData\Local\Temp\lsvalhff.dll",b
"cmds"=rundll32.exe c:\users\MONET\AppData\Local\Temp\tuvSkLcY.dll,c
"MSServer"=rundll32.exe c:\users\MONET\AppData\Local\Temp\nnnmlKCT.dll,#1
"LSA Shellu"=c:\users\MONET\lsass.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ALUAlert"=c:\program files\Symantec\LiveUpdate\ALuNotify.exe
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe"
"WarReg_PopUp"=c:\acer\WR_PopUp\WarReg_PopUp.exe
"Acer Empowering Technology Monitor"=c:\acer\Empowering Technology\SysMonitor.exe
"MSServer"=rundll32.exe c:\windows\system32\ddcYqrpM.dll,#1
"RtHDVCpl"=RtHDVCpl.exe
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe"
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BB82DE3E-0D30-4A0E-A4DE-24FEE90A20B8}"= Profile=Private|c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{30C66B97-5348-432C-8C8D-FDC5D53398A8}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{1E17540B-C6F2-4603-B6BB-FCF18E577BD7}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{FABD7FB2-EB66-446D-B88F-9BBF64D3EC89}"= c:\program files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{94D99930-8327-4375-9044-66379D3E2AB6}"= c:\program files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{6195F082-0459-41EC-98AD-25E7EDDB9082}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{EAE4E69B-2B6D-4112-AE38-9A20F6A4089C}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{DC6AA3C5-B182-4B2C-A647-820993D94A25}"= c:\program files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{F9EEAD95-DBAD-4A39-AE68-07DD01DE7DD5}"= c:\program files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{3E4CEE3D-74AD-4AE3-9930-49A16845202C}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{19940BEA-3D80-457B-B109-2ED69152588B}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FDCF21D8-3960-41C2-AF8B-9B11173EAB65}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{854C3A2B-6210-4FE2-9739-BE62A579896E}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{F71AB188-A47C-4163-86DE-446E70AE531D}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{1D76D64F-1929-46A7-A8E0-1CE511E95F33}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{EA2F1D41-8B9C-4000-BD64-593A114963A6}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{45555AA4-68D7-45C5-8383-CA0E19C9C1ED}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{CA43BADD-AE70-4138-993F-E2F6F8E350A9}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{1616121A-0B41-4070-A213-3CD9859457B2}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{F71FF062-43F6-4F5E-8B62-EF6408958206}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{08835A44-3D31-4545-92AE-88629986867D}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{2390B826-08FC-477E-AC9A-E5B79D04A6D3}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{8F6291EC-6803-41B7-B8A6-FA37415D1F6C}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{7FA3D92F-D4EA-411C-8081-8F38DFA8249A}"= UDP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{1199F163-9C05-4F93-8B6F-ADCDD867D93B}"= TCP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{F8E85458-EDBA-4B4B-AECC-D2CD1C97478C}"= UDP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"{B9FC6A35-2ECA-4035-A649-5E8C7B069323}"= TCP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"TCP Query User{B5BA147C-A6A8-47F4-8FCE-BB70E1816A45}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"UDP Query User{11FB6107-55D6-4113-8E9D-F49AF248BA06}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"TCP Query User{2CC372CC-A817-40AD-B36D-94D78135DC32}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"UDP Query User{D38265CC-ACDE-41B9-997B-2EB76D5576A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"TCP Query User{0FF6B665-943E-4F39-90B9-BAF9BC4A630E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"UDP Query User{DB50AF0B-6575-4BFD-95B1-7F2E50D24656}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"TCP Query User{7A4D10CC-2EE6-4E88-9304-A725FDD48573}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"UDP Query User{C7F78B6F-D4CF-4915-9A69-CE7376B4BF12}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"TCP Query User{FC87378F-96F8-4CB3-9CA1-2EC2CBB6E4AF}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"UDP Query User{009A94A2-27D4-4684-BE6D-520BC29E8CD9}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"TCP Query User{EC98FAC6-624F-42F1-B1F4-69AE2BB45D82}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"UDP Query User{E61928B4-A41E-41E1-918C-13CFFACF4B02}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"TCP Query User{27947143-2540-4752-B82F-CF61E3D6247F}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"UDP Query User{0B2E734B-4146-4594-BC69-2811BD2F09F8}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"TCP Query User{FF9E006B-F93B-4F2A-A4DB-FA09B26F5BA0}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"UDP Query User{30E149FD-EAF0-4546-962B-2D8CAEE4F632}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"TCP Query User{1CCF575B-BA1B-43BA-8DC9-18248B30D8E7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"UDP Query User{8C8A4410-5058-49B2-A967-6DBA3BA45105}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"TCP Query User{53C58EFE-7452-49DB-B75C-7C75782C5C6A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"UDP Query User{F6F7C8AE-58B5-4B31-96F1-1253DB6CDDB2}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"TCP Query User{263F051A-6642-49C1-BD81-B9735D9E0CFB}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"UDP Query User{5EC39034-5A0C-4E91-9789-AB4656F082F5}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"TCP Query User{AC1AD9B1-8464-4A7C-8B38-773D70BABD46}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"UDP Query User{D8257A5C-5ED6-47C6-AC48-297DC8ED30BD}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"TCP Query User{FC74C1C4-8C09-44F3-AA57-1F4F9090008A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"UDP Query User{68D1899D-88C3-4385-B8DF-A6ED49BBF172}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"TCP Query User{98FCE685-2D95-45D2-B6CB-5A477DB6B9A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"UDP Query User{8061A454-4D88-4FC7-8073-CFE5E0BB6B7E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"TCP Query User{51D46E30-41D3-415B-A79B-DDD4E9FD8161}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8F2ABA34-40E4-4A1C-879E-13C5C9DB446A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{E55EF3BB-309C-4FDD-9F21-2E86F7EA632D}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"UDP Query User{718238A3-7245-48E5-A510-75131F5A122E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"TCP Query User{D53090B0-977F-4C97-9713-9BA0D2D7A036}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"UDP Query User{72F64873-372A-45D6-92CB-97D59522023E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"{A9B38984-92D2-4581-96DB-B45A931E0641}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{BC3F088F-247E-4671-81D5-CEE0EE63AFF0}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4E44F572-C3C4-47F4-BC3C-49F52057B5DA}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A225D047-5E4E-4EEE-9631-8ED889B824AA}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{BA2265CC-9472-4F41-A318-C8F786F5425B}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8B948B46-4EFB-419D-8D00-D3C1B75D771D}"= Disabled:c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{3EB26DA4-763A-4683-92A3-A71120090234}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CB2BB86F-271A-46B8-B21B-6CF1BC62FF62}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AD2D0A66-BF37-434A-8E3E-6815AC75E9DC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A2BC7ACF-78A5-40FD-BAF4-D0616BEF345D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FE91996D-586F-445B-AFAE-DB83F567B113}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{3B3B9A4F-11CB-4ED3-BFAA-A5D060168422}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{B66FA882-9689-443E-8EDE-AA4ADBD7E93C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{DF5CD41B-22EF-456C-B1D1-675235E6742B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1C9849AF-BACE-4AD4-B155-42E332973342}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DEEBE6BD-E5FA-4D01-BE38-57E7CE70F454}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E7C84905-617F-40B5-B156-629CDE1F244E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CEAE3139-1D98-4E8C-8C90-F4BFB3890B4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [2008-12-30 138368]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [2007-08-14 5504]
R4 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-20 266343]
R4 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R4 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [2006-09-27 28672]
R4 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [2006-10-19 7424]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-05-24 810320]
S3 BthAvrcp;Profil AVRCP Bluetooth;c:\windows\System32\drivers\BthAvrcp.sys [2007-08-24 15872]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-28 33752]
S3 IntelDHSvcConf;IntelDHSvcConf;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [2006-11-18 36312]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;c:\windows\System32\drivers\usbiad.sys [2005-06-13 31579]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
\shell\AutoRun\command - E:\Startup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-14 c:\windows\Tasks\ahkavddq.job
- c:\users\MONET\AppData\Local\Temp\khfdcCTn.dll []
2009-01-30 c:\windows\Tasks\Norton Internet Security - Analyse système complète - MONET.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
2009-01-31 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Acer Tour Reminder - (no file)
HKLM-Run-SSBkgdUpdate - c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
HKLM-Run-WMBoot - c:\program files\Logitech\WingMan Profiler\ChekList.exe -L:e:\ws\FRA\Setup.exe
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
HKU-Default-Run-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sfr.fr/kit/adsl/
mWindow Title =
uInternet Settings,ProxyServer = <local>
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\MONET\AppData\Roaming\Mozilla\Firefox\Profiles\p2pk2ktf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://fr-fr.facebook.com/
.
.
------- Associations de fichier -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-31 15:31:02
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'Explorer.exe'(4528)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
Heure de fin: 2009-01-31 15:33:00
ComboFix-quarantined-files.txt 2009-01-31 14:32:57
Avant-CF: 105 318 973 440 octets libres
Après-CF: 105,287,651,328 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
334 --- E O F --- 2008-02-14 17:29:42
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
chimay8
Messages postés
7720
Date d'inscription
jeudi 1 mai 2008
Statut
Contributeur sécurité
Dernière intervention
3 janvier 2014
60
31 janv. 2009 à 18:52
31 janv. 2009 à 18:52
on s'en fiche de ce que chante google
par contre j'ai pas le rapport de OtMoveit
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
par contre j'ai pas le rapport de OtMoveit
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
chimay8
Messages postés
7720
Date d'inscription
jeudi 1 mai 2008
Statut
Contributeur sécurité
Dernière intervention
3 janvier 2014
60
31 janv. 2009 à 18:54
31 janv. 2009 à 18:54
regarde ce qu'on dis de google
https://www.serruriergonesse.com/
https://www.serruriergonesse.com/
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
31 janv. 2009 à 19:20
31 janv. 2009 à 19:20
Oui excusez moi je l'avait oublié..
le voici :
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E015787-B1E3-404a-95DE-3E71E1FA0305}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E015787-B1E3-404a-95DE-3E71E1FA0305}\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\winlogon not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\spa_start not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ajeojs not found.
========== FILES ==========
File/Folder c:\users\monet\appdata\local\ajeojs.exe not found.
File/Folder c:\windows\system32\mysidesearch_sidebar.dll not found.
File/Folder c:\windows\system32\nspcf6b.dll not found.
File/Folder c:\windows\system32\sprt_ads.dll not found.
File/Folder c:\windows\system32\spads.dll not found.
File/Folder c:\windows\winlogon.exe not found.
File move failed. c:\windows\system32\rundll32.exe scheduled to be moved on reboot.
========== COMMANDS ==========
File delete failed. C:\Users\MONET\AppData\Local\Temp\etilqs_tXuU0R9cEj2bnRJFPuMt scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DF9986.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DF99D1.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DFBA57.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DFBA6E.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DFE265.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\ZLT009c7.TMP scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\ZLT009ca.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01312009_140236
Files moved on Reboot...
File move failed. c:\windows\system32\rundll32.exe scheduled to be moved on reboot.
File C:\Users\MONET\AppData\Local\Temp\etilqs_tXuU0R9cEj2bnRJFPuMt not found!
File C:\Users\MONET\AppData\Local\Temp\~DF9986.tmp not found!
File C:\Users\MONET\AppData\Local\Temp\~DF99D1.tmp not found!
File C:\Users\MONET\AppData\Local\Temp\~DFBA57.tmp not found!
File C:\Users\MONET\AppData\Local\Temp\~DFBA6E.tmp not found!
C:\Users\MONET\AppData\Local\Temp\~DFE265.tmp moved successfully.
File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be moved on reboot.
File C:\Windows\temp\ZLT009c7.TMP not found!
File C:\Windows\temp\ZLT009ca.TMP not found!
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_001_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_002_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_003_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\urlclassifier3.sqlite moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\XUL.mfl moved successfully.
le voici :
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79F562E5-768C-4494-8E6C-824ADA4A9C2C}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8E015787-B1E3-404a-95DE-3E71E1FA0305}\\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E015787-B1E3-404a-95DE-3E71E1FA0305}\\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\winlogon not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\spa_start not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ajeojs not found.
========== FILES ==========
File/Folder c:\users\monet\appdata\local\ajeojs.exe not found.
File/Folder c:\windows\system32\mysidesearch_sidebar.dll not found.
File/Folder c:\windows\system32\nspcf6b.dll not found.
File/Folder c:\windows\system32\sprt_ads.dll not found.
File/Folder c:\windows\system32\spads.dll not found.
File/Folder c:\windows\winlogon.exe not found.
File move failed. c:\windows\system32\rundll32.exe scheduled to be moved on reboot.
========== COMMANDS ==========
File delete failed. C:\Users\MONET\AppData\Local\Temp\etilqs_tXuU0R9cEj2bnRJFPuMt scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DF9986.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DF99D1.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DFBA57.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DFBA6E.tmp scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Temp\~DFE265.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\ZLT009c7.TMP scheduled to be deleted on reboot.
File delete failed. C:\Windows\temp\ZLT009ca.TMP scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01312009_140236
Files moved on Reboot...
File move failed. c:\windows\system32\rundll32.exe scheduled to be moved on reboot.
File C:\Users\MONET\AppData\Local\Temp\etilqs_tXuU0R9cEj2bnRJFPuMt not found!
File C:\Users\MONET\AppData\Local\Temp\~DF9986.tmp not found!
File C:\Users\MONET\AppData\Local\Temp\~DF99D1.tmp not found!
File C:\Users\MONET\AppData\Local\Temp\~DFBA57.tmp not found!
File C:\Users\MONET\AppData\Local\Temp\~DFBA6E.tmp not found!
C:\Users\MONET\AppData\Local\Temp\~DFE265.tmp moved successfully.
File move failed. C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt scheduled to be moved on reboot.
File move failed. C:\Windows\temp\CLDigitalHome\PCMMediaServer.log scheduled to be moved on reboot.
File move failed. C:\Windows\temp\nmsmc_DQLWinService.log scheduled to be moved on reboot.
File C:\Windows\temp\ZLT009c7.TMP not found!
File C:\Windows\temp\ZLT009ca.TMP not found!
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_001_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_002_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_003_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\Cache\_CACHE_MAP_ moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\urlclassifier3.sqlite moved successfully.
C:\Users\MONET\AppData\Local\Mozilla\Firefox\Profiles\p2pk2ktf.default\XUL.mfl moved successfully.
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
31 janv. 2009 à 19:23
31 janv. 2009 à 19:23
a ouais d'accord..merci pour l'info a propos de google ;)
la situation est revenu a la normal avec google maintenant.
la situation est revenu a la normal avec google maintenant.
chimay8
Messages postés
7720
Date d'inscription
jeudi 1 mai 2008
Statut
Contributeur sécurité
Dernière intervention
3 janvier 2014
60
31 janv. 2009 à 21:10
31 janv. 2009 à 21:10
Copie le texte ci-dessous :
File::
c:\users\MONET\HAesIhwnEI.exe
c:\users\MONET\u1a0dq7MoX.exe
c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
c:\users\monet\appdata\local\ajeojs.exe
c:\windows\Tasks\ahkavddq.job
Folder::
C:\542985663
c:\windows\System32\whSLD02
c:\temp\REX81
c:\program files\Bonjour
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt c'est important
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
File::
c:\users\MONET\HAesIhwnEI.exe
c:\users\MONET\u1a0dq7MoX.exe
c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
c:\users\monet\appdata\local\ajeojs.exe
c:\windows\Tasks\ahkavddq.job
Folder::
C:\542985663
c:\windows\System32\whSLD02
c:\temp\REX81
c:\program files\Bonjour
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt c'est important
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
1 févr. 2009 à 12:32
1 févr. 2009 à 12:32
VOICI LE COMBOFIX LOG :
ComboFix 09-01-21.04 - MONET 2009-02-01 11:41:32.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2046.1150 [GMT 1:00]
Lancé depuis: c:\users\MONET\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\MONET\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *enabled*
* Un nouveau point de restauration a été créé
.
- Mode FONCTIONNALITES REDUITES -
FILE ::
c:\users\monet\appdata\local\ajeojs.exe
c:\users\MONET\HAesIhwnEI.exe
c:\users\MONET\u1a0dq7MoX.exe
c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
c:\windows\Tasks\ahkavddq.job
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\542985663\
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\temp\REX81
c:\users\MONET\HAesIhwnEI.exe
c:\users\MONET\u1a0dq7MoX.exe
c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
c:\windows\System32\whSLD02
c:\windows\Tasks\ahkavddq.job
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-01 au 2009-02-01 ))))))))))))))))))))))))))))))))))))
.
2009-01-31 14:02 . 2009-01-31 14:02 <REP> d-------- C:\_OTMoveIt
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\MONET\AppData\Roaming\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\programdata\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-29 15:56 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-29 15:56 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-29 10:49 . 2009-01-29 15:45 <REP> d-------- C:\ToolBar SD
2009-01-29 09:02 . 2009-01-29 11:38 <REP> d-------- c:\program files\Navilog1
2009-01-29 09:00 . 2009-01-29 09:00 2 --a------ C:\542985663
2009-01-28 11:34 . 2009-01-28 11:35 <REP> d-------- c:\program files\Common Files\Adobe
2009-01-28 11:34 . 2009-01-28 11:34 <REP> d-------- c:\program files\Adobe(0)
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\users\All Users\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\programdata\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\program files\NOS
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-01 10:44 352,614 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2009-01-31 14:56 --------- d-----w c:\program files\Spyware Terminator
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-29 17:32 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-01-29 17:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-29 17:19 --------- d-----w c:\programdata\Symantec
2009-01-29 08:21 --------- d-----w c:\programdata\Spyware Terminator
2009-01-26 16:35 --------- d-----w c:\program files\Google
2009-01-17 22:00 1,893,376 ----a-w c:\windows\Internet Logs\xDBD273.tmp
2009-01-02 17:02 --------- d-----w c:\program files\SniffPass
2009-01-02 15:56 22 ----a-w c:\users\MONET\a.zip
2008-12-30 18:58 138,368 ----a-w c:\windows\system32\drivers\sp_rsdrv2.sys
2008-12-30 16:42 --------- d-----w c:\programdata\Lavasoft
2008-12-30 16:42 --------- d-----w c:\program files\Lavasoft
2008-12-30 16:40 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-30 16:37 --------- d-----w c:\users\MONET\AppData\Roaming\Application Data
2008-12-30 11:32 7,077,095 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-12-22 10:02 584,192 ----a-w c:\windows\Internet Logs\xDBBA57.tmp
2008-12-22 10:02 1,838,080 ----a-w c:\windows\Internet Logs\xDBBDE2.tmp
2008-12-19 20:01 1,835,008 ----a-w c:\windows\Internet Logs\xDBEA7F.tmp
2008-12-19 17:08 1,834,496 ----a-w c:\windows\Internet Logs\xDBBA76.tmp
2008-12-17 17:47 1,831,424 ----a-w c:\windows\Internet Logs\xDBC69B.tmp
2008-12-16 22:58 59,392 ----a-w c:\windows\Internet Logs\xDBCBAC.tmp
2008-12-16 16:35 --------- d-----w c:\program files\CCleaner
2008-12-16 16:28 2,646,016 ----a-w c:\windows\Internet Logs\xDBAA3A.tmp
2008-12-16 13:15 --------- d-----w c:\users\MONET\AppData\Roaming\LimeWire
2008-12-09 20:47 3,752 ----a-w c:\users\MONET\AppData\Roaming\wklnhst.dat
2008-12-04 10:59 --------- d-----w c:\programdata\Microsoft Help
2008-12-01 13:56 --------- d-----w c:\program files\Yahoo!
2008-11-08 12:39 2,621,440 ----a-w c:\windows\Internet Logs\xDBF184.tmp
2008-10-19 17:23 147,456 ----a-w c:\users\MONET\vbzip10.dll
2008-10-19 17:21 511 ----a-w c:\users\MONET\899.bat
2008-10-19 17:20 68 ----a-w c:\users\MONET\z.bat
2007-10-28 11:00 174 --sha-w c:\program files\desktop.ini
2006-05-03 09:06 163,328 --sh--r c:\windows\System32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\System32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-31_15.31.49,18 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-31 13:06:48 1,572,864 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-01 10:44:22 1,572,864 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2009-01-31 14:30:40 1,572,864 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-01 10:44:22 1,572,864 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
- 2009-01-31 13:04:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-01 10:43:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-31 13:04:42 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-01 10:43:59 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-31 13:04:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-01 10:43:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-05 12:28:21 378,592 ----a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-02-01 10:12:37 378,592 ----a-w c:\windows\System32\FNTCACHE.DAT
- 2009-01-31 13:09:32 103,726 ----a-w c:\windows\System32\perfc009.dat
+ 2009-02-01 10:17:45 103,726 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-31 13:09:32 117,366 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-02-01 10:17:45 117,366 ----a-w c:\windows\System32\perfc00C.dat
- 2009-01-31 13:09:32 609,944 ----a-w c:\windows\System32\perfh009.dat
+ 2009-02-01 10:17:45 609,944 ----a-w c:\windows\System32\perfh009.dat
- 2009-01-31 13:09:32 690,594 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-02-01 10:17:45 690,594 ----a-w c:\windows\System32\perfh00C.dat
- 2009-01-31 13:06:28 14,158 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2288649053-3584678336-516994887-1001_UserData.bin
+ 2009-02-01 10:14:38 14,158 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2288649053-3584678336-516994887-1001_UserData.bin
- 2009-01-31 13:06:28 83,782 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-01 10:14:37 83,782 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-31 13:06:27 79,794 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-01 10:14:32 79,794 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Acer Tour Reminder"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-03-22 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-22 8425472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-22 81920]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-06 707360]
"MaxBlastMonitor.exe"="c:\program files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-08-08 1169440]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"AcronisTimounterMonitor"="c:\program files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 1945448]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-11-15 151552]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 148760]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-12-30 2735616]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-04-20 528384]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
PCM Media Sharing.lnk - c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-04-20 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
"msacm.fraunhoferacm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ ?ü??ü???\[u]0/ulsdelete\[u]0/u
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"ajeojs"=c:\users\monet\appdata\local\ajeojs.exe ajeojs
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
"205d4d10"=rundll32.exe "c:\users\MONET\AppData\Local\Temp\lsvalhff.dll",b
"cmds"=rundll32.exe c:\users\MONET\AppData\Local\Temp\tuvSkLcY.dll,c
"MSServer"=rundll32.exe c:\users\MONET\AppData\Local\Temp\nnnmlKCT.dll,#1
"LSA Shellu"=c:\users\MONET\lsass.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ALUAlert"=c:\program files\Symantec\LiveUpdate\ALuNotify.exe
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe"
"WarReg_PopUp"=c:\acer\WR_PopUp\WarReg_PopUp.exe
"Acer Empowering Technology Monitor"=c:\acer\Empowering Technology\SysMonitor.exe
"MSServer"=rundll32.exe c:\windows\system32\ddcYqrpM.dll,#1
"RtHDVCpl"=RtHDVCpl.exe
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe"
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BB82DE3E-0D30-4A0E-A4DE-24FEE90A20B8}"= Profile=Private|c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{30C66B97-5348-432C-8C8D-FDC5D53398A8}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{1E17540B-C6F2-4603-B6BB-FCF18E577BD7}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{FABD7FB2-EB66-446D-B88F-9BBF64D3EC89}"= c:\program files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{94D99930-8327-4375-9044-66379D3E2AB6}"= c:\program files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{6195F082-0459-41EC-98AD-25E7EDDB9082}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{EAE4E69B-2B6D-4112-AE38-9A20F6A4089C}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{DC6AA3C5-B182-4B2C-A647-820993D94A25}"= c:\program files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{F9EEAD95-DBAD-4A39-AE68-07DD01DE7DD5}"= c:\program files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{3E4CEE3D-74AD-4AE3-9930-49A16845202C}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{19940BEA-3D80-457B-B109-2ED69152588B}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FDCF21D8-3960-41C2-AF8B-9B11173EAB65}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{854C3A2B-6210-4FE2-9739-BE62A579896E}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{F71AB188-A47C-4163-86DE-446E70AE531D}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{1D76D64F-1929-46A7-A8E0-1CE511E95F33}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{EA2F1D41-8B9C-4000-BD64-593A114963A6}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{45555AA4-68D7-45C5-8383-CA0E19C9C1ED}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{CA43BADD-AE70-4138-993F-E2F6F8E350A9}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{1616121A-0B41-4070-A213-3CD9859457B2}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{F71FF062-43F6-4F5E-8B62-EF6408958206}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{08835A44-3D31-4545-92AE-88629986867D}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{2390B826-08FC-477E-AC9A-E5B79D04A6D3}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{8F6291EC-6803-41B7-B8A6-FA37415D1F6C}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{7FA3D92F-D4EA-411C-8081-8F38DFA8249A}"= UDP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{1199F163-9C05-4F93-8B6F-ADCDD867D93B}"= TCP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{F8E85458-EDBA-4B4B-AECC-D2CD1C97478C}"= UDP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"{B9FC6A35-2ECA-4035-A649-5E8C7B069323}"= TCP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"TCP Query User{B5BA147C-A6A8-47F4-8FCE-BB70E1816A45}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"UDP Query User{11FB6107-55D6-4113-8E9D-F49AF248BA06}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"TCP Query User{2CC372CC-A817-40AD-B36D-94D78135DC32}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"UDP Query User{D38265CC-ACDE-41B9-997B-2EB76D5576A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"TCP Query User{0FF6B665-943E-4F39-90B9-BAF9BC4A630E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"UDP Query User{DB50AF0B-6575-4BFD-95B1-7F2E50D24656}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"TCP Query User{7A4D10CC-2EE6-4E88-9304-A725FDD48573}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"UDP Query User{C7F78B6F-D4CF-4915-9A69-CE7376B4BF12}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"TCP Query User{FC87378F-96F8-4CB3-9CA1-2EC2CBB6E4AF}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"UDP Query User{009A94A2-27D4-4684-BE6D-520BC29E8CD9}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"TCP Query User{EC98FAC6-624F-42F1-B1F4-69AE2BB45D82}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"UDP Query User{E61928B4-A41E-41E1-918C-13CFFACF4B02}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"TCP Query User{27947143-2540-4752-B82F-CF61E3D6247F}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"UDP Query User{0B2E734B-4146-4594-BC69-2811BD2F09F8}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"TCP Query User{FF9E006B-F93B-4F2A-A4DB-FA09B26F5BA0}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"UDP Query User{30E149FD-EAF0-4546-962B-2D8CAEE4F632}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"TCP Query User{1CCF575B-BA1B-43BA-8DC9-18248B30D8E7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"UDP Query User{8C8A4410-5058-49B2-A967-6DBA3BA45105}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"TCP Query User{53C58EFE-7452-49DB-B75C-7C75782C5C6A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"UDP Query User{F6F7C8AE-58B5-4B31-96F1-1253DB6CDDB2}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"TCP Query User{263F051A-6642-49C1-BD81-B9735D9E0CFB}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"UDP Query User{5EC39034-5A0C-4E91-9789-AB4656F082F5}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"TCP Query User{AC1AD9B1-8464-4A7C-8B38-773D70BABD46}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"UDP Query User{D8257A5C-5ED6-47C6-AC48-297DC8ED30BD}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"TCP Query User{FC74C1C4-8C09-44F3-AA57-1F4F9090008A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"UDP Query User{68D1899D-88C3-4385-B8DF-A6ED49BBF172}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"TCP Query User{98FCE685-2D95-45D2-B6CB-5A477DB6B9A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"UDP Query User{8061A454-4D88-4FC7-8073-CFE5E0BB6B7E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"TCP Query User{51D46E30-41D3-415B-A79B-DDD4E9FD8161}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8F2ABA34-40E4-4A1C-879E-13C5C9DB446A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{E55EF3BB-309C-4FDD-9F21-2E86F7EA632D}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"UDP Query User{718238A3-7245-48E5-A510-75131F5A122E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"TCP Query User{D53090B0-977F-4C97-9713-9BA0D2D7A036}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"UDP Query User{72F64873-372A-45D6-92CB-97D59522023E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"{A9B38984-92D2-4581-96DB-B45A931E0641}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{BC3F088F-247E-4671-81D5-CEE0EE63AFF0}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4E44F572-C3C4-47F4-BC3C-49F52057B5DA}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A225D047-5E4E-4EEE-9631-8ED889B824AA}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{BA2265CC-9472-4F41-A318-C8F786F5425B}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8B948B46-4EFB-419D-8D00-D3C1B75D771D}"= Disabled:c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{3EB26DA4-763A-4683-92A3-A71120090234}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CB2BB86F-271A-46B8-B21B-6CF1BC62FF62}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AD2D0A66-BF37-434A-8E3E-6815AC75E9DC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A2BC7ACF-78A5-40FD-BAF4-D0616BEF345D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FE91996D-586F-445B-AFAE-DB83F567B113}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{3B3B9A4F-11CB-4ED3-BFAA-A5D060168422}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{B66FA882-9689-443E-8EDE-AA4ADBD7E93C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{DF5CD41B-22EF-456C-B1D1-675235E6742B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1C9849AF-BACE-4AD4-B155-42E332973342}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DEEBE6BD-E5FA-4D01-BE38-57E7CE70F454}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E7C84905-617F-40B5-B156-629CDE1F244E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CEAE3139-1D98-4E8C-8C90-F4BFB3890B4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [2008-12-30 138368]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [2007-08-14 5504]
R4 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-20 266343]
R4 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R4 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [2006-09-27 28672]
R4 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [2006-10-19 7424]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-05-24 810320]
S3 BthAvrcp;Profil AVRCP Bluetooth;c:\windows\System32\drivers\BthAvrcp.sys [2007-08-24 15872]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-28 33752]
S3 IntelDHSvcConf;IntelDHSvcConf;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [2006-11-18 36312]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;c:\windows\System32\drivers\usbiad.sys [2005-06-13 31579]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
\shell\AutoRun\command - E:\Startup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-30 c:\windows\Tasks\Norton Internet Security - Analyse système complète - MONET.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
2009-01-31 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-cmds - c:\users\MONET\AppData\Local\Temp\tuvSkLcY.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sfr.fr/kit/adsl/
mWindow Title =
uInternet Settings,ProxyServer = <local>
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\MONET\AppData\Roaming\Mozilla\Firefox\Profiles\p2pk2ktf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://fr-fr.facebook.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-01 11:44:25
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\users\MONET\AppData\Roaming\GTek\GTUpdate\AUpdate\NMSSupport\DB\{90E132E4-E36B-4394-8368-31DD9260E8A0}.xml 415 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'Explorer.exe'(3816)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Common Files\Maxtor\Schedule2\schedul2.exe
c:\program files\Intel\IntelDH\CCU\AlertService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
c:\acer\Empowering Technology\eRecovery\eRAgent.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-02-01 11:47:57 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-02-01 10:47:53
ComboFix2.txt 2009-01-31 14:33:01
Avant-CF: 97 231 855 616 octets libres
Après-CF: 97,398,480,896 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
383 --- E O F --- 2008-02-14 17:29:42
ComboFix 09-01-21.04 - MONET 2009-02-01 11:41:32.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2046.1150 [GMT 1:00]
Lancé depuis: c:\users\MONET\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\MONET\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *enabled*
* Un nouveau point de restauration a été créé
.
- Mode FONCTIONNALITES REDUITES -
FILE ::
c:\users\monet\appdata\local\ajeojs.exe
c:\users\MONET\HAesIhwnEI.exe
c:\users\MONET\u1a0dq7MoX.exe
c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
c:\windows\Tasks\ahkavddq.job
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\542985663\
c:\program files\Bonjour
c:\program files\Bonjour\About Bonjour.rtf
c:\program files\Bonjour\mdnsNSP.dll
c:\program files\Bonjour\mDNSResponder.exe
c:\temp\REX81
c:\users\MONET\HAesIhwnEI.exe
c:\users\MONET\u1a0dq7MoX.exe
c:\windows\Internet Logs\vsmon_on_demand_2009_01_29_22_30_58_full.dmp.zip
c:\windows\Internet Logs\vsmon_on_demand_2009_01_31_14_03_31_full.dmp.zip
c:\windows\System32\whSLD02
c:\windows\Tasks\ahkavddq.job
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-01 au 2009-02-01 ))))))))))))))))))))))))))))))))))))
.
2009-01-31 14:02 . 2009-01-31 14:02 <REP> d-------- C:\_OTMoveIt
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\MONET\AppData\Roaming\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\programdata\Malwarebytes
2009-01-29 15:56 . 2009-01-29 15:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-29 15:56 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-01-29 15:56 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-01-29 10:49 . 2009-01-29 15:45 <REP> d-------- C:\ToolBar SD
2009-01-29 09:02 . 2009-01-29 11:38 <REP> d-------- c:\program files\Navilog1
2009-01-29 09:00 . 2009-01-29 09:00 2 --a------ C:\542985663
2009-01-28 11:34 . 2009-01-28 11:35 <REP> d-------- c:\program files\Common Files\Adobe
2009-01-28 11:34 . 2009-01-28 11:34 <REP> d-------- c:\program files\Adobe(0)
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\users\All Users\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\programdata\NOS
2009-01-28 11:28 . 2009-01-29 08:10 <REP> d-------- c:\program files\NOS
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-01 10:44 352,614 ---ha-w c:\windows\system32\drivers\vsconfig.xml
2009-01-31 14:56 --------- d-----w c:\program files\Spyware Terminator
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-31 14:30 2,359,296 --sha-w c:\users\Invité\ntuser.dat
2009-01-29 17:32 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-01-29 17:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-29 17:19 --------- d-----w c:\programdata\Symantec
2009-01-29 08:21 --------- d-----w c:\programdata\Spyware Terminator
2009-01-26 16:35 --------- d-----w c:\program files\Google
2009-01-17 22:00 1,893,376 ----a-w c:\windows\Internet Logs\xDBD273.tmp
2009-01-02 17:02 --------- d-----w c:\program files\SniffPass
2009-01-02 15:56 22 ----a-w c:\users\MONET\a.zip
2008-12-30 18:58 138,368 ----a-w c:\windows\system32\drivers\sp_rsdrv2.sys
2008-12-30 16:42 --------- d-----w c:\programdata\Lavasoft
2008-12-30 16:42 --------- d-----w c:\program files\Lavasoft
2008-12-30 16:40 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-30 16:37 --------- d-----w c:\users\MONET\AppData\Roaming\Application Data
2008-12-30 11:32 7,077,095 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-12-22 10:02 584,192 ----a-w c:\windows\Internet Logs\xDBBA57.tmp
2008-12-22 10:02 1,838,080 ----a-w c:\windows\Internet Logs\xDBBDE2.tmp
2008-12-19 20:01 1,835,008 ----a-w c:\windows\Internet Logs\xDBEA7F.tmp
2008-12-19 17:08 1,834,496 ----a-w c:\windows\Internet Logs\xDBBA76.tmp
2008-12-17 17:47 1,831,424 ----a-w c:\windows\Internet Logs\xDBC69B.tmp
2008-12-16 22:58 59,392 ----a-w c:\windows\Internet Logs\xDBCBAC.tmp
2008-12-16 16:35 --------- d-----w c:\program files\CCleaner
2008-12-16 16:28 2,646,016 ----a-w c:\windows\Internet Logs\xDBAA3A.tmp
2008-12-16 13:15 --------- d-----w c:\users\MONET\AppData\Roaming\LimeWire
2008-12-09 20:47 3,752 ----a-w c:\users\MONET\AppData\Roaming\wklnhst.dat
2008-12-04 10:59 --------- d-----w c:\programdata\Microsoft Help
2008-12-01 13:56 --------- d-----w c:\program files\Yahoo!
2008-11-08 12:39 2,621,440 ----a-w c:\windows\Internet Logs\xDBF184.tmp
2008-10-19 17:23 147,456 ----a-w c:\users\MONET\vbzip10.dll
2008-10-19 17:21 511 ----a-w c:\users\MONET\899.bat
2008-10-19 17:20 68 ----a-w c:\users\MONET\z.bat
2007-10-28 11:00 174 --sha-w c:\program files\desktop.ini
2006-05-03 09:06 163,328 --sh--r c:\windows\System32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\System32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-31_15.31.49,18 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-31 13:06:48 1,572,864 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-02-01 10:44:22 1,572,864 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
- 2009-01-31 14:30:40 1,572,864 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-02-01 10:44:22 1,572,864 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
- 2009-01-31 13:04:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-02-01 10:43:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-31 13:04:42 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-01 10:43:59 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-31 13:04:42 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-01 10:43:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-05 12:28:21 378,592 ----a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-02-01 10:12:37 378,592 ----a-w c:\windows\System32\FNTCACHE.DAT
- 2009-01-31 13:09:32 103,726 ----a-w c:\windows\System32\perfc009.dat
+ 2009-02-01 10:17:45 103,726 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-31 13:09:32 117,366 ----a-w c:\windows\System32\perfc00C.dat
+ 2009-02-01 10:17:45 117,366 ----a-w c:\windows\System32\perfc00C.dat
- 2009-01-31 13:09:32 609,944 ----a-w c:\windows\System32\perfh009.dat
+ 2009-02-01 10:17:45 609,944 ----a-w c:\windows\System32\perfh009.dat
- 2009-01-31 13:09:32 690,594 ----a-w c:\windows\System32\perfh00C.dat
+ 2009-02-01 10:17:45 690,594 ----a-w c:\windows\System32\perfh00C.dat
- 2009-01-31 13:06:28 14,158 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2288649053-3584678336-516994887-1001_UserData.bin
+ 2009-02-01 10:14:38 14,158 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2288649053-3584678336-516994887-1001_UserData.bin
- 2009-01-31 13:06:28 83,782 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-01 10:14:37 83,782 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-31 13:06:27 79,794 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-02-01 10:14:32 79,794 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"Acer Tour Reminder"="" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-03-22 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-22 8425472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-22 81920]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 75304]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-06 707360]
"MaxBlastMonitor.exe"="c:\program files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-08-08 1169440]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-02-15 151552]
"AcronisTimounterMonitor"="c:\program files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 1945448]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-02-06 464168]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-11-15 151552]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 148760]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-03 959976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-12-30 2735616]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-04-20 528384]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
PCM Media Sharing.lnk - c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-04-20 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
"msacm.fraunhoferacm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ ?ü??ü???\[u]0/ulsdelete\[u]0/u
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Sidebar"=c:\program files\Windows Sidebar\sidebar.exe /autoRun
"ajeojs"=c:\users\monet\appdata\local\ajeojs.exe ajeojs
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
"205d4d10"=rundll32.exe "c:\users\MONET\AppData\Local\Temp\lsvalhff.dll",b
"cmds"=rundll32.exe c:\users\MONET\AppData\Local\Temp\tuvSkLcY.dll,c
"MSServer"=rundll32.exe c:\users\MONET\AppData\Local\Temp\nnnmlKCT.dll,#1
"LSA Shellu"=c:\users\MONET\lsass.exe
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ALUAlert"=c:\program files\Symantec\LiveUpdate\ALuNotify.exe
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe"
"WarReg_PopUp"=c:\acer\WR_PopUp\WarReg_PopUp.exe
"Acer Empowering Technology Monitor"=c:\acer\Empowering Technology\SysMonitor.exe
"MSServer"=rundll32.exe c:\windows\system32\ddcYqrpM.dll,#1
"RtHDVCpl"=RtHDVCpl.exe
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe"
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{BB82DE3E-0D30-4A0E-A4DE-24FEE90A20B8}"= Profile=Private|c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{30C66B97-5348-432C-8C8D-FDC5D53398A8}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{1E17540B-C6F2-4603-B6BB-FCF18E577BD7}"= c:\program files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{FABD7FB2-EB66-446D-B88F-9BBF64D3EC89}"= c:\program files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{94D99930-8327-4375-9044-66379D3E2AB6}"= c:\program files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{6195F082-0459-41EC-98AD-25E7EDDB9082}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{EAE4E69B-2B6D-4112-AE38-9A20F6A4089C}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{DC6AA3C5-B182-4B2C-A647-820993D94A25}"= c:\program files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{F9EEAD95-DBAD-4A39-AE68-07DD01DE7DD5}"= c:\program files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{3E4CEE3D-74AD-4AE3-9930-49A16845202C}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{19940BEA-3D80-457B-B109-2ED69152588B}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{FDCF21D8-3960-41C2-AF8B-9B11173EAB65}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{854C3A2B-6210-4FE2-9739-BE62A579896E}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{F71AB188-A47C-4163-86DE-446E70AE531D}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{1D76D64F-1929-46A7-A8E0-1CE511E95F33}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{EA2F1D41-8B9C-4000-BD64-593A114963A6}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{45555AA4-68D7-45C5-8383-CA0E19C9C1ED}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{CA43BADD-AE70-4138-993F-E2F6F8E350A9}"= UDP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{1616121A-0B41-4070-A213-3CD9859457B2}"= TCP:c:\program files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
"{F71FF062-43F6-4F5E-8B62-EF6408958206}"= UDP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{08835A44-3D31-4545-92AE-88629986867D}"= TCP:c:\program files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
"{2390B826-08FC-477E-AC9A-E5B79D04A6D3}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{8F6291EC-6803-41B7-B8A6-FA37415D1F6C}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{7FA3D92F-D4EA-411C-8081-8F38DFA8249A}"= UDP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{1199F163-9C05-4F93-8B6F-ADCDD867D93B}"= TCP:c:\program files\Microsoft Games\Halo 2\halo2.exe:Halo 2
"{F8E85458-EDBA-4B4B-AECC-D2CD1C97478C}"= UDP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"{B9FC6A35-2ECA-4035-A649-5E8C7B069323}"= TCP:c:\program files\Microsoft Games\Halo 2 Dedicated Server\h2server.exe:Halo 2 Dedicated Server
"TCP Query User{B5BA147C-A6A8-47F4-8FCE-BB70E1816A45}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"UDP Query User{11FB6107-55D6-4113-8E9D-F49AF248BA06}c:\\users\\monet\\appdata\\local\\temp\\rarsfx73\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx73\haloce.exe:haloce.exe
"TCP Query User{2CC372CC-A817-40AD-B36D-94D78135DC32}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"UDP Query User{D38265CC-ACDE-41B9-997B-2EB76D5576A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx74\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx74\haloce.exe:haloce.exe
"TCP Query User{0FF6B665-943E-4F39-90B9-BAF9BC4A630E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"UDP Query User{DB50AF0B-6575-4BFD-95B1-7F2E50D24656}c:\\users\\monet\\appdata\\local\\temp\\rarsfx75\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx75\haloce.exe:haloce.exe
"TCP Query User{7A4D10CC-2EE6-4E88-9304-A725FDD48573}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"UDP Query User{C7F78B6F-D4CF-4915-9A69-CE7376B4BF12}c:\\users\\monet\\appdata\\local\\temp\\rarsfx77\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx77\haloce.exe:haloce.exe
"TCP Query User{FC87378F-96F8-4CB3-9CA1-2EC2CBB6E4AF}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"UDP Query User{009A94A2-27D4-4684-BE6D-520BC29E8CD9}c:\\users\\monet\\appdata\\local\\temp\\rarsfx78\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx78\haloce.exe:haloce.exe
"TCP Query User{EC98FAC6-624F-42F1-B1F4-69AE2BB45D82}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"UDP Query User{E61928B4-A41E-41E1-918C-13CFFACF4B02}c:\\users\\monet\\appdata\\local\\temp\\rarsfx80\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx80\haloce.exe:haloce.exe
"TCP Query User{27947143-2540-4752-B82F-CF61E3D6247F}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"UDP Query User{0B2E734B-4146-4594-BC69-2811BD2F09F8}c:\\users\\monet\\appdata\\local\\temp\\rarsfx82\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx82\haloce.exe:haloce.exe
"TCP Query User{FF9E006B-F93B-4F2A-A4DB-FA09B26F5BA0}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"UDP Query User{30E149FD-EAF0-4546-962B-2D8CAEE4F632}c:\\users\\monet\\appdata\\local\\temp\\rarsfx83\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx83\haloce.exe:haloce.exe
"TCP Query User{1CCF575B-BA1B-43BA-8DC9-18248B30D8E7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"UDP Query User{8C8A4410-5058-49B2-A967-6DBA3BA45105}c:\\users\\monet\\appdata\\local\\temp\\rarsfx84\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx84\haloce.exe:haloce.exe
"TCP Query User{53C58EFE-7452-49DB-B75C-7C75782C5C6A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"UDP Query User{F6F7C8AE-58B5-4B31-96F1-1253DB6CDDB2}c:\\users\\monet\\appdata\\local\\temp\\rarsfx85\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx85\haloce.exe:haloce.exe
"TCP Query User{263F051A-6642-49C1-BD81-B9735D9E0CFB}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"UDP Query User{5EC39034-5A0C-4E91-9789-AB4656F082F5}c:\\users\\monet\\appdata\\local\\temp\\rarsfx86\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx86\haloce.exe:haloce.exe
"TCP Query User{AC1AD9B1-8464-4A7C-8B38-773D70BABD46}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"UDP Query User{D8257A5C-5ED6-47C6-AC48-297DC8ED30BD}c:\\users\\monet\\appdata\\local\\temp\\rarsfx87\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx87\haloce.exe:haloce.exe
"TCP Query User{FC74C1C4-8C09-44F3-AA57-1F4F9090008A}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"UDP Query User{68D1899D-88C3-4385-B8DF-A6ED49BBF172}c:\\users\\monet\\appdata\\local\\temp\\rarsfx88\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx88\haloce.exe:haloce.exe
"TCP Query User{98FCE685-2D95-45D2-B6CB-5A477DB6B9A7}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"UDP Query User{8061A454-4D88-4FC7-8073-CFE5E0BB6B7E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx89\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx89\haloce.exe:haloce.exe
"TCP Query User{51D46E30-41D3-415B-A79B-DDD4E9FD8161}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8F2ABA34-40E4-4A1C-879E-13C5C9DB446A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{E55EF3BB-309C-4FDD-9F21-2E86F7EA632D}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"UDP Query User{718238A3-7245-48E5-A510-75131F5A122E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx90\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx90\haloce.exe:haloce.exe
"TCP Query User{D53090B0-977F-4C97-9713-9BA0D2D7A036}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= UDP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"UDP Query User{72F64873-372A-45D6-92CB-97D59522023E}c:\\users\\monet\\appdata\\local\\temp\\rarsfx91\\haloce.exe"= TCP:c:\users\monet\appdata\local\temp\rarsfx91\haloce.exe:haloce.exe
"{A9B38984-92D2-4581-96DB-B45A931E0641}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{BC3F088F-247E-4671-81D5-CEE0EE63AFF0}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4E44F572-C3C4-47F4-BC3C-49F52057B5DA}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{A225D047-5E4E-4EEE-9631-8ED889B824AA}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{BA2265CC-9472-4F41-A318-C8F786F5425B}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{8B948B46-4EFB-419D-8D00-D3C1B75D771D}"= Disabled:c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{3EB26DA4-763A-4683-92A3-A71120090234}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CB2BB86F-271A-46B8-B21B-6CF1BC62FF62}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{AD2D0A66-BF37-434A-8E3E-6815AC75E9DC}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A2BC7ACF-78A5-40FD-BAF4-D0616BEF345D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FE91996D-586F-445B-AFAE-DB83F567B113}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{3B3B9A4F-11CB-4ED3-BFAA-A5D060168422}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{B66FA882-9689-443E-8EDE-AA4ADBD7E93C}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{DF5CD41B-22EF-456C-B1D1-675235E6742B}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{1C9849AF-BACE-4AD4-B155-42E332973342}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{DEEBE6BD-E5FA-4D01-BE38-57E7CE70F454}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{E7C84905-617F-40B5-B156-629CDE1F244E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CEAE3139-1D98-4E8C-8C90-F4BFB3890B4F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [2008-12-30 138368]
R3 IntelDH;IntelDH Driver;c:\windows\System32\drivers\IntelDH.sys [2007-08-14 5504]
R4 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2007-04-20 266343]
R4 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R4 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\System32\drivers\nmsgopro.sys [2006-09-27 28672]
R4 nmsunidr;UniDriver for NMS;c:\windows\System32\drivers\nmsunidr.sys [2006-10-19 7424]
R4 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-05-24 810320]
S3 BthAvrcp;Profil AVRCP Bluetooth;c:\windows\System32\drivers\BthAvrcp.sys [2007-08-24 15872]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-28 33752]
S3 IntelDHSvcConf;IntelDHSvcConf;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [2006-11-18 36312]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;c:\windows\System32\drivers\usbiad.sys [2005-06-13 31579]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
\shell\AutoRun\command - E:\Startup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
\shell\Auto\command - F:\Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Start.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-30 c:\windows\Tasks\Norton Internet Security - Analyse système complète - MONET.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []
2009-01-31 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-cmds - c:\users\MONET\AppData\Local\Temp\tuvSkLcY.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sfr.fr/kit/adsl/
mWindow Title =
uInternet Settings,ProxyServer = <local>
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\MONET\AppData\Roaming\Mozilla\Firefox\Profiles\p2pk2ktf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://fr-fr.facebook.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-01 11:44:25
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\users\MONET\AppData\Roaming\GTek\GTUpdate\AUpdate\NMSSupport\DB\{90E132E4-E36B-4394-8368-31DD9260E8A0}.xml 415 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'Explorer.exe'(3816)
c:\windows\system32\MsnChatHook.dll
c:\windows\system32\ShowErrMsg.dll
c:\windows\system32\sysenv.dll
c:\windows\system32\BatchCrypto.dll
c:\windows\system32\CryptoAPI.dll
c:\windows\system32\keyManager.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\windows\System32\ZoneLabs\vsmon.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\acer\Empowering Technology\ePerformance\MemCheck.exe
c:\program files\Common Files\Maxtor\Schedule2\schedul2.exe
c:\program files\Intel\IntelDH\CCU\AlertService.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
c:\acer\Empowering Technology\eRecovery\eRAgent.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-02-01 11:47:57 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-02-01 10:47:53
ComboFix2.txt 2009-01-31 14:33:01
Avant-CF: 97 231 855 616 octets libres
Après-CF: 97,398,480,896 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=11 Sets=1,2,3,4,5,6,7,8,9,10,11
383 --- E O F --- 2008-02-14 17:29:42
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
1 févr. 2009 à 12:33
1 févr. 2009 à 12:33
ET LE RAPPORT HiJACKThis::
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:25, on 26/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\vVX1000.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MONET\AppData\Local\ajeojs.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchg.symantec.com/search?q=altavista&site=symc_en_US_sup&entqr=0&sort=date%3AD%3AL%3Ad1&output=xml_no_dtd&src=gbh&client=symc_en_US&ud=1&context=gbh&oe=UTF-8&ie=UTF-8&proxystylesheet=symc_en_US
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WMBoot] C:\Program Files\Logitech\WingMan Profiler\ChekList.exe -L:E:\WS\FRA\Setup.exe -CD -CL4 -LP:" reboot"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUpldfr-fr.cab
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IntelDHSvcConf - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:25, on 26/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\vVX1000.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MONET\AppData\Local\ajeojs.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchg.symantec.com/search?q=altavista&site=symc_en_US_sup&entqr=0&sort=date%3AD%3AL%3Ad1&output=xml_no_dtd&src=gbh&client=symc_en_US&ud=1&context=gbh&oe=UTF-8&ie=UTF-8&proxystylesheet=symc_en_US
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WMBoot] C:\Program Files\Logitech\WingMan Profiler\ChekList.exe -L:E:\WS\FRA\Setup.exe -CD -CL4 -LP:" reboot"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUpldfr-fr.cab
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IntelDHSvcConf - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
chimay8
Messages postés
7720
Date d'inscription
jeudi 1 mai 2008
Statut
Contributeur sécurité
Dernière intervention
3 janvier 2014
60
2 févr. 2009 à 09:37
2 févr. 2009 à 09:37
re,
quelque chose relance l'infection
Télécharge Navilog1.exe de il mafioso
Note : Si, lors du téléchargement, ton Antivirus fais une alerte, ignore-là, un composant de Navilog1 est détecté par certains AntiVirus comme étant un Malware .
Ce n'en est nullement un !
* Choisis Enregistrer sous.... et enregistre-le sur ton bureau.
* Sous XP, double clique sur navilog1.exe pour lancer l'installation.
**Sous VISTA, fais un clic droit dessus et dans le menu contextuel choisis "Exécuter en tant qu'administrateur".
tuto pour vista
Une fois l'installation terminée, fais un clic droit sur le raccourci Navilog1
présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valide.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
* Patiente jusqu'au message :
***Analyse Termine le.....***
* Appuie sur une touche comme demandé, le bloc-note va s'ouvrir.
* Copie/colle l'intégralité du rapport dans ta réponse.
Referme le bloc-note.
* Le rapport est en outre sauvegardé à la racine du disque C:\ (fixnavi.txt)
Copie/colle le ici dans ta prochaine réponse stp.
Relance Navilog, Sur le menu principal, choisis l'option 2.
Suis les instructions et patiente.
L'outil va t'informer qu'il redémarrera ton ordinateur.
Sauvegarde les documents ouverts, s'il y en a, puis ferme toutes les fenêtres.
Appuie sur une touche ainsi que demandé.
Si ton ordinateur ne redémarre pas automatiquement, fais le manuellement.
Choisis ta session habituelle si nécessaire.
Patiente jusqu'au message *** Nettoyage terminé le ….*** (il se peut que ça prenne un certain temps).
Un document du Bloc-notes est créé. Sauvegarde le rapport de manière à le retrouver.
* Copie/colle le contenu de ce compte-rendu dans ta prochaine réponse.
Referme le Bloc-notes.
Ton Bureau va réapparaître.
Note : Si ton Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Onglet "Processus" > Fichier (menu) > Nouvelle tâche (Exécuter...) > tape explorer et clique sur OK.
ensuite
double-clique sur OTMoveIt3.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" est cochée
Copie les lignes(qui sont en gras) qui se trouvent en dessous :
:Processes
explorer.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
:Folders
C:\542985663
:Commands
[emptytemp]
[start explorer]
[Reboot]
et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
-Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )
/!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître, dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi sur l'onglet "Processus". Clique en haut à gauche sur "Fichiers" et choisis "Exécuter"
Tape "explorer.exe"(sans les guillemèts) et valide. Cela fera réapparaître le Bureau.
ensuite
**désactive ton antivirus, logiciels de protections et logiciels pouvant bloquer les popups (barres Google, barres Yahoo etc..).**
Ouvre internet explorer --> Outils --> Options internet --> onglet "sécurité" --> Valide "niveau par défaut".
Toujours sur Internet explorer --> Outils --> Options internet --> onglet "avancé" --> valide "Paramètres par défaut".
Scan en ligne avec Kaspersky :
- https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr en utilisant Internet Explorer et pas Firefox, ça ne marchera pas!.
- Si tu es perdu, tu peux suivre l'aide pour les scans en ligne https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
AIDE : Configurer le contrôle des ActiveX < http://www.inoculer.com/activex.php3 >
Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html , ou là : https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)
- Au moment de choisir la cible à analyser, clique sur le bouton Paramètres d'analyse
- Dans la nouvelle fenêtre, coche "étendu" au milieu puis clique sur OK.
- Choisis le poste de travail dans la cible à analyser
- Copie/colle le rapport du scan ici
NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner,
reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
quelque chose relance l'infection
Télécharge Navilog1.exe de il mafioso
Note : Si, lors du téléchargement, ton Antivirus fais une alerte, ignore-là, un composant de Navilog1 est détecté par certains AntiVirus comme étant un Malware .
Ce n'en est nullement un !
* Choisis Enregistrer sous.... et enregistre-le sur ton bureau.
* Sous XP, double clique sur navilog1.exe pour lancer l'installation.
**Sous VISTA, fais un clic droit dessus et dans le menu contextuel choisis "Exécuter en tant qu'administrateur".
tuto pour vista
Une fois l'installation terminée, fais un clic droit sur le raccourci Navilog1
présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).
Laisse-toi guider. Au menu principal, choisis 1 et valide.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
* Patiente jusqu'au message :
***Analyse Termine le.....***
* Appuie sur une touche comme demandé, le bloc-note va s'ouvrir.
* Copie/colle l'intégralité du rapport dans ta réponse.
Referme le bloc-note.
* Le rapport est en outre sauvegardé à la racine du disque C:\ (fixnavi.txt)
Copie/colle le ici dans ta prochaine réponse stp.
Relance Navilog, Sur le menu principal, choisis l'option 2.
Suis les instructions et patiente.
L'outil va t'informer qu'il redémarrera ton ordinateur.
Sauvegarde les documents ouverts, s'il y en a, puis ferme toutes les fenêtres.
Appuie sur une touche ainsi que demandé.
Si ton ordinateur ne redémarre pas automatiquement, fais le manuellement.
Choisis ta session habituelle si nécessaire.
Patiente jusqu'au message *** Nettoyage terminé le ….*** (il se peut que ça prenne un certain temps).
Un document du Bloc-notes est créé. Sauvegarde le rapport de manière à le retrouver.
* Copie/colle le contenu de ce compte-rendu dans ta prochaine réponse.
Referme le Bloc-notes.
Ton Bureau va réapparaître.
Note : Si ton Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Onglet "Processus" > Fichier (menu) > Nouvelle tâche (Exécuter...) > tape explorer et clique sur OK.
ensuite
double-clique sur OTMoveIt3.exe pour le lancer.
Assure toi que la case "Unregister Dll's and Ocx's" est cochée
Copie les lignes(qui sont en gras) qui se trouvent en dessous :
:Processes
explorer.exe
:Reg
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2585f72a-c029-11dc-baac-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a7f9cc-92d2-11dd-bba7-0016ce5a90a9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3f5ffe5a-4a35-11dc-8b6f-806e6f6e6963}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e58cabe9-8a08-11dc-9f76-0016ce5a90a9}]
:Folders
C:\542985663
:Commands
[emptytemp]
[start explorer]
[Reboot]
et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
Clique sur "MoveIt!" pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
-Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )
/!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître, dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi sur l'onglet "Processus". Clique en haut à gauche sur "Fichiers" et choisis "Exécuter"
Tape "explorer.exe"(sans les guillemèts) et valide. Cela fera réapparaître le Bureau.
ensuite
**désactive ton antivirus, logiciels de protections et logiciels pouvant bloquer les popups (barres Google, barres Yahoo etc..).**
Ouvre internet explorer --> Outils --> Options internet --> onglet "sécurité" --> Valide "niveau par défaut".
Toujours sur Internet explorer --> Outils --> Options internet --> onglet "avancé" --> valide "Paramètres par défaut".
Scan en ligne avec Kaspersky :
- https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr en utilisant Internet Explorer et pas Firefox, ça ne marchera pas!.
- Si tu es perdu, tu peux suivre l'aide pour les scans en ligne https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
AIDE : Configurer le contrôle des ActiveX < http://www.inoculer.com/activex.php3 >
Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html , ou là : https://forum.pcastuces.com/sujet.asp?f=25&s=37641 (par Morgane & nico_dodo)
- Au moment de choisir la cible à analyser, clique sur le bouton Paramètres d'analyse
- Dans la nouvelle fenêtre, coche "étendu" au milieu puis clique sur OK.
- Choisis le poste de travail dans la cible à analyser
- Copie/colle le rapport du scan ici
NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner,
reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
3 févr. 2009 à 19:28
3 févr. 2009 à 19:28
NAVILOG :
Search Navipromo version 3.7.1 commencé le 03/02/2009 à 16:23:51,12
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 02.01.2009 à 19h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU 2140 @ 1.60GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : MONET ( Not Administrator ! )
BOOT : Normal boot
Firewall : ZoneAlarm Firewall 7.1.254.000 (Activated)
C:\ (Local Disk) - NTFS - Total:228 Go (Free:90 Go)
D:\ (Local Disk) - NTFS - Total:227 Go (Free:227 Go)
E:\ (CD or DVD) - UDF - Total:3 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\Windows" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***
*** Recherche dossiers dans "C:\ProgramData" ***
*** Recherche dossiers dans "c:\users\monet\appdata\roaming\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "C:\Users\MONET\AppData\Local\virtualstore\Program Files" ***
*** Recherche dossiers dans "C:\Users\MONET\AppData\Local" ***
*** Recherche dossiers dans "C:\Users\INVIT~1\AppData\Local" ***
*** Recherche dossiers dans "C:\Users\MONET\AppData\Roaming" ***
*** Recherche dossiers dans "C:\Users\INVIT~1\appdata\roaming" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\Windows\system32" *
* Recherche dans "C:\Users\MONET\AppData\Local\Microsoft" *
* Recherche dans "C:\Users\MONET\AppData\Local\virtualstore\windows\system32" *
* Recherche dans "C:\Users\MONET\AppData\Local" *
* Recherche dans "C:\Users\INVIT~1\AppData\Local" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\Windows\system32" :
* Dans "C:\Users\MONET\AppData\Local\Microsoft" :
* Dans "C:\Users\MONET\AppData\Local\virtualstore\windows\system32" :
* Dans "C:\Users\MONET\AppData\Local" :
* Dans "C:\Users\INVIT~1\AppData\Local" :
3)Recherche Certificats :
Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche autres dossiers et fichiers connus :
*** Analyse terminée le 03/02/2009 à 19:21:33,90 ***
Search Navipromo version 3.7.1 commencé le 03/02/2009 à 16:23:51,12
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 02.01.2009 à 19h00 par IL-MAFIOSO
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Genuine Intel(R) CPU 2140 @ 1.60GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : MONET ( Not Administrator ! )
BOOT : Normal boot
Firewall : ZoneAlarm Firewall 7.1.254.000 (Activated)
C:\ (Local Disk) - NTFS - Total:228 Go (Free:90 Go)
D:\ (Local Disk) - NTFS - Total:227 Go (Free:227 Go)
E:\ (CD or DVD) - UDF - Total:3 Go (Free:0 Go)
H:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
Recherche executé en mode normal
*** Recherche Programmes installés ***
*** Recherche dossiers dans "C:\Windows" ***
*** Recherche dossiers dans "C:\Program Files" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***
*** Recherche dossiers dans "C:\ProgramData" ***
*** Recherche dossiers dans "c:\users\monet\appdata\roaming\micros~1\windows\startm~1\programs" ***
*** Recherche dossiers dans "C:\Users\MONET\AppData\Local\virtualstore\Program Files" ***
*** Recherche dossiers dans "C:\Users\MONET\AppData\Local" ***
*** Recherche dossiers dans "C:\Users\INVIT~1\AppData\Local" ***
*** Recherche dossiers dans "C:\Users\MONET\AppData\Roaming" ***
*** Recherche dossiers dans "C:\Users\INVIT~1\appdata\roaming" ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans "C:\Windows\system32" *
* Recherche dans "C:\Users\MONET\AppData\Local\Microsoft" *
* Recherche dans "C:\Users\MONET\AppData\Local\virtualstore\windows\system32" *
* Recherche dans "C:\Users\MONET\AppData\Local" *
* Recherche dans "C:\Users\INVIT~1\AppData\Local" *
*** Recherche fichiers ***
*** Recherche clés spécifiques dans le Registre ***
!! Les clés trouvées ne sont pas forcément infectées !!
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche nouveaux fichiers Instant Access :
2)Recherche Heuristique :
* Dans "C:\Windows\system32" :
* Dans "C:\Users\MONET\AppData\Local\Microsoft" :
* Dans "C:\Users\MONET\AppData\Local\virtualstore\windows\system32" :
* Dans "C:\Users\MONET\AppData\Local" :
* Dans "C:\Users\INVIT~1\AppData\Local" :
3)Recherche Certificats :
Certificat Egroup absent !
Certificat Electronic-Group absent !
Certificat Montorgueil absent !
Certificat OOO-Favorit absent !
Certificat Sunny-Day-Design-Ltd absent !
4)Recherche autres dossiers et fichiers connus :
*** Analyse terminée le 03/02/2009 à 19:21:33,90 ***
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
4 févr. 2009 à 22:01
4 févr. 2009 à 22:01
désplé je met du temps mais je suis en pleins bac blanc :)
je tache de faire le reste vendredi.
je tache de faire le reste vendredi.
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
22 févr. 2009 à 18:00
22 févr. 2009 à 18:00
Me revoila de vacances , me remet au travail de suite...
djslimd
Messages postés
35
Date d'inscription
lundi 3 novembre 2008
Statut
Membre
Dernière intervention
29 mars 2009
1
23 févr. 2009 à 21:28
23 févr. 2009 à 21:28
je n'arrive pas a réanaliser avec mon navilog , jais toujours un message d'erreur , jais choper un truc en désactivant la sécurité en voulant refaire une analyse navilog mais jais choper un truc , voici un nouveau rapport Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:25, on 26/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\vVX1000.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MONET\AppData\Local\ajeojs.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchg.symantec.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WMBoot] C:\Program Files\Logitech\WingMan Profiler\ChekList.exe -L:E:\WS\FRA\Setup.exe -CD -CL4 -LP:" reboot"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUpldfr-fr.cab
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IntelDHSvcConf - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:25, on 26/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe
C:\Windows\vVX1000.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\MONET\AppData\Local\ajeojs.exe
C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchg.symantec.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: MySidesearch Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} - C:\Windows\system32\mysidesearch_sidebar.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: dcads - {6FC3C36D-7635-4D43-BA62-0D9D2F2CD06E} - C:\Windows\system32\nspCF6B.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: superiorads - {79F562E5-768C-4494-8E6C-824ADA4A9C2C} - C:\Windows\system32\sprt_ads.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: browser optimizer superiorads - {8E015787-B1E3-404a-95DE-3E71E1FA0305} - C:\Windows\system32\spads.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WMBoot] C:\Program Files\Logitech\WingMan Profiler\ChekList.exe -L:E:\WS\FRA\Setup.exe -CD -CL4 -LP:" reboot"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [winlogon] C:\Windows\winlogon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [spa_start] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\sprt_ads.dll" DllStart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ajeojs] c:\users\monet\appdata\local\ajeojs.exe ajeojs
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PCM Media Sharing.lnk = C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/VistaMSNPUpldfr-fr.cab
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: IntelDHSvcConf - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe