Ordi lent et infecter svp
amar
-
amar -
amar -
Bonjour,voici le rapport de hijakthis kk1 peut maider svp
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:41, on 08/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Acer\Empowering Technology\SysMonitor.exe
C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\Lefeve Catherine\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1006&m=aspire_x3200
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1006&m=aspire_x3200
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] "C:\Program Files\Acer\Empowering Technology\SysMonitor.exe"
O4 - HKLM\..\Run: [EmpoweringTechnology] "C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe" boot
O4 - HKLM\..\Run: [eDataSecurity Loader] "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe"
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] "C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Eset HTTP Server (EHttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\bin32\nSvcAppFlt.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\bin32\nSvcIp.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:41, on 08/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Acer\Empowering Technology\SysMonitor.exe
C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\Lefeve Catherine\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1006&m=aspire_x3200
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&l=040c&s=1&o=vp32&d=1006&m=aspire_x3200
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [RtHDVCpl] "C:\Windows\RtHDVCpl.exe"
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] "C:\Program Files\Acer\Empowering Technology\SysMonitor.exe"
O4 - HKLM\..\Run: [EmpoweringTechnology] "C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe" boot
O4 - HKLM\..\Run: [eDataSecurity Loader] "C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe"
O4 - HKLM\..\Run: [PCMMediaSharing] "C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WarReg_PopUp] "C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ORAHSSSessionManager] "C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O13 - Gopher Prefix:
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Eset HTTP Server (EHttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\bin32\nSvcAppFlt.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\bin32\nSvcIp.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
A voir également:
- Ordi lent et infecter svp
- Pc lent - Guide
- Comment reinitialiser un ordi - Guide
- Mon mac est lent comment le nettoyer - Guide
- Mon pc est trop lent et se bloque - Guide
- Ordi scrabble - Télécharger - Jeux vidéo
54 réponses
Télécharge Superantispyware (SAS) en cliquant sur ce lien :
Choisis "enregistrer" et enregistre-le sur ton bureau.
Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
Créé une icône sur le bureau.
Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.
- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
Dans la colonne de gauche, coche C:\Fixed Drive.
Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
Pour recopier les informations sur le forum, fais ceci :
- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
- Copie son contenu dans ta réponse.
Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
Choisis "enregistrer" et enregistre-le sur ton bureau.
Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.
Créé une icône sur le bureau.
Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.
- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :
Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.
- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.
- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".
Dans la colonne de gauche, coche C:\Fixed Drive.
Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"
Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.
A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.
Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".
Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.
Pour recopier les informations sur le forum, fais ceci :
- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.
- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.
- Copie son contenu dans ta réponse.
Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
slt merci de maider
ba en faite les chargement sont tres lent et certaine fois internet ne repond plus
et si mon antivirus est nod32 voila en esperant ton aide...
ba en faite les chargement sont tres lent et certaine fois internet ne repond plus
et si mon antivirus est nod32 voila en esperant ton aide...
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Fait ceci et poste moi le rapport à la suite de la question êtes vous aider par quelqu'un. Merci.
Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
Dézippe le dossier, double-clique sur GenProc.bat
En final, poste le contenu du rapport qui s'affiche.
Comment utiliser GenProc
Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
Dézippe le dossier, double-clique sur GenProc.bat
En final, poste le contenu du rapport qui s'affiche.
Comment utiliser GenProc
Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs
salut -;)
L'antivirus est bien présent : C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
Pour suivre....
L'antivirus est bien présent : C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
Pour suivre....
re: dsl pour le retard voici le rapport:
Rapport GenProc 2.351 [2] - 08/02/2009 - Windows Vista
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
Poste un rapport NanoScan https://www.micro-astuce.com/securite/NanoScan-Panda.php
__________________________________________________________________________________________________________
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
Rapport GenProc 2.351 [2] - 08/02/2009 - Windows Vista
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
Poste un rapport NanoScan https://www.micro-astuce.com/securite/NanoScan-Panda.php
__________________________________________________________________________________________________________
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
slt dsl pour le retard
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 02/09/2009 at 08:42 PM
Application Version : 4.25.1012
Core Rules Database Version : 3724
Trace Rules Database Version: 1698
Scan type : Complete Scan
Total Scan Time : 02:46:15
Memory items scanned : 679
Memory threats detected : 0
Registry items scanned : 7002
Registry threats detected : 1
File items scanned : 337432
File threats detected : 4
Unclassified.Unknown Origin
HKU\S-1-5-21-361662847-2979653976-3885516880-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Adware.Vundo/Variant-MSFake
C:\DOCUMENTS AND SETTINGS\LEFEVE CATHERINE\APPDATA\ROAMING\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
C:\DOCUMENTS AND SETTINGS\LEFEVE CATHERINE\APPLICATION DATA\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
C:\USERS\LEFEVE CATHERINE\APPDATA\ROAMING\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
C:\USERS\LEFEVE CATHERINE\APPLICATION DATA\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/
Generated 02/09/2009 at 08:42 PM
Application Version : 4.25.1012
Core Rules Database Version : 3724
Trace Rules Database Version: 1698
Scan type : Complete Scan
Total Scan Time : 02:46:15
Memory items scanned : 679
Memory threats detected : 0
Registry items scanned : 7002
Registry threats detected : 1
File items scanned : 337432
File threats detected : 4
Unclassified.Unknown Origin
HKU\S-1-5-21-361662847-2979653976-3885516880-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Adware.Vundo/Variant-MSFake
C:\DOCUMENTS AND SETTINGS\LEFEVE CATHERINE\APPDATA\ROAMING\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
C:\DOCUMENTS AND SETTINGS\LEFEVE CATHERINE\APPLICATION DATA\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
C:\USERS\LEFEVE CATHERINE\APPDATA\ROAMING\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
C:\USERS\LEFEVE CATHERINE\APPLICATION DATA\MICROSOFT\LIVE SEARCH\SUPPRESSION-LIVE-SEARCH.EXE
re:
ComboFix 09-02-10.01 - Lefeve Catherine 2009-02-10 21:21:37.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2814.1678 [GMT 1:00]
Lancé depuis: c:\users\Lefeve Catherine\Downloads\Killfix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Lefeve Catherine\AppData\Roaming\.#
c:\users\Lefeve Catherine\AppData\Roaming\.#\MBX@A68@17F2990.###
c:\users\Lefeve Catherine\AppData\Roaming\.#\MBX@A68@17F29C0.###
c:\users\Lefeve Catherine\AppData\Roaming\.#\MBX@A68@17F29F0.###
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-10 au 2009-02-10 ))))))))))))))))))))))))))))))))))))
.
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\SUPERAntiSpyware.com
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\users\All Users\SUPERAntiSpyware.com
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\programdata\SUPERAntiSpyware.com
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\program files\SUPERAntiSpyware
2009-02-09 17:31 . 2009-02-09 17:31 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-02-08 21:10 . 2009-02-08 21:10 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-08 21:10 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-08 21:10 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-07 20:31 . 2009-02-07 20:42 <REP> d-------- c:\program files\RogueRemover FREE
2009-02-06 12:26 . 2009-02-06 12:26 70,104 --a------ c:\windows\System32\GDIPFONTCACHEV1.DAT
2009-02-06 12:24 . 2009-02-08 12:48 <REP> d-------- C:\_OTMoveIt
2009-02-03 22:21 . 2009-02-03 22:22 <REP> d-------- c:\program files\trend micro
2009-02-03 19:09 . 2009-02-04 12:25 <REP> d-------- c:\program files\FindyKill
2009-02-01 01:22 . 2009-02-01 01:22 <REP> d-------- c:\program files\Common Files\Adobe
2009-02-01 00:27 . 2009-02-01 00:30 <REP> d-------- c:\users\Lefeve Catherine\.SunDownloadManager
2009-02-01 00:17 . 2009-02-01 00:17 <REP> d-------- c:\program files\Java
2009-01-31 20:50 . 2009-01-31 20:50 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Nullriver
2009-01-31 20:50 . 2009-01-31 21:08 <REP> d-------- c:\program files\PSPWare
2009-01-31 20:36 . 2009-01-31 20:36 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Red Kawa
2009-01-31 20:36 . 2009-01-31 20:37 <REP> d-------- c:\program files\Red Kawa
2009-01-31 20:36 . 2009-01-31 20:36 <REP> d-------- c:\program files\AviSynth 2.5
2009-01-31 20:36 . 2009-01-31 20:36 <REP> d-------- C:\OpenCandy
2009-01-31 18:07 . 2009-01-31 18:07 <REP> d-------- C:\My Videos
2009-01-31 18:05 . 2009-01-31 18:05 <REP> d-------- c:\users\All Users\Apowersoft
2009-01-31 18:05 . 2009-01-31 18:05 <REP> d-------- c:\programdata\Apowersoft
2009-01-31 18:05 . 2009-01-31 18:05 <REP> d-------- c:\program files\Apowersoft
2009-01-31 00:39 . 2009-01-31 00:39 <REP> d-------- c:\windows\Sun
2009-01-31 00:38 . 2009-02-01 00:17 410,984 --a------ c:\windows\System32\deploytk.dll
2009-01-30 19:12 . 2009-01-30 22:27 <REP> d-------- c:\program files\Panda Security
2009-01-30 12:11 . 1996-08-20 20:37 15,840 --a------ c:\windows\System32\Machnm1.exe
2009-01-30 12:11 . 2005-09-25 16:37 5,632 --a------ c:\windows\System32\Machnm64.sys
2009-01-30 12:11 . 2009-01-30 12:11 3,120 --a------ c:\windows\System32\118290.54
2009-01-30 12:11 . 2009-01-30 12:11 3,120 --a------ c:\windows\118294.78
2009-01-30 12:11 . 2003-08-13 00:27 2,304 --a------ c:\windows\System32\Machnm32.sys
2009-01-30 00:04 . 2009-01-30 00:04 <REP> d-------- C:\rsit
2009-01-26 23:09 . 2009-01-26 23:29 <REP> d-------- c:\users\All Users\Yahoo! Companion
2009-01-26 23:09 . 2009-01-26 23:29 <REP> d-------- c:\programdata\Yahoo! Companion
2009-01-26 23:08 . 2009-01-26 23:09 <REP> d-------- c:\program files\CCleaner
2009-01-26 20:43 . 2009-01-28 19:18 <REP> d----c--- c:\windows\System32\DRVSTORE
2009-01-26 20:43 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\System32\d3dx9_32.dll
2009-01-26 20:42 . 2009-01-26 20:42 <REP> d-------- c:\program files\Microsoft SQL Server Compact Edition
2009-01-25 21:56 . 2009-02-09 23:51 <REP> d-------- c:\users\All Users\Google Updater
2009-01-25 21:56 . 2009-02-09 23:51 <REP> d-------- c:\programdata\Google Updater
2009-01-25 19:20 . 2008-11-06 02:03 <REP> d-------- C:\SDFix
2009-01-25 18:33 . 2009-01-25 18:33 <REP> d-------- c:\users\All Users\WebRoot
2009-01-25 18:33 . 2009-01-25 18:33 <REP> d-------- c:\programdata\WebRoot
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- c:\users\Default.LOG2
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- c:\users\Default.LOG1
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- C:\ProgramData.LOG2
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- C:\ProgramData.LOG1
2009-01-25 13:03 . 2009-01-25 13:03 <REP> d-------- c:\program files\Webroot
2009-01-25 12:55 . 2009-01-25 12:55 164 --a------ C:\install.dat
2009-01-24 23:33 . 2009-01-24 23:33 <REP> d-------- c:\users\All Users\Avg8
2009-01-24 23:33 . 2009-01-24 23:33 <REP> d-------- c:\programdata\Avg8
2009-01-24 21:29 . 2009-01-24 21:29 <REP> d-------- c:\program files\AVG
2009-01-24 20:39 . 2009-01-24 20:39 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Malwarebytes
2009-01-24 20:39 . 2009-01-24 20:39 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-24 20:39 . 2009-01-24 20:39 <REP> d-------- c:\programdata\Malwarebytes
2009-01-24 15:47 . 2009-01-24 15:47 <REP> d-------- c:\program files\Alwil Software
2009-01-24 14:42 . 2009-01-24 14:42 <REP> d-------- c:\program files\Microsoft Silverlight
2009-01-24 13:36 . 2009-01-30 22:24 <REP> d-------- c:\users\All Users\Spybot - Search & Destroy
2009-01-24 13:36 . 2009-01-30 22:24 <REP> d-------- c:\programdata\Spybot - Search & Destroy
2009-01-24 13:36 . 2009-01-30 22:25 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-22 14:24 . 2009-01-22 14:24 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\CyberLink
2009-01-22 01:42 . 2009-01-22 01:42 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Yahoo!
2009-01-22 01:42 . 2009-01-26 23:09 <REP> d-------- c:\program files\Yahoo!
2009-01-22 01:41 . 2009-01-22 01:41 <REP> d-------- c:\program files\Veoh Networks
2009-01-18 22:15 . 2009-01-18 22:15 <REP> d-------- c:\program files\Common Files\Windows Live
2009-01-16 20:21 . 2009-02-04 22:30 <REP> d-------- c:\program files\Dofus
2009-01-14 22:02 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-11 18:54 . 2009-01-11 18:54 <REP> d-------- c:\users\All Users\NortonInstaller
2009-01-11 18:54 . 2009-01-11 18:54 <REP> d-------- c:\programdata\NortonInstaller
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 18:50 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-01 20:17 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\Vso
2009-01-29 21:38 --------- d-----w c:\programdata\NVIDIA
2009-01-28 18:17 --------- d-----w c:\program files\Windows Live
2009-01-28 15:40 --------- d-----w c:\program files\EA GAMES
2009-01-28 15:39 --------- d-----w c:\program files\Common Files\Oberon Media
2009-01-28 15:39 --------- d-----w c:\program files\Acer GameZone
2009-01-26 19:39 --------- d-----w c:\programdata\WLInstaller
2009-01-25 20:58 --------- d-----w c:\program files\Google
2009-01-25 11:41 --------- d-----w c:\programdata\McAfee
2009-01-25 11:34 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\vlc
2009-01-25 11:34 --------- d-----w c:\program files\Windows Photo Gallery
2009-01-25 11:34 --------- d-----w c:\program files\Windows Defender
2009-01-16 20:11 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\dvdcss
2009-01-15 21:17 --------- d-----w c:\program files\Norton Security Scan
2009-01-09 20:42 --------- d-----w c:\program files\Ares
2009-01-08 19:38 0 ----a-w c:\users\Lefeve Catherine\AppData\Roaming\wklnhst.dat
2009-01-08 19:38 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\Template
2009-01-03 23:05 --------- d---a-w c:\programdata\TEMP
2009-01-03 13:47 --------- d-----w c:\program files\SiteAdvisor
2009-01-03 13:38 --------- d-----w c:\programdata\AWEM
2009-01-03 13:27 --------- d-----w c:\programdata\MumboJumbo
2009-01-02 21:24 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\FloodLightGames
2009-01-02 21:17 192,512 ----a-w c:\windows\off-road-uninst.exe
2009-01-02 20:12 --------- d-----w c:\programdata\Media Center Programs
2009-01-02 17:20 --------- d-----w c:\programdata\SiteAdvisor
2009-01-01 20:21 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-01-01 20:21 47,360 ----a-w c:\users\Lefeve Catherine\AppData\Roaming\pcouffin.sys
2009-01-01 17:17 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\Shareaza
2009-01-01 15:28 --------- d-----w c:\program files\Shareaza
2009-01-01 14:56 --------- d-----w c:\program files\BitComet
2008-12-31 23:42 --------- d-----w c:\program files\eMule
2008-12-31 19:48 --------- d-----w c:\program files\SHARP
2008-12-27 20:21 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-12-27 16:56 --------- d-----w c:\programdata\ESET
2008-12-27 16:56 --------- d-----w c:\program files\ESET
2008-12-26 23:47 --------- d-----w c:\programdata\Microsoft Help
2008-12-26 23:33 --------- d-----w c:\program files\MSXML 4.0
2008-12-26 23:33 --------- d-----w c:\program files\Microsoft Works
2008-12-26 22:48 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-12-26 19:39 --------- d-----w c:\program files\TRENDnet
2008-12-26 18:14 --------- d-sh--w c:\programdata\Modèles
2008-12-26 18:14 --------- d-sh--w c:\programdata\Menu Démarrer
2008-12-26 18:14 --------- d-sh--w c:\programdata\Favoris
2008-12-26 18:14 --------- d-sh--w c:\programdata\Bureau
2008-12-26 18:14 --------- d-sh--w c:\program files\Fichiers communs
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 22:38 121392 --a------ c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ares"="c:\program files\Ares\Ares.exe" [2009-01-03 893952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\windows\RtHDVCpl.exe" [2008-03-26 5369856]
"Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-04-25 319488]
"EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-04-25 319488]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-22 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-22 92704]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-02-01 30192]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-01 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-424UB\WlanCU.exe [2007-04-29 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D0C4BE1C-C5B4-4EDF-8FAE-55F438D2DD45}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{D90364C1-473F-4313-B223-9241901080C1}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
"{AA766C76-F16E-4FE2-A422-7D2BC7C139D9}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
"{42C706D2-3910-46FE-98CE-7F03D2047D4F}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
"{5649A2D4-F7CA-4F7C-97E2-374C5D2FDF1C}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
"{DEDBB5C9-7C94-4700-B32A-CE4BFF5B1973}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
"{FB16079E-B65F-45E2-8AEC-A6FAD42159A2}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
"{88149B78-7766-4162-8F83-D8B6FC8BC0C6}"= c:\program files\Acer Arcade Live\Acer HomeMedia Trial Creator\Acer HomeMedia Trial Creator.exe:Acer HomeMedia Trial Creator
"{7ACC89C8-89F3-4312-9C9F-199767E21D32}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C579C023-D32A-41D7-8B1A-6026E5BF1B7B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B1E1D851-ED4E-43FF-BD3F-080B20BDC023}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
"{140386EE-96E0-4FEF-A02F-6FAC37BDD3A7}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{EF4F573B-DB47-4635-B3BF-FEB2070B6865}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{38BFF5AF-2C45-4A78-A138-33101997BA94}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{6AEEC8E4-82E8-4C7B-A265-0761020E8073}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{DD76C2F8-89EE-4986-880C-2661D4ACB58C}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{6A18787C-34F5-43E8-BD37-A88FF14BAB64}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{B02DA8D5-1203-4717-BE64-C3CC7B1FE6AD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BBF8AD80-93EC-4386-BA8B-6D49FA27E2E6}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"{42EFD4D1-3997-422C-86A9-6AFAE460B8F4}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"TCP Query User{31C61B21-AE01-4E77-85E9-96789B8B5A4D}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{50D0F718-542A-460D-8184-1C4206EE79F3}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"{4FC0BD5A-6859-4A99-976B-5E190426360A}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2154737F-A634-4520-B94E-2B37933ED036}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R0 ssfs0bbc;ssfs0bbc;c:\windows\System32\drivers\ssfs0bbc.sys [2008-08-09 29808]
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2008-02-20 33800]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-09 269448]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-05-09 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [2008-05-08 43552]
R3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\System32\drivers\RTL8187B.sys [2007-07-19 281088]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-12-26 30192]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [2009-02-08 38496]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-12-26 28224]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a62abb11-efc6-11dd-b9c6-001d72a8274c}]
\shell\AutoRun\command - e:\.pspware\PSPWareLauncher.exe
.
Contenu du dossier 'Tâches planifiées'
2009-02-08 c:\windows\Tasks\Norton Security Scan for Lefeve Catherine.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = hxxp://fr.fr.acer.yahoo.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-10 21:23:21
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-02-10 21:25:17
ComboFix-quarantined-files.txt 2009-02-10 20:25:15
Avant-CF: 92 403 924 992 octets libres
Après-CF: 92,079,439,872 octets libres
256 --- E O F --- 2009-02-10 10:04:41
ComboFix 09-02-10.01 - Lefeve Catherine 2009-02-10 21:21:37.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2814.1678 [GMT 1:00]
Lancé depuis: c:\users\Lefeve Catherine\Downloads\Killfix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Lefeve Catherine\AppData\Roaming\.#
c:\users\Lefeve Catherine\AppData\Roaming\.#\MBX@A68@17F2990.###
c:\users\Lefeve Catherine\AppData\Roaming\.#\MBX@A68@17F29C0.###
c:\users\Lefeve Catherine\AppData\Roaming\.#\MBX@A68@17F29F0.###
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-10 au 2009-02-10 ))))))))))))))))))))))))))))))))))))
.
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\SUPERAntiSpyware.com
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\users\All Users\SUPERAntiSpyware.com
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\programdata\SUPERAntiSpyware.com
2009-02-09 17:50 . 2009-02-09 17:50 <REP> d-------- c:\program files\SUPERAntiSpyware
2009-02-09 17:31 . 2009-02-09 17:31 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-02-08 21:10 . 2009-02-08 21:10 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-08 21:10 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-08 21:10 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-07 20:31 . 2009-02-07 20:42 <REP> d-------- c:\program files\RogueRemover FREE
2009-02-06 12:26 . 2009-02-06 12:26 70,104 --a------ c:\windows\System32\GDIPFONTCACHEV1.DAT
2009-02-06 12:24 . 2009-02-08 12:48 <REP> d-------- C:\_OTMoveIt
2009-02-03 22:21 . 2009-02-03 22:22 <REP> d-------- c:\program files\trend micro
2009-02-03 19:09 . 2009-02-04 12:25 <REP> d-------- c:\program files\FindyKill
2009-02-01 01:22 . 2009-02-01 01:22 <REP> d-------- c:\program files\Common Files\Adobe
2009-02-01 00:27 . 2009-02-01 00:30 <REP> d-------- c:\users\Lefeve Catherine\.SunDownloadManager
2009-02-01 00:17 . 2009-02-01 00:17 <REP> d-------- c:\program files\Java
2009-01-31 20:50 . 2009-01-31 20:50 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Nullriver
2009-01-31 20:50 . 2009-01-31 21:08 <REP> d-------- c:\program files\PSPWare
2009-01-31 20:36 . 2009-01-31 20:36 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Red Kawa
2009-01-31 20:36 . 2009-01-31 20:37 <REP> d-------- c:\program files\Red Kawa
2009-01-31 20:36 . 2009-01-31 20:36 <REP> d-------- c:\program files\AviSynth 2.5
2009-01-31 20:36 . 2009-01-31 20:36 <REP> d-------- C:\OpenCandy
2009-01-31 18:07 . 2009-01-31 18:07 <REP> d-------- C:\My Videos
2009-01-31 18:05 . 2009-01-31 18:05 <REP> d-------- c:\users\All Users\Apowersoft
2009-01-31 18:05 . 2009-01-31 18:05 <REP> d-------- c:\programdata\Apowersoft
2009-01-31 18:05 . 2009-01-31 18:05 <REP> d-------- c:\program files\Apowersoft
2009-01-31 00:39 . 2009-01-31 00:39 <REP> d-------- c:\windows\Sun
2009-01-31 00:38 . 2009-02-01 00:17 410,984 --a------ c:\windows\System32\deploytk.dll
2009-01-30 19:12 . 2009-01-30 22:27 <REP> d-------- c:\program files\Panda Security
2009-01-30 12:11 . 1996-08-20 20:37 15,840 --a------ c:\windows\System32\Machnm1.exe
2009-01-30 12:11 . 2005-09-25 16:37 5,632 --a------ c:\windows\System32\Machnm64.sys
2009-01-30 12:11 . 2009-01-30 12:11 3,120 --a------ c:\windows\System32\118290.54
2009-01-30 12:11 . 2009-01-30 12:11 3,120 --a------ c:\windows\118294.78
2009-01-30 12:11 . 2003-08-13 00:27 2,304 --a------ c:\windows\System32\Machnm32.sys
2009-01-30 00:04 . 2009-01-30 00:04 <REP> d-------- C:\rsit
2009-01-26 23:09 . 2009-01-26 23:29 <REP> d-------- c:\users\All Users\Yahoo! Companion
2009-01-26 23:09 . 2009-01-26 23:29 <REP> d-------- c:\programdata\Yahoo! Companion
2009-01-26 23:08 . 2009-01-26 23:09 <REP> d-------- c:\program files\CCleaner
2009-01-26 20:43 . 2009-01-28 19:18 <REP> d----c--- c:\windows\System32\DRVSTORE
2009-01-26 20:43 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\System32\d3dx9_32.dll
2009-01-26 20:42 . 2009-01-26 20:42 <REP> d-------- c:\program files\Microsoft SQL Server Compact Edition
2009-01-25 21:56 . 2009-02-09 23:51 <REP> d-------- c:\users\All Users\Google Updater
2009-01-25 21:56 . 2009-02-09 23:51 <REP> d-------- c:\programdata\Google Updater
2009-01-25 19:20 . 2008-11-06 02:03 <REP> d-------- C:\SDFix
2009-01-25 18:33 . 2009-01-25 18:33 <REP> d-------- c:\users\All Users\WebRoot
2009-01-25 18:33 . 2009-01-25 18:33 <REP> d-------- c:\programdata\WebRoot
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- c:\users\Default.LOG2
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- c:\users\Default.LOG1
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- C:\ProgramData.LOG2
2009-01-25 18:32 . 2009-01-25 18:32 0 --ah----- C:\ProgramData.LOG1
2009-01-25 13:03 . 2009-01-25 13:03 <REP> d-------- c:\program files\Webroot
2009-01-25 12:55 . 2009-01-25 12:55 164 --a------ C:\install.dat
2009-01-24 23:33 . 2009-01-24 23:33 <REP> d-------- c:\users\All Users\Avg8
2009-01-24 23:33 . 2009-01-24 23:33 <REP> d-------- c:\programdata\Avg8
2009-01-24 21:29 . 2009-01-24 21:29 <REP> d-------- c:\program files\AVG
2009-01-24 20:39 . 2009-01-24 20:39 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Malwarebytes
2009-01-24 20:39 . 2009-01-24 20:39 <REP> d-------- c:\users\All Users\Malwarebytes
2009-01-24 20:39 . 2009-01-24 20:39 <REP> d-------- c:\programdata\Malwarebytes
2009-01-24 15:47 . 2009-01-24 15:47 <REP> d-------- c:\program files\Alwil Software
2009-01-24 14:42 . 2009-01-24 14:42 <REP> d-------- c:\program files\Microsoft Silverlight
2009-01-24 13:36 . 2009-01-30 22:24 <REP> d-------- c:\users\All Users\Spybot - Search & Destroy
2009-01-24 13:36 . 2009-01-30 22:24 <REP> d-------- c:\programdata\Spybot - Search & Destroy
2009-01-24 13:36 . 2009-01-30 22:25 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-22 14:24 . 2009-01-22 14:24 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\CyberLink
2009-01-22 01:42 . 2009-01-22 01:42 <REP> d-------- c:\users\Lefeve Catherine\AppData\Roaming\Yahoo!
2009-01-22 01:42 . 2009-01-26 23:09 <REP> d-------- c:\program files\Yahoo!
2009-01-22 01:41 . 2009-01-22 01:41 <REP> d-------- c:\program files\Veoh Networks
2009-01-18 22:15 . 2009-01-18 22:15 <REP> d-------- c:\program files\Common Files\Windows Live
2009-01-16 20:21 . 2009-02-04 22:30 <REP> d-------- c:\program files\Dofus
2009-01-14 22:02 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-11 18:54 . 2009-01-11 18:54 <REP> d-------- c:\users\All Users\NortonInstaller
2009-01-11 18:54 . 2009-01-11 18:54 <REP> d-------- c:\programdata\NortonInstaller
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 18:50 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-01 20:17 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\Vso
2009-01-29 21:38 --------- d-----w c:\programdata\NVIDIA
2009-01-28 18:17 --------- d-----w c:\program files\Windows Live
2009-01-28 15:40 --------- d-----w c:\program files\EA GAMES
2009-01-28 15:39 --------- d-----w c:\program files\Common Files\Oberon Media
2009-01-28 15:39 --------- d-----w c:\program files\Acer GameZone
2009-01-26 19:39 --------- d-----w c:\programdata\WLInstaller
2009-01-25 20:58 --------- d-----w c:\program files\Google
2009-01-25 11:41 --------- d-----w c:\programdata\McAfee
2009-01-25 11:34 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\vlc
2009-01-25 11:34 --------- d-----w c:\program files\Windows Photo Gallery
2009-01-25 11:34 --------- d-----w c:\program files\Windows Defender
2009-01-16 20:11 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\dvdcss
2009-01-15 21:17 --------- d-----w c:\program files\Norton Security Scan
2009-01-09 20:42 --------- d-----w c:\program files\Ares
2009-01-08 19:38 0 ----a-w c:\users\Lefeve Catherine\AppData\Roaming\wklnhst.dat
2009-01-08 19:38 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\Template
2009-01-03 23:05 --------- d---a-w c:\programdata\TEMP
2009-01-03 13:47 --------- d-----w c:\program files\SiteAdvisor
2009-01-03 13:38 --------- d-----w c:\programdata\AWEM
2009-01-03 13:27 --------- d-----w c:\programdata\MumboJumbo
2009-01-02 21:24 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\FloodLightGames
2009-01-02 21:17 192,512 ----a-w c:\windows\off-road-uninst.exe
2009-01-02 20:12 --------- d-----w c:\programdata\Media Center Programs
2009-01-02 17:20 --------- d-----w c:\programdata\SiteAdvisor
2009-01-01 20:21 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2009-01-01 20:21 47,360 ----a-w c:\users\Lefeve Catherine\AppData\Roaming\pcouffin.sys
2009-01-01 17:17 --------- d-----w c:\users\Lefeve Catherine\AppData\Roaming\Shareaza
2009-01-01 15:28 --------- d-----w c:\program files\Shareaza
2009-01-01 14:56 --------- d-----w c:\program files\BitComet
2008-12-31 23:42 --------- d-----w c:\program files\eMule
2008-12-31 19:48 --------- d-----w c:\program files\SHARP
2008-12-27 20:21 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-12-27 16:56 --------- d-----w c:\programdata\ESET
2008-12-27 16:56 --------- d-----w c:\program files\ESET
2008-12-26 23:47 --------- d-----w c:\programdata\Microsoft Help
2008-12-26 23:33 --------- d-----w c:\program files\MSXML 4.0
2008-12-26 23:33 --------- d-----w c:\program files\Microsoft Works
2008-12-26 22:48 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-12-26 19:39 --------- d-----w c:\program files\TRENDnet
2008-12-26 18:14 --------- d-sh--w c:\programdata\Modèles
2008-12-26 18:14 --------- d-sh--w c:\programdata\Menu Démarrer
2008-12-26 18:14 --------- d-sh--w c:\programdata\Favoris
2008-12-26 18:14 --------- d-sh--w c:\programdata\Bureau
2008-12-26 18:14 --------- d-sh--w c:\program files\Fichiers communs
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-03-04 22:38 121392 --a------ c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ares"="c:\program files\Ares\Ares.exe" [2009-01-03 893952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-25 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\windows\RtHDVCpl.exe" [2008-03-26 5369856]
"Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-04-25 319488]
"EmpoweringTechnology"="c:\program files\Acer\Empowering Technology\Framework.Launcher.exe" [2008-04-25 319488]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-04 526896]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-01-25 204908]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-25 28672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-22 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-22 92704]
"WarReg_PopUp"="c:\program files\Acer\WR_PopUp\WarReg_PopUp.exe" [2008-01-29 303104]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-02-01 30192]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-01 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-424UB\WlanCU.exe [2007-04-29 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= c:\progra~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D0C4BE1C-C5B4-4EDF-8FAE-55F438D2DD45}"= c:\program files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{D90364C1-473F-4313-B223-9241901080C1}"= c:\program files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
"{AA766C76-F16E-4FE2-A422-7D2BC7C139D9}"= c:\program files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
"{42C706D2-3910-46FE-98CE-7F03D2047D4F}"= c:\program files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
"{5649A2D4-F7CA-4F7C-97E2-374C5D2FDF1C}"= c:\program files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
"{DEDBB5C9-7C94-4700-B32A-CE4BFF5B1973}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
"{FB16079E-B65F-45E2-8AEC-A6FAD42159A2}"= c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
"{88149B78-7766-4162-8F83-D8B6FC8BC0C6}"= c:\program files\Acer Arcade Live\Acer HomeMedia Trial Creator\Acer HomeMedia Trial Creator.exe:Acer HomeMedia Trial Creator
"{7ACC89C8-89F3-4312-9C9F-199767E21D32}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C579C023-D32A-41D7-8B1A-6026E5BF1B7B}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B1E1D851-ED4E-43FF-BD3F-080B20BDC023}"= c:\program files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
"{140386EE-96E0-4FEF-A02F-6FAC37BDD3A7}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{EF4F573B-DB47-4635-B3BF-FEB2070B6865}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{38BFF5AF-2C45-4A78-A138-33101997BA94}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe:AgentSvc.exe
"{6AEEC8E4-82E8-4C7B-A265-0761020E8073}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe:SchedulerSvc.exe
"{DD76C2F8-89EE-4986-880C-2661D4ACB58C}"= UDP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{6A18787C-34F5-43E8-BD37-A88FF14BAB64}"= TCP:c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe:BackupSvc.exe
"{B02DA8D5-1203-4717-BE64-C3CC7B1FE6AD}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BBF8AD80-93EC-4386-BA8B-6D49FA27E2E6}"= UDP:c:\program files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"{42EFD4D1-3997-422C-86A9-6AFAE460B8F4}"= TCP:c:\program files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"TCP Query User{31C61B21-AE01-4E77-85E9-96789B8B5A4D}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{50D0F718-542A-460D-8184-1C4206EE79F3}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows
"{4FC0BD5A-6859-4A99-976B-5E190426360A}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2154737F-A634-4520-B94E-2B37933ED036}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R0 ssfs0bbc;ssfs0bbc;c:\windows\System32\drivers\ssfs0bbc.sys [2008-08-09 29808]
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2008-02-20 33800]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-09 269448]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-05-09 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-25 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-25 131072]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [2008-05-08 43552]
R3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle;c:\windows\System32\drivers\RTL8187B.sys [2007-07-19 281088]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-12-26 30192]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [2009-02-08 38496]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-12-26 28224]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a62abb11-efc6-11dd-b9c6-001d72a8274c}]
\shell\AutoRun\command - e:\.pspware\PSPWareLauncher.exe
.
Contenu du dossier 'Tâches planifiées'
2009-02-08 c:\windows\Tasks\Norton Security Scan for Lefeve Catherine.job
- c:\program files\Norton Security Scan\Nss.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = hxxp://fr.fr.acer.yahoo.com
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-10 21:23:21
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-02-10 21:25:17
ComboFix-quarantined-files.txt 2009-02-10 20:25:15
Avant-CF: 92 403 924 992 octets libres
Après-CF: 92,079,439,872 octets libres
256 --- E O F --- 2009-02-10 10:04:41
tu doit avoir combofix sur ton ordi? ComboFix 09-02-10.01 - Lefeve Catherine 2009-02-10 21:21:37.1 - NTFSx86
On ne peux faire un hijackthis en combofix c'est impossible.
On ne peux faire un hijackthis en combofix c'est impossible.
Fait ceci STP :
Télécharge Toolscleaner sur ton Bureau :
* Double-clique sur ToolsCleaner2.exe et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
Télécharge Toolscleaner sur ton Bureau :
* Double-clique sur ToolsCleaner2.exe et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse