Tres grosse infection !!
Résolu
laura
-
sims de toi -
sims de toi -
salut tout le monde
apparement j'ai une tres grosse infection d'apres mon copain.
il ma conseillè de faire un rapport et de l envoyer ici
merci a vous de votre aide
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:11:40, on 16/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\3361\svchost.exe
C:\Windows\System32\inf\rundll33.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Windows\vsnpstd.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\hgcheck.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\msrstart.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\3361\svchost.exe
C:\Windows\System32\inf\rundll33.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Windows\vsnpstd.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\hgcheck.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Angélique\AppData\Local\wkewkio.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\umtcdtw.sys
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,userinit.exe,
O1 - Hosts: 92.62.101.129 google.co.uk
O1 - Hosts: 92.62.101.129 google.co.in
O1 - Hosts: 92.62.101.129 google.com
O1 - Hosts: 92.62.101.129 google.ru
O1 - Hosts: 92.62.101.129 google.de
O1 - Hosts: 92.62.101.129 google.ca
O1 - Hosts: 92.62.101.129 google.fr
O1 - Hosts: 92.62.101.129 google.it
O1 - Hosts: 92.62.101.129 google.es
O1 - Hosts: 92.62.101.129 google.pl
O1 - Hosts: 92.62.101.129 google.nl
O1 - Hosts: 92.62.101.129 www.google.co.uk
O1 - Hosts: 92.62.101.129 www.google.co.in
O1 - Hosts: 92.62.101.129 www.google.com
O1 - Hosts: 92.62.101.129 www.google.ru
O1 - Hosts: 92.62.101.129 www.google.de
O1 - Hosts: 92.62.101.129 www.google.ca
O1 - Hosts: 92.62.101.129 www.google.fr
O1 - Hosts: 92.62.101.129 www.google.it
O1 - Hosts: 92.62.101.129 www.google.es
O1 - Hosts: 92.62.101.129 www.google.pl
O1 - Hosts: 92.62.101.129 www.google.nl
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0f8b900a-324f-4f48-a4b4-8f184ec5ad8c} - C:\Windows\system32\zutozube.dll (file missing)
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: {1d4a2b1d-7066-0b68-cb04-893758140e8c} - {c8e04185-7398-40bc-86b0-6607d1b2a4d1} - C:\Windows\system32\vegfvy.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O4 - HKLM\..\Run: [svchost.exe] "C:\Windows\system32\3361\svchost.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [snpstd] C:\Windows\vsnpstd.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [hgcheck] C:\Windows\System32\hgcheck.exe
O4 - HKLM\..\Run: [gabaroriju] Rundll32.exe "C:\Windows\system32\febihago.dll",s
O4 - HKLM\..\Run: [Explorer] C:\Windows\system32\msrstart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\RunOnce: [svchost.exe] "C:\Windows\system32\3361\svchost.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [wkewkio] "c:\users\angélique\appdata\local\wkewkio.exe" wkewkio
O4 - HKLM\..\Policies\Explorer\Run: [xccinit] C:\Windows\system32\inf\rundll33.exe C:\Windows\xccdf16_090313a.dll xccd16
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-406981787-4262907449-3248825866-1000\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (User '?')
O4 - HKUS\S-1-5-21-406981787-4262907449-3248825866-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-18\..\Run: [Win32load] C:\Windows\system32\config\systemprofile\AppData\Roaming\syssl.exe -lds (User '?')
O4 - HKUS\.DEFAULT\..\Run: [Win32load] C:\Windows\system32\config\systemprofile\AppData\Roaming\syssl.exe -lds (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: c:\windows\system32\fibunewu.dll C:\Windows\system32\rukabipe.dll c:\windows\system32\jusirodo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\Windows\system32\afisicx.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\Windows\system32\mabidwe.exe
O23 - Service: sopidkc Service (sopidkc) - Unknown owner - C:\Windows\system32\sopidkc.exe
O23 - Service: Tcp ipx Service (Tcpipsrv) - Unknown owner - c:\windows\$ntunistalls\svchost.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
apparement j'ai une tres grosse infection d'apres mon copain.
il ma conseillè de faire un rapport et de l envoyer ici
merci a vous de votre aide
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:11:40, on 16/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\3361\svchost.exe
C:\Windows\System32\inf\rundll33.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Windows\vsnpstd.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\hgcheck.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\msrstart.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\3361\svchost.exe
C:\Windows\System32\inf\rundll33.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Windows\vsnpstd.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\hgcheck.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Angélique\AppData\Local\wkewkio.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\umtcdtw.sys
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,userinit.exe,
O1 - Hosts: 92.62.101.129 google.co.uk
O1 - Hosts: 92.62.101.129 google.co.in
O1 - Hosts: 92.62.101.129 google.com
O1 - Hosts: 92.62.101.129 google.ru
O1 - Hosts: 92.62.101.129 google.de
O1 - Hosts: 92.62.101.129 google.ca
O1 - Hosts: 92.62.101.129 google.fr
O1 - Hosts: 92.62.101.129 google.it
O1 - Hosts: 92.62.101.129 google.es
O1 - Hosts: 92.62.101.129 google.pl
O1 - Hosts: 92.62.101.129 google.nl
O1 - Hosts: 92.62.101.129 www.google.co.uk
O1 - Hosts: 92.62.101.129 www.google.co.in
O1 - Hosts: 92.62.101.129 www.google.com
O1 - Hosts: 92.62.101.129 www.google.ru
O1 - Hosts: 92.62.101.129 www.google.de
O1 - Hosts: 92.62.101.129 www.google.ca
O1 - Hosts: 92.62.101.129 www.google.fr
O1 - Hosts: 92.62.101.129 www.google.it
O1 - Hosts: 92.62.101.129 www.google.es
O1 - Hosts: 92.62.101.129 www.google.pl
O1 - Hosts: 92.62.101.129 www.google.nl
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0f8b900a-324f-4f48-a4b4-8f184ec5ad8c} - C:\Windows\system32\zutozube.dll (file missing)
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: {1d4a2b1d-7066-0b68-cb04-893758140e8c} - {c8e04185-7398-40bc-86b0-6607d1b2a4d1} - C:\Windows\system32\vegfvy.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O4 - HKLM\..\Run: [svchost.exe] "C:\Windows\system32\3361\svchost.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [snpstd] C:\Windows\vsnpstd.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [hgcheck] C:\Windows\System32\hgcheck.exe
O4 - HKLM\..\Run: [gabaroriju] Rundll32.exe "C:\Windows\system32\febihago.dll",s
O4 - HKLM\..\Run: [Explorer] C:\Windows\system32\msrstart.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\RunOnce: [svchost.exe] "C:\Windows\system32\3361\svchost.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [wkewkio] "c:\users\angélique\appdata\local\wkewkio.exe" wkewkio
O4 - HKLM\..\Policies\Explorer\Run: [xccinit] C:\Windows\system32\inf\rundll33.exe C:\Windows\xccdf16_090313a.dll xccd16
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?')
O4 - HKUS\S-1-5-21-406981787-4262907449-3248825866-1000\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (User '?')
O4 - HKUS\S-1-5-21-406981787-4262907449-3248825866-1001\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User '?')
O4 - HKUS\S-1-5-18\..\Run: [Win32load] C:\Windows\system32\config\systemprofile\AppData\Roaming\syssl.exe -lds (User '?')
O4 - HKUS\.DEFAULT\..\Run: [Win32load] C:\Windows\system32\config\systemprofile\AppData\Roaming\syssl.exe -lds (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O20 - AppInit_DLLs: c:\windows\system32\fibunewu.dll C:\Windows\system32\rukabipe.dll c:\windows\system32\jusirodo.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O23 - Service: afisicx Service (afisicx) - Unknown owner - C:\Windows\system32\afisicx.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: mabidwe Service (mabidwe) - Unknown owner - C:\Windows\system32\mabidwe.exe
O23 - Service: sopidkc Service (sopidkc) - Unknown owner - C:\Windows\system32\sopidkc.exe
O23 - Service: Tcp ipx Service (Tcpipsrv) - Unknown owner - c:\windows\$ntunistalls\svchost.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
A voir également:
- Tres grosse infection !!
- Infection ad.doubleclick.net ✓ - Forum Virus
- Infection FileRepMetagen - Forum Virus
- Infection WonderShare ✓ - Forum Virus
- Infection winrmsrv ✓ - Forum Virus
- Infection fahcore_a8 ✓ - Forum Virus
85 réponses
fais ceci :
Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
- Vas dans "Démarrer" puis Panneau de configuration.
- Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
- Clique sur Continuer.
- Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
- Valide par OK et redémarre.
Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517
ensuite retente toolbar
Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):
- Vas dans "Démarrer" puis Panneau de configuration.
- Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
- Clique sur Continuer.
- Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
- Valide par OK et redémarre.
Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517
ensuite retente toolbar
c'est ce que je fais
mais c'est normal que ça soit aussi long ?
car la ça fait une bonne demi heure que ça tourne
mais c'est normal que ça soit aussi long ?
car la ça fait une bonne demi heure que ça tourne
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Copie le texte ci-dessous :
File::
c:\windows\system32\febihago.dll
c:\windows\System32\dctool32.sys
c:\windows\system\xccef090313.exe
c:\windows\System32\hgcheck.exe
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\system32\3361\svchost.exe
c:\windows\system32\fibunewu.dll
c:\windows\system32\rukabipe.dll
c:\windows\system32\jusirodo.dll
c:\users\Angélique\aTzJGaoG.exe
c:\users\Angélique\LqPBtoniil.bat
c:\users\Angélique\mdqpJI.exe
Folder::
c:\program files\Navilog1
c:\program files\FindyKill
c:\program files\Common Files\Symantec Shared
c:\programdata\Symantec
Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Win32load"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"svchost.exe"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hgcheck"=-
"gabaroriju"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\syssl.exe"=-
"c:\\Windows\\system32\\3361\\svchost.exe"=-
DirLook::
c:\windows\System32\config\systemprofile\Documents
c:\windows\system32\3361
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt
S'il n'y a pas de rédémarrage, poste quand même le rapport
.
File::
c:\windows\system32\febihago.dll
c:\windows\System32\dctool32.sys
c:\windows\system\xccef090313.exe
c:\windows\System32\hgcheck.exe
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\system32\3361\svchost.exe
c:\windows\system32\fibunewu.dll
c:\windows\system32\rukabipe.dll
c:\windows\system32\jusirodo.dll
c:\users\Angélique\aTzJGaoG.exe
c:\users\Angélique\LqPBtoniil.bat
c:\users\Angélique\mdqpJI.exe
Folder::
c:\program files\Navilog1
c:\program files\FindyKill
c:\program files\Common Files\Symantec Shared
c:\programdata\Symantec
Registry::
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Win32load"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"svchost.exe"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hgcheck"=-
"gabaroriju"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\syssl.exe"=-
"c:\\Windows\\system32\\3361\\svchost.exe"=-
DirLook::
c:\windows\System32\config\systemprofile\Documents
c:\windows\system32\3361
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt
S'il n'y a pas de rédémarrage, poste quand même le rapport
.
salut chiquitine je ne sais pas si tu es la je te met me rapport de suite
le pc a l air d aller mieux en tout cas
le pc a l air d aller mieux en tout cas
voila le rapport
par contre j ai des fenetre de pub sur des antivirus qui arrete pas de s ' ouvrir
il est encore infectè tu crois?
ComboFix 09-03-15.01 - Angélique 2009-03-16 21:15:22.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2038.1210 [GMT 1:00]
Lancé depuis: c:\users\Angélique\Downloads\ComboFix.exe
Commutateurs utilisés :: c:\users\Angélique\Desktop\CFScript.txt
* Un nouveau point de restauration a été créé
FILE ::
c:\users\Angélique\aTzJGaoG.exe
c:\users\Angélique\LqPBtoniil.bat
c:\users\Angélique\mdqpJI.exe
c:\windows\system\xccef090313.exe
c:\windows\system32\3361\svchost.exe
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\System32\dctool32.sys
c:\windows\system32\febihago.dll
c:\windows\system32\fibunewu.dll
c:\windows\System32\hgcheck.exe
c:\windows\system32\jusirodo.dll
c:\windows\system32\rukabipe.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\FindyKill
c:\program files\FindyKill\FindyKill.cmd
c:\program files\FindyKill\Tools\ico.ico
c:\program files\FindyKill\Tools\Kill.exe
c:\program files\FindyKill\Tools\Proc.exe
c:\program files\FindyKill\Tools\Process.exe
c:\program files\FindyKill\Tools\SP2.reg
c:\program files\FindyKill\Tools\SP3.reg
c:\program files\FindyKill\Tools\swreg.exe
c:\program files\FindyKill\Tools\Trad.cmd
c:\program files\FindyKill\Tools\Vista.reg
c:\program files\FindyKill\Uninstal.exe
c:\program files\Navilog1
c:\program files\Navilog1\Backupnavi\wkewkio.dat
c:\program files\Navilog1\Backupnavi\wkewkio.exe
c:\program files\Navilog1\Backupnavi\wkewkio_nav.dat
c:\program files\Navilog1\Backupnavi\wkewkio_navps.dat
c:\program files\Navilog1\catchme.exe
c:\program files\Navilog1\Contents\Filess.bat
c:\program files\Navilog1\Contents\Folders.bat
c:\program files\Navilog1\Contents\Folderss.bat
c:\program files\Navilog1\Contents\Gnc2.bat
c:\program files\Navilog1\Contents\Gnc2su.bat
c:\program files\Navilog1\Contents\Gncs.bat
c:\program files\Navilog1\Contents\Gncssfil.bat
c:\program files\Navilog1\Contents\Heurs.bat
c:\program files\Navilog1\Contents\Heurss.bat
c:\program files\Navilog1\Contents\Orphus.bat
c:\program files\Navilog1\Contents\Wlist.bat
c:\program files\Navilog1\GetPaths.exe
c:\program files\Navilog1\gnc.exe
c:\program files\Navilog1\navilog1.bat
c:\program files\Navilog1\Navreb.bat
c:\program files\Navilog1\oem2ansi.exe
c:\program files\Navilog1\OsV.exe
c:\program files\Navilog1\Process.exe
c:\program files\Navilog1\reg.exe
c:\program files\Navilog1\regnavi.reg
c:\program files\Navilog1\Report\catchmeF.log
c:\program files\Navilog1\Safebackup\backup_registry.dat
c:\program files\Navilog1\Safebackup\HKCU_Run.reg
c:\program files\Navilog1\Safebackup\HKLM_Run.reg
c:\program files\Navilog1\Safebackup\HKLM_Startupreg.reg
c:\program files\Navilog1\Safebackup\HKLM_Uninstall.reg
c:\program files\Navilog1\traite.bat
c:\program files\Navilog1\traite2.bat
c:\program files\Navilog1\traite3.bat
c:\program files\Navilog1\unins000.dat
c:\program files\Navilog1\unins000.exe
c:\programdata\Symantec
c:\programdata\Symantec\Definitions\SymcData\nco1.0defs\latest-hub-webauth.sql\LHW.sql.bin
c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\catalog.dat
c:\programdata\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
c:\programdata\Symantec\LiveUpdate\Settings.LiveUpdate
c:\users\Angélique\aTzJGaoG.exe
c:\users\Angélique\LqPBtoniil.bat
c:\users\Angélique\mdqpJI.exe
c:\windows\system\xccef090313.exe
c:\windows\System32\dctool32.sys
c:\windows\system32\drivers\senekadilnmreq.sys
c:\windows\system32\evorebez.ini
c:\windows\system32\pjczbz.dll
c:\windows\system32\senekadghdfbqd.dll
c:\windows\system32\senekafrpibilo.dll
c:\windows\system32\senekasnvfpltj.dat
c:\windows\system32\senekatvcapumm.dat
c:\windows\system32\senekavotjnpxs.dll
c:\windows\system32\zidewomi.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
-------\Service_SENEKA
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-17 au 2009-03-17 ))))))))))))))))))))))))))))))))))))
.
2009-03-16 21:22 . 2009-03-16 21:22 265,361,525 --a------ c:\windows\MEMORY.DMP
2009-03-16 19:48 . 2009-03-16 19:48 50 --a------ c:\windows\MegaManager.INI
2009-03-16 19:40 . 2009-03-16 19:40 <REP> d-------- c:\users\All Users\Avira
2009-03-16 19:40 . 2009-03-16 19:40 <REP> d-------- c:\programdata\Avira
2009-03-16 19:40 . 2009-03-16 19:40 <REP> d-------- c:\program files\Avira
2009-03-16 16:45 . 2009-03-16 19:08 <REP> d-------- C:\ToolBar SD
2009-03-16 15:11 . 2009-03-16 15:11 <REP> d-------- c:\program files\Trend Micro
2009-03-14 19:38 . 2009-03-14 19:38 <REP> d-------- c:\program files\Bonjour
2009-03-14 12:49 . 2009-03-14 12:49 <REP> d-------- c:\program files\Combined Community Codec Pack
2009-03-14 12:18 . 2009-03-14 12:18 <REP> d-------- c:\windows\System32\config\systemprofile\Documents
2009-03-14 11:17 . 2009-03-14 11:17 <REP> d-------- c:\users\Angélique\AppData\Roaming\Malwarebytes
2009-03-14 10:15 . 2009-03-14 10:15 <REP> d-------- c:\program files\Lavalys
2009-03-13 17:38 . 2009-03-13 17:38 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\users\sophie\AppData\Roaming\Malwarebytes
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\users\All Users\Malwarebytes
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\programdata\Malwarebytes
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-13 17:37 . 2008-05-05 20:46 27,048 --a------ c:\windows\System32\drivers\mbamcatchme.sys
2009-03-13 17:37 . 2008-05-05 20:46 15,864 --a------ c:\windows\System32\drivers\mbam.sys
2009-03-13 17:23 . 2009-03-14 12:51 <REP> d-------- c:\program files\Error Repair Professional
2009-03-06 16:58 . 2009-03-06 16:58 <REP> d-------- c:\program files\Alwil Software
2009-03-05 23:01 . 2009-03-05 23:01 <REP> d-------- c:\users\Angélique\AppData\Roaming\nidle
2009-03-05 23:00 . 2009-03-05 23:01 <REP> d-------- c:\windows\System32\MR
2009-03-05 22:36 . 2009-03-05 22:36 2,560 --a------ c:\windows\_MSRSTRT.EXE
2009-03-05 22:11 . 2009-03-05 22:11 16 --a------ c:\windows\System32\coh.cache
2009-03-05 21:27 . 2009-03-05 23:00 <REP> d-------- c:\windows\System32\aNI02
2009-03-05 21:27 . 2009-03-05 23:00 <REP> d-------- c:\temp\atmp8
2009-03-03 19:01 . 2009-03-03 19:01 <REP> d--hs---- c:\windows\$ntunistalls
2009-03-02 19:32 . 2009-03-16 21:13 <REP> d-------- c:\windows\System32\3361
2009-03-02 19:32 . 2009-03-02 19:32 108,336 --a------ c:\windows\System32\MSWINSCK.OCX
2009-02-28 18:55 . 2009-02-28 18:55 <REP> d-------- C:\La Fouine - Mes Repères (2009)
2009-02-28 11:18 . 2009-03-16 19:54 209 --a------ c:\windows\System32\hgset.ini
2009-02-28 11:18 . 2009-03-16 17:51 52 --a------ c:\windows\System32\work.ini
2009-02-28 11:17 . 2002-02-15 14:02 676,352 --a------ c:\windows\System32\rtl60.bpl
2009-02-28 11:14 . 2009-03-16 15:58 <REP> d-------- c:\windows\System32\inf
2009-02-22 17:13 . 2009-02-22 17:13 12,540 ---hs---- C:\AlbumArt_{19E996A3-90D2-4ABB-9553-C2E08FAAA4BE}_Large.jpg
2009-02-22 17:13 . 2009-02-22 17:13 9,547 ---hs---- C:\Folder.jpg
2009-02-22 17:13 . 2009-02-22 17:13 9,547 ---hs---- C:\AlbumArt_{E6043A2C-BBEB-49C5-BCF0-5259B6332C34}_Large.jpg
2009-02-22 17:13 . 2009-02-22 17:13 3,172 ---hs---- C:\AlbumArt_{19E996A3-90D2-4ABB-9553-C2E08FAAA4BE}_Small.jpg
2009-02-22 17:13 . 2009-02-22 17:13 2,464 ---hs---- C:\AlbumArtSmall.jpg
2009-02-22 17:13 . 2009-02-22 17:13 2,464 ---hs---- C:\AlbumArt_{E6043A2C-BBEB-49C5-BCF0-5259B6332C34}_Small.jpg
2009-02-22 17:13 . 2009-02-22 17:13 357 ---hs---- C:\desktop.ini
2009-02-18 21:24 . 2009-03-05 22:36 <REP> d-------- c:\program files\Hotspot_Shield
2009-02-18 21:24 . 2009-02-18 21:24 <REP> d-------- c:\program files\Conduit
2009-02-17 12:58 . 2009-02-17 12:58 244 --ah----- C:\sqmnoopt00.sqm
2009-02-17 12:58 . 2009-02-17 12:58 232 --ah----- C:\sqmdata00.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 07:28 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-17 07:28 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-16 18:49 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-14 10:17 --------- d-----w c:\users\Angélique\AppData\Roaming\Malwarebytes
2009-03-13 17:54 --------- d-----w c:\users\sophie\AppData\Roaming\Toshiba
2009-03-13 16:39 --------- d-----w c:\program files\CCleaner
2009-03-05 22:01 --------- d-----w c:\users\Angélique\AppData\Roaming\nidle
2009-03-05 21:57 --------- d-----w c:\program files\DivX
2009-03-05 21:46 --------- d-----w c:\program files\PCFriendly
2009-02-28 18:37 --------- d-----w c:\users\Angélique\AppData\Roaming\LimeWire
2009-02-21 15:03 --------- d-----w c:\users\sophie\AppData\Roaming\LimeWire
2009-02-15 23:14 --------- d-----w c:\program files\skyrocktbar
2009-02-15 17:43 --------- d-----w c:\program files\LimeWire
2009-02-15 16:50 --------- d-----w c:\users\Angélique\AppData\Roaming\AVS4YOU
2009-02-15 16:50 --------- d-----w c:\program files\AVS4YOU
2009-02-15 16:37 --------- d-----w c:\users\Angélique\AppData\Roaming\MegauploadToolbar
2009-02-15 16:37 --------- d-----w c:\programdata\Megaupload
2009-02-15 16:37 --------- d-----w c:\programdata\EmailNotifier
2009-02-15 16:37 --------- d-----w c:\program files\MegauploadToolbar
2009-01-23 18:27 --------- d-----w c:\users\Angélique\AppData\Roaming\DivX
2009-01-21 15:52 --------- d-----w c:\users\sophie\AppData\Roaming\DivX
2009-01-17 17:45 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-15 04:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-12-12 02:16 174 --sha-w c:\program files\desktop.ini
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\3361 ----
2009-03-16 20:56 4 --a------ c:\windows\system32\3361\mlog
---- Directory of c:\windows\System32\config\systemprofile\Documents ----
2009-03-14 12:18 597 --a------ c:\windows\System32\config\systemprofile\Documents\Contacts\Angélique.contact
2009-03-14 12:18 412 --ahs---- c:\windows\System32\config\systemprofile\Documents\Contacts\desktop.ini
((((((((((((((((((((((((((((( SnapShot@2009-03-16_16.07.40.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-16 15:01:47 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-03-16 20:07:50 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-03-16 15:02:56 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-16 15:02:56 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-16 15:04:15 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-16 15:04:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-16 15:03:48 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-17 07:27:45 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-16 14:29:44 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009031620090317\index.dat
+ 2009-03-16 15:13:26 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009031620090317\index.dat
- 2009-03-16 15:03:48 376,832 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 07:27:45 393,216 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-16 15:03:48 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-17 07:27:45 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-16 14:51:42 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-16 19:57:34 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-16 19:57:34 262,144 ---ha-w c:\windows\System32\config\systemprofile\ntuser.dat.LOG1
+ 2008-10-30 09:21:03 75,072 ----a-w c:\windows\System32\drivers\avipbb.sys
+ 2007-11-08 17:03:26 21,248 ----a-w c:\windows\System32\drivers\ssmdrv.sys
+ 2009-03-16 15:54:02 84,992 --sha-w c:\windows\System32\pawovuda.dll
- 2009-03-16 14:58:03 7,924 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
+ 2009-03-16 20:24:51 9,138 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
- 2009-03-16 14:58:03 83,840 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-16 20:24:51 84,774 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-16 14:57:55 56,576 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-16 20:13:25 57,980 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-16 15:53:59 79,872 --sha-w c:\windows\System32\zeberove.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0f8b900a-324f-4f48-a4b4-8f184ec5ad8c}]
c:\windows\system32\zutozube.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-969A-2AB983EE729B}]
2008-06-03 14:52 2012632 --a------ c:\progra~1\SKYROC~1\SKYROC~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}]
2008-08-04 21:44 1947080 --a------ c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "c:\progra~1\MEGAUP~2\MEGAUP~1.DLL" [2008-08-04 1947080]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "c:\progra~1\MEGAUP~2\MEGAUP~1.DLL" [2008-08-04 1947080]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1232896]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-14 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-07 185896]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"snpstd"="c:\windows\vsnpstd.exe" [2005-10-11 339968]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"fae266ec"="c:\windows\system32\zeberove.dll" [2009-03-16 79872]
"CPMf9d15570"="c:\windows\system32\pawovuda.dll" [2009-03-16 84992]
"MSConfig"="c:\windows\system32\msconfig.exe" [2006-11-02 222208]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Win32load"="c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe" [2009-02-22 5632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\pawovuda.dll" [2009-03-16 84992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\pawovuda.dll [2009-03-16 84992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\pawovuda.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdss.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\xcommsvr.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\[u]0/uautocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 2008-06-12 13:28 266497 c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 2008-05-18 10:14 5799936 c:\program files\eMule\eMule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
--a------ 2007-02-19 15:00 571024 c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-406981787-4262907449-3248825866-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2AADE598-D30B-4020-84C1-D45D536EE837}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CBD24638-2A19-4B78-A91C-F72D8E223730}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{5FF44E8C-063A-4EE9-818A-A8DFEEC41855}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{B7A716A7-4ED8-4B2A-BEC0-DA8881B3E345}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{3EF6132F-255C-4919-8131-11E3E1ED3FDC}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{1A7E7381-C340-4191-AA62-2BF35DDEAD47}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B0220275-8A2C-4283-878B-F693E66D88AF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{AC409A63-E931-4E4C-A2CB-6AAA883E4B4B}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F802DFD6-676A-4343-B415-F203C112B618}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C32D9118-011F-4B92-ACDE-FF855B0CDA91}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{E5E79935-E3F3-4E17-BB9F-268BB3A0FAE2}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{2A4CF6DD-F756-4D72-9B87-B9355F7ACDA8}"= UDP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{0638A894-EDA4-42FE-AB6D-020A2EAB2966}"= TCP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{B380569C-6A99-4C0E-970C-A1D0A43DA58E}"= UDP:c:\windows\System32\wininit.exe:wininit
"{AA27C693-EFD5-49A9-832B-A62B5E5D97DE}"= TCP:c:\windows\System32\wininit.exe:wininit
"{16FA3A40-E187-4724-A1B4-834D8351429B}"= UDP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{AC91D579-113C-4C12-AED3-FCAA0EE04884}"= TCP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{D81775A1-B7A7-45EB-BDFA-D8D90F767CC9}"= UDP:c:\windows\explorer.exe:Explorer
"{54A4E806-6CB9-4282-AC40-366C983AB977}"= TCP:c:\windows\explorer.exe:Explorer
"{0EF61965-D101-4AE0-96FA-1DCE2A0A9F75}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1BA8EB8C-FBF3-4BD4-8DAD-0B697016189C}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3C1EFE2C-5A9B-4AC9-9D16-D66D63E7E114}"= UDP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{C35AEF5A-C597-4FD5-98AF-0599E0491925}"= TCP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{A0C07B34-FA4A-4AD8-B0CA-01DD7BB44DFB}"= UDP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{82BFF3FC-F03F-4A45-8108-4D4D7B5699B9}"= TCP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{759FE909-AFB0-4340-98C4-E2F7DC93CECB}"= UDP:c:\combofix\NirCmd.cfexe:NirCmd
"{47A635DC-82BC-4083-816D-7200503E58B0}"= TCP:c:\combofix\NirCmd.cfexe:NirCmd
"{0F329B87-0929-413B-A1EE-1838CFCA42E6}"= UDP:c:\windows\System32\igfxpers.exe:igfxpers
"{B84D3E4A-584F-4FE2-9570-5CCB75B11FF6}"= TCP:c:\windows\System32\igfxpers.exe:igfxpers
"{634DEC58-1B08-420F-9AA0-3F4C9BAD984A}"= UDP:c:\windows\System32\mobsync.exe:mobsync
"{E7CE97ED-BA85-4D4C-8216-78EA6F9B1473}"= TCP:c:\windows\System32\mobsync.exe:mobsync
"{1401CA5E-8649-4D53-BE6B-350BFD908D86}"= UDP:c:\windows\System32\igfxtray.exe:igfxtray
"{4816D01E-01C8-4728-8B4C-40327168C0C7}"= TCP:c:\windows\System32\igfxtray.exe:igfxtray
"{E4E9ABFA-7968-45CA-88BF-1526017058EF}"= UDP:c:\windows\ehome\ehtray.exe:ehtray
"{E03B7B00-B8B4-4CDA-82D1-BD1DA045A0A5}"= TCP:c:\windows\ehome\ehtray.exe:ehtray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\nscagent.exe"= c:\windows\system32\config\systemprofile\AppData\Roaming\nscagent.exe:*:Enabled:Win32load
R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
R3 TpChoice;Touch Pad Detection Filter driver; [x]
R4 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
S2 Tcpipsrv;Tcp ipx Service;c:\windows\$ntunistalls\svchost.exe [2009-03-03 197120]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - AFD
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - Beep
*Deregistered* - BlueletAudio
*Deregistered* - BlueletSCOAudio
*Deregistered* - bowser
*Deregistered* - BT
*Deregistered* - BTHidEnum
*Deregistered* - BTHidMgr
*Deregistered* - cdfs
*Deregistered* - circlass
*Deregistered* - CLFS
*Deregistered* - Compbatt
*Deregistered* - crcdisk
*Deregistered* - DfsC
*Deregistered* - DXGKrnl
*Deregistered* - fastfat
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - HTTP
*Deregistered* - iScsiPrt
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - Modem
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - msahci
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NativeWifiP
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - rspndr
*Deregistered* - secdrv
*Deregistered* - Serenum
*Deregistered* - Smb
*Deregistered* - spldr
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - ssmdrv
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - TermDD
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - umbus
*Deregistered* - VcommMgr
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8956d3b-eee8-11dd-904d-001167714e6e}]
\shell\AutoRun\command - G:\AMCD.EXE
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{7c7e23ae-ec55-4c54-8920-947abe1c08cf} - c:\windows\system32\pjczbz.dll
MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr
FF - ProfilePath - c:\users\Angélique\AppData\Roaming\Mozilla\Firefox\Profiles\19mwtt7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 21:23:25
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(820)
c:\windows\system32\pawovuda.dll
- - - - - - - > 'lsass.exe'(780)
c:\windows\system32\pawovuda.dll
- - - - - - - > 'Explorer.exe'(5372)
c:\windows\system32\pawovuda.dll
c:\windows\system32\zeberove.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\conime.exe
c:\windows\System32\conime.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-17 8:32:03 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-17 07:31:56
ComboFix2.txt 2009-03-16 15:08:51
Avant-CF: 4,265,451,520 octets libres
Après-CF: 3,597,389,824 octets libres
529 --- E O F --- 2009-02-20 10:56:48
par contre j ai des fenetre de pub sur des antivirus qui arrete pas de s ' ouvrir
il est encore infectè tu crois?
ComboFix 09-03-15.01 - Angélique 2009-03-16 21:15:22.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2038.1210 [GMT 1:00]
Lancé depuis: c:\users\Angélique\Downloads\ComboFix.exe
Commutateurs utilisés :: c:\users\Angélique\Desktop\CFScript.txt
* Un nouveau point de restauration a été créé
FILE ::
c:\users\Angélique\aTzJGaoG.exe
c:\users\Angélique\LqPBtoniil.bat
c:\users\Angélique\mdqpJI.exe
c:\windows\system\xccef090313.exe
c:\windows\system32\3361\svchost.exe
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\System32\dctool32.sys
c:\windows\system32\febihago.dll
c:\windows\system32\fibunewu.dll
c:\windows\System32\hgcheck.exe
c:\windows\system32\jusirodo.dll
c:\windows\system32\rukabipe.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\Symantec Shared
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
c:\program files\FindyKill
c:\program files\FindyKill\FindyKill.cmd
c:\program files\FindyKill\Tools\ico.ico
c:\program files\FindyKill\Tools\Kill.exe
c:\program files\FindyKill\Tools\Proc.exe
c:\program files\FindyKill\Tools\Process.exe
c:\program files\FindyKill\Tools\SP2.reg
c:\program files\FindyKill\Tools\SP3.reg
c:\program files\FindyKill\Tools\swreg.exe
c:\program files\FindyKill\Tools\Trad.cmd
c:\program files\FindyKill\Tools\Vista.reg
c:\program files\FindyKill\Uninstal.exe
c:\program files\Navilog1
c:\program files\Navilog1\Backupnavi\wkewkio.dat
c:\program files\Navilog1\Backupnavi\wkewkio.exe
c:\program files\Navilog1\Backupnavi\wkewkio_nav.dat
c:\program files\Navilog1\Backupnavi\wkewkio_navps.dat
c:\program files\Navilog1\catchme.exe
c:\program files\Navilog1\Contents\Filess.bat
c:\program files\Navilog1\Contents\Folders.bat
c:\program files\Navilog1\Contents\Folderss.bat
c:\program files\Navilog1\Contents\Gnc2.bat
c:\program files\Navilog1\Contents\Gnc2su.bat
c:\program files\Navilog1\Contents\Gncs.bat
c:\program files\Navilog1\Contents\Gncssfil.bat
c:\program files\Navilog1\Contents\Heurs.bat
c:\program files\Navilog1\Contents\Heurss.bat
c:\program files\Navilog1\Contents\Orphus.bat
c:\program files\Navilog1\Contents\Wlist.bat
c:\program files\Navilog1\GetPaths.exe
c:\program files\Navilog1\gnc.exe
c:\program files\Navilog1\navilog1.bat
c:\program files\Navilog1\Navreb.bat
c:\program files\Navilog1\oem2ansi.exe
c:\program files\Navilog1\OsV.exe
c:\program files\Navilog1\Process.exe
c:\program files\Navilog1\reg.exe
c:\program files\Navilog1\regnavi.reg
c:\program files\Navilog1\Report\catchmeF.log
c:\program files\Navilog1\Safebackup\backup_registry.dat
c:\program files\Navilog1\Safebackup\HKCU_Run.reg
c:\program files\Navilog1\Safebackup\HKLM_Run.reg
c:\program files\Navilog1\Safebackup\HKLM_Startupreg.reg
c:\program files\Navilog1\Safebackup\HKLM_Uninstall.reg
c:\program files\Navilog1\traite.bat
c:\program files\Navilog1\traite2.bat
c:\program files\Navilog1\traite3.bat
c:\program files\Navilog1\unins000.dat
c:\program files\Navilog1\unins000.exe
c:\programdata\Symantec
c:\programdata\Symantec\Definitions\SymcData\nco1.0defs\latest-hub-webauth.sql\LHW.sql.bin
c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\BinHub\catalog.dat
c:\programdata\Symantec\LiveUpdate\Product.Inventory.LiveUpdate
c:\programdata\Symantec\LiveUpdate\Settings.LiveUpdate
c:\users\Angélique\aTzJGaoG.exe
c:\users\Angélique\LqPBtoniil.bat
c:\users\Angélique\mdqpJI.exe
c:\windows\system\xccef090313.exe
c:\windows\System32\dctool32.sys
c:\windows\system32\drivers\senekadilnmreq.sys
c:\windows\system32\evorebez.ini
c:\windows\system32\pjczbz.dll
c:\windows\system32\senekadghdfbqd.dll
c:\windows\system32\senekafrpibilo.dll
c:\windows\system32\senekasnvfpltj.dat
c:\windows\system32\senekatvcapumm.dat
c:\windows\system32\senekavotjnpxs.dll
c:\windows\system32\zidewomi.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
-------\Service_SENEKA
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-17 au 2009-03-17 ))))))))))))))))))))))))))))))))))))
.
2009-03-16 21:22 . 2009-03-16 21:22 265,361,525 --a------ c:\windows\MEMORY.DMP
2009-03-16 19:48 . 2009-03-16 19:48 50 --a------ c:\windows\MegaManager.INI
2009-03-16 19:40 . 2009-03-16 19:40 <REP> d-------- c:\users\All Users\Avira
2009-03-16 19:40 . 2009-03-16 19:40 <REP> d-------- c:\programdata\Avira
2009-03-16 19:40 . 2009-03-16 19:40 <REP> d-------- c:\program files\Avira
2009-03-16 16:45 . 2009-03-16 19:08 <REP> d-------- C:\ToolBar SD
2009-03-16 15:11 . 2009-03-16 15:11 <REP> d-------- c:\program files\Trend Micro
2009-03-14 19:38 . 2009-03-14 19:38 <REP> d-------- c:\program files\Bonjour
2009-03-14 12:49 . 2009-03-14 12:49 <REP> d-------- c:\program files\Combined Community Codec Pack
2009-03-14 12:18 . 2009-03-14 12:18 <REP> d-------- c:\windows\System32\config\systemprofile\Documents
2009-03-14 11:17 . 2009-03-14 11:17 <REP> d-------- c:\users\Angélique\AppData\Roaming\Malwarebytes
2009-03-14 10:15 . 2009-03-14 10:15 <REP> d-------- c:\program files\Lavalys
2009-03-13 17:38 . 2009-03-13 17:38 <REP> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\users\sophie\AppData\Roaming\Malwarebytes
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\users\All Users\Malwarebytes
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\programdata\Malwarebytes
2009-03-13 17:37 . 2009-03-13 17:37 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-13 17:37 . 2008-05-05 20:46 27,048 --a------ c:\windows\System32\drivers\mbamcatchme.sys
2009-03-13 17:37 . 2008-05-05 20:46 15,864 --a------ c:\windows\System32\drivers\mbam.sys
2009-03-13 17:23 . 2009-03-14 12:51 <REP> d-------- c:\program files\Error Repair Professional
2009-03-06 16:58 . 2009-03-06 16:58 <REP> d-------- c:\program files\Alwil Software
2009-03-05 23:01 . 2009-03-05 23:01 <REP> d-------- c:\users\Angélique\AppData\Roaming\nidle
2009-03-05 23:00 . 2009-03-05 23:01 <REP> d-------- c:\windows\System32\MR
2009-03-05 22:36 . 2009-03-05 22:36 2,560 --a------ c:\windows\_MSRSTRT.EXE
2009-03-05 22:11 . 2009-03-05 22:11 16 --a------ c:\windows\System32\coh.cache
2009-03-05 21:27 . 2009-03-05 23:00 <REP> d-------- c:\windows\System32\aNI02
2009-03-05 21:27 . 2009-03-05 23:00 <REP> d-------- c:\temp\atmp8
2009-03-03 19:01 . 2009-03-03 19:01 <REP> d--hs---- c:\windows\$ntunistalls
2009-03-02 19:32 . 2009-03-16 21:13 <REP> d-------- c:\windows\System32\3361
2009-03-02 19:32 . 2009-03-02 19:32 108,336 --a------ c:\windows\System32\MSWINSCK.OCX
2009-02-28 18:55 . 2009-02-28 18:55 <REP> d-------- C:\La Fouine - Mes Repères (2009)
2009-02-28 11:18 . 2009-03-16 19:54 209 --a------ c:\windows\System32\hgset.ini
2009-02-28 11:18 . 2009-03-16 17:51 52 --a------ c:\windows\System32\work.ini
2009-02-28 11:17 . 2002-02-15 14:02 676,352 --a------ c:\windows\System32\rtl60.bpl
2009-02-28 11:14 . 2009-03-16 15:58 <REP> d-------- c:\windows\System32\inf
2009-02-22 17:13 . 2009-02-22 17:13 12,540 ---hs---- C:\AlbumArt_{19E996A3-90D2-4ABB-9553-C2E08FAAA4BE}_Large.jpg
2009-02-22 17:13 . 2009-02-22 17:13 9,547 ---hs---- C:\Folder.jpg
2009-02-22 17:13 . 2009-02-22 17:13 9,547 ---hs---- C:\AlbumArt_{E6043A2C-BBEB-49C5-BCF0-5259B6332C34}_Large.jpg
2009-02-22 17:13 . 2009-02-22 17:13 3,172 ---hs---- C:\AlbumArt_{19E996A3-90D2-4ABB-9553-C2E08FAAA4BE}_Small.jpg
2009-02-22 17:13 . 2009-02-22 17:13 2,464 ---hs---- C:\AlbumArtSmall.jpg
2009-02-22 17:13 . 2009-02-22 17:13 2,464 ---hs---- C:\AlbumArt_{E6043A2C-BBEB-49C5-BCF0-5259B6332C34}_Small.jpg
2009-02-22 17:13 . 2009-02-22 17:13 357 ---hs---- C:\desktop.ini
2009-02-18 21:24 . 2009-03-05 22:36 <REP> d-------- c:\program files\Hotspot_Shield
2009-02-18 21:24 . 2009-02-18 21:24 <REP> d-------- c:\program files\Conduit
2009-02-17 12:58 . 2009-02-17 12:58 244 --ah----- C:\sqmnoopt00.sqm
2009-02-17 12:58 . 2009-02-17 12:58 232 --ah----- C:\sqmdata00.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 07:28 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-17 07:28 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-16 18:49 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-14 10:17 --------- d-----w c:\users\Angélique\AppData\Roaming\Malwarebytes
2009-03-13 17:54 --------- d-----w c:\users\sophie\AppData\Roaming\Toshiba
2009-03-13 16:39 --------- d-----w c:\program files\CCleaner
2009-03-05 22:01 --------- d-----w c:\users\Angélique\AppData\Roaming\nidle
2009-03-05 21:57 --------- d-----w c:\program files\DivX
2009-03-05 21:46 --------- d-----w c:\program files\PCFriendly
2009-02-28 18:37 --------- d-----w c:\users\Angélique\AppData\Roaming\LimeWire
2009-02-21 15:03 --------- d-----w c:\users\sophie\AppData\Roaming\LimeWire
2009-02-15 23:14 --------- d-----w c:\program files\skyrocktbar
2009-02-15 17:43 --------- d-----w c:\program files\LimeWire
2009-02-15 16:50 --------- d-----w c:\users\Angélique\AppData\Roaming\AVS4YOU
2009-02-15 16:50 --------- d-----w c:\program files\AVS4YOU
2009-02-15 16:37 --------- d-----w c:\users\Angélique\AppData\Roaming\MegauploadToolbar
2009-02-15 16:37 --------- d-----w c:\programdata\Megaupload
2009-02-15 16:37 --------- d-----w c:\programdata\EmailNotifier
2009-02-15 16:37 --------- d-----w c:\program files\MegauploadToolbar
2009-01-23 18:27 --------- d-----w c:\users\Angélique\AppData\Roaming\DivX
2009-01-21 15:52 --------- d-----w c:\users\sophie\AppData\Roaming\DivX
2009-01-17 17:45 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-15 04:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-12-12 02:16 174 --sha-w c:\program files\desktop.ini
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\windows\system32\3361 ----
2009-03-16 20:56 4 --a------ c:\windows\system32\3361\mlog
---- Directory of c:\windows\System32\config\systemprofile\Documents ----
2009-03-14 12:18 597 --a------ c:\windows\System32\config\systemprofile\Documents\Contacts\Angélique.contact
2009-03-14 12:18 412 --ahs---- c:\windows\System32\config\systemprofile\Documents\Contacts\desktop.ini
((((((((((((((((((((((((((((( SnapShot@2009-03-16_16.07.40.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-16 15:01:47 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-03-16 20:07:50 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-03-16 15:02:56 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-16 15:02:56 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-16 15:04:15 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-16 15:04:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-16 20:23:15 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-16 15:03:48 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-17 07:27:45 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-16 14:29:44 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009031620090317\index.dat
+ 2009-03-16 15:13:26 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009031620090317\index.dat
- 2009-03-16 15:03:48 376,832 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 07:27:45 393,216 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-16 15:03:48 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-17 07:27:45 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-16 14:51:42 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-16 19:57:34 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-03-16 19:57:34 262,144 ---ha-w c:\windows\System32\config\systemprofile\ntuser.dat.LOG1
+ 2008-10-30 09:21:03 75,072 ----a-w c:\windows\System32\drivers\avipbb.sys
+ 2007-11-08 17:03:26 21,248 ----a-w c:\windows\System32\drivers\ssmdrv.sys
+ 2009-03-16 15:54:02 84,992 --sha-w c:\windows\System32\pawovuda.dll
- 2009-03-16 14:58:03 7,924 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
+ 2009-03-16 20:24:51 9,138 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
- 2009-03-16 14:58:03 83,840 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-16 20:24:51 84,774 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-16 14:57:55 56,576 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-16 20:13:25 57,980 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-16 15:53:59 79,872 --sha-w c:\windows\System32\zeberove.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0f8b900a-324f-4f48-a4b4-8f184ec5ad8c}]
c:\windows\system32\zutozube.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-969A-2AB983EE729B}]
2008-06-03 14:52 2012632 --a------ c:\progra~1\SKYROC~1\SKYROC~1.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-C39E-35F1D2A32EC8}]
2008-08-04 21:44 1947080 --a------ c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "c:\progra~1\MEGAUP~2\MEGAUP~1.DLL" [2008-08-04 1947080]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-C39E-35F1D2A32EC8}"= "c:\progra~1\MEGAUP~2\MEGAUP~1.DLL" [2008-08-04 1947080]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1232896]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-14 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-07 185896]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"snpstd"="c:\windows\vsnpstd.exe" [2005-10-11 339968]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"fae266ec"="c:\windows\system32\zeberove.dll" [2009-03-16 79872]
"CPMf9d15570"="c:\windows\system32\pawovuda.dll" [2009-03-16 84992]
"MSConfig"="c:\windows\system32\msconfig.exe" [2006-11-02 222208]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Win32load"="c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe" [2009-02-22 5632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\pawovuda.dll" [2009-03-16 84992]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\pawovuda.dll [2009-03-16 84992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\pawovuda.dll
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdss.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\xcommsvr.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\[u]0/uautocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 2008-06-12 13:28 266497 c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 2008-05-18 10:14 5799936 c:\program files\eMule\eMule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
--a------ 2007-02-19 15:00 571024 c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-406981787-4262907449-3248825866-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2AADE598-D30B-4020-84C1-D45D536EE837}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CBD24638-2A19-4B78-A91C-F72D8E223730}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{5FF44E8C-063A-4EE9-818A-A8DFEEC41855}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{B7A716A7-4ED8-4B2A-BEC0-DA8881B3E345}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{3EF6132F-255C-4919-8131-11E3E1ED3FDC}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{1A7E7381-C340-4191-AA62-2BF35DDEAD47}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B0220275-8A2C-4283-878B-F693E66D88AF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{AC409A63-E931-4E4C-A2CB-6AAA883E4B4B}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F802DFD6-676A-4343-B415-F203C112B618}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C32D9118-011F-4B92-ACDE-FF855B0CDA91}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{E5E79935-E3F3-4E17-BB9F-268BB3A0FAE2}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{2A4CF6DD-F756-4D72-9B87-B9355F7ACDA8}"= UDP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{0638A894-EDA4-42FE-AB6D-020A2EAB2966}"= TCP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{B380569C-6A99-4C0E-970C-A1D0A43DA58E}"= UDP:c:\windows\System32\wininit.exe:wininit
"{AA27C693-EFD5-49A9-832B-A62B5E5D97DE}"= TCP:c:\windows\System32\wininit.exe:wininit
"{16FA3A40-E187-4724-A1B4-834D8351429B}"= UDP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{AC91D579-113C-4C12-AED3-FCAA0EE04884}"= TCP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{D81775A1-B7A7-45EB-BDFA-D8D90F767CC9}"= UDP:c:\windows\explorer.exe:Explorer
"{54A4E806-6CB9-4282-AC40-366C983AB977}"= TCP:c:\windows\explorer.exe:Explorer
"{0EF61965-D101-4AE0-96FA-1DCE2A0A9F75}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1BA8EB8C-FBF3-4BD4-8DAD-0B697016189C}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3C1EFE2C-5A9B-4AC9-9D16-D66D63E7E114}"= UDP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{C35AEF5A-C597-4FD5-98AF-0599E0491925}"= TCP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{A0C07B34-FA4A-4AD8-B0CA-01DD7BB44DFB}"= UDP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{82BFF3FC-F03F-4A45-8108-4D4D7B5699B9}"= TCP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{759FE909-AFB0-4340-98C4-E2F7DC93CECB}"= UDP:c:\combofix\NirCmd.cfexe:NirCmd
"{47A635DC-82BC-4083-816D-7200503E58B0}"= TCP:c:\combofix\NirCmd.cfexe:NirCmd
"{0F329B87-0929-413B-A1EE-1838CFCA42E6}"= UDP:c:\windows\System32\igfxpers.exe:igfxpers
"{B84D3E4A-584F-4FE2-9570-5CCB75B11FF6}"= TCP:c:\windows\System32\igfxpers.exe:igfxpers
"{634DEC58-1B08-420F-9AA0-3F4C9BAD984A}"= UDP:c:\windows\System32\mobsync.exe:mobsync
"{E7CE97ED-BA85-4D4C-8216-78EA6F9B1473}"= TCP:c:\windows\System32\mobsync.exe:mobsync
"{1401CA5E-8649-4D53-BE6B-350BFD908D86}"= UDP:c:\windows\System32\igfxtray.exe:igfxtray
"{4816D01E-01C8-4728-8B4C-40327168C0C7}"= TCP:c:\windows\System32\igfxtray.exe:igfxtray
"{E4E9ABFA-7968-45CA-88BF-1526017058EF}"= UDP:c:\windows\ehome\ehtray.exe:ehtray
"{E03B7B00-B8B4-4CDA-82D1-BD1DA045A0A5}"= TCP:c:\windows\ehome\ehtray.exe:ehtray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\nscagent.exe"= c:\windows\system32\config\systemprofile\AppData\Roaming\nscagent.exe:*:Enabled:Win32load
R3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCAMp50.sys [2006-11-28 28224]
R3 TpChoice;Touch Pad Detection Filter driver; [x]
R4 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
S2 Tcpipsrv;Tcp ipx Service;c:\windows\$ntunistalls\svchost.exe [2009-03-03 197120]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - AFD
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - Beep
*Deregistered* - BlueletAudio
*Deregistered* - BlueletSCOAudio
*Deregistered* - bowser
*Deregistered* - BT
*Deregistered* - BTHidEnum
*Deregistered* - BTHidMgr
*Deregistered* - cdfs
*Deregistered* - circlass
*Deregistered* - CLFS
*Deregistered* - Compbatt
*Deregistered* - crcdisk
*Deregistered* - DfsC
*Deregistered* - DXGKrnl
*Deregistered* - fastfat
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - HTTP
*Deregistered* - iScsiPrt
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - Modem
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - msahci
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NativeWifiP
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - rspndr
*Deregistered* - secdrv
*Deregistered* - Serenum
*Deregistered* - Smb
*Deregistered* - spldr
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - ssmdrv
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - TermDD
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - umbus
*Deregistered* - VcommMgr
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8956d3b-eee8-11dd-904d-001167714e6e}]
\shell\AutoRun\command - G:\AMCD.EXE
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{7c7e23ae-ec55-4c54-8920-947abe1c08cf} - c:\windows\system32\pjczbz.dll
MSConfigStartUp-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr
FF - ProfilePath - c:\users\Angélique\AppData\Roaming\Mozilla\Firefox\Profiles\19mwtt7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 21:23:25
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(820)
c:\windows\system32\pawovuda.dll
- - - - - - - > 'lsass.exe'(780)
c:\windows\system32\pawovuda.dll
- - - - - - - > 'Explorer.exe'(5372)
c:\windows\system32\pawovuda.dll
c:\windows\system32\zeberove.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\rundll32.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\conime.exe
c:\windows\System32\conime.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-17 8:32:03 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-17 07:31:56
ComboFix2.txt 2009-03-16 15:08:51
Avant-CF: 4,265,451,520 octets libres
Après-CF: 3,597,389,824 octets libres
529 --- E O F --- 2009-02-20 10:56:48
bonjour Laura ,
il est encore infectè tu crois?
oui il l est ... mais moins
j ai besoin que tu refasse ceci stp :
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt
il est encore infectè tu crois?
oui il l est ... mais moins
j ai besoin que tu refasse ceci stp :
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt
re laura,
quand tu m auras envoyé le rapport log.txt, fais ceci :
telecharge ce fichier :
http://sd-1.archive-host.com/membres/up/116615172019703188/Laura.bat
execute le en admnistrateur et post le rapport Laura.txt
je dois sortir faire une course je te preparerai la suite une fois avoir lu les rapport
quand tu m auras envoyé le rapport log.txt, fais ceci :
telecharge ce fichier :
http://sd-1.archive-host.com/membres/up/116615172019703188/Laura.bat
execute le en admnistrateur et post le rapport Laura.txt
je dois sortir faire une course je te preparerai la suite une fois avoir lu les rapport
pour l'autre rapport ça me marque sur une fenetre noir " fichier introuvable"
et le bloc note s"ouvre mais c'est vierge
et le bloc note s"ouvre mais c'est vierge
Copie le texte ci-dessous :
File::
C:\Windows\system32\msrstart.exe
c:\windows\MegaManager.INI
c:\windows\_MSRSTRT.EXE
c:\windows\System32\coh.cache
c:\windows\System32\MSWINSCK.OCX
c:\windows\System32\zeberove.dll
c:\windows\System32\pawovuda.dll
c:\windows\system32\zutozube.dll
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\$ntunistalls\svchost.exe
Folder::
c:\windows\System32\3361
C:\ToolBar SD
c:\program files\Trend Micro
c:\program files\Conduit
c:\users\Angélique\AppData\Roaming\MegauploadToolbar
c:\programdata\Megaupload
c:\program files\MegauploadToolbar
c:\progra~1\MEGAUP~2
Registry::
[-HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[-HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fae266ec"=-
"CPMf9d15570"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Win32load"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
"LoadAppInit_DLLs"=0
Driver::
Tcpipsrv
DirLook::
c:\users\Angélique\AppData\Roaming\nidle
c:\windows\System32\MR
c:\windows\System32\aNI02
c:\temp\atmp8
c:\windows\$ntunistalls
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt
S'il n'y a pas de rédémarrage, poste quand même le rapport.
File::
C:\Windows\system32\msrstart.exe
c:\windows\MegaManager.INI
c:\windows\_MSRSTRT.EXE
c:\windows\System32\coh.cache
c:\windows\System32\MSWINSCK.OCX
c:\windows\System32\zeberove.dll
c:\windows\System32\pawovuda.dll
c:\windows\system32\zutozube.dll
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\$ntunistalls\svchost.exe
Folder::
c:\windows\System32\3361
C:\ToolBar SD
c:\program files\Trend Micro
c:\program files\Conduit
c:\users\Angélique\AppData\Roaming\MegauploadToolbar
c:\programdata\Megaupload
c:\program files\MegauploadToolbar
c:\progra~1\MEGAUP~2
Registry::
[-HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c39e-35f1d2a32ec8}]
[-HKEY_CLASSES_ROOT\megauploadtoolbar.MEGAUPLOADTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fae266ec"=-
"CPMf9d15570"=-
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Win32load"=-
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
"LoadAppInit_DLLs"=0
Driver::
Tcpipsrv
DirLook::
c:\users\Angélique\AppData\Roaming\nidle
c:\windows\System32\MR
c:\windows\System32\aNI02
c:\temp\atmp8
c:\windows\$ntunistalls
Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt
S'il n'y a pas de rédémarrage, poste quand même le rapport.
ComboFix 09-03-15.01 - Angélique 2009-03-17 13:29:57.3 - NTFSx86
Lancé depuis: c:\users\Angélique\Downloads\ComboFix.exe
Commutateurs utilisés :: c:\users\Angélique\Desktop\CFScript.txt
FILE ::
c:\windows\$ntunistalls\svchost.exe
c:\windows\_MSRSTRT.EXE
c:\windows\MegaManager.INI
c:\windows\System32\coh.cache
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\system32\msrstart.exe
c:\windows\System32\MSWINSCK.OCX
c:\windows\System32\pawovuda.dll
c:\windows\System32\zeberove.dll
c:\windows\system32\zutozube.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\MEGAUP~2
c:\progra~1\MEGAUP~2\megauploadtoolbar.dll
c:\progra~1\MEGAUP~2\tbuninstall.exe
c:\progra~1\MEGAUP~2\toolbar.ini
c:\progra~1\MEGAUP~2\uninstall.exe
c:\program files\Conduit
c:\program files\Conduit\Community Alerts\Alert.dll
c:\program files\MegauploadToolbar\megauploadtoolbar.dll
c:\program files\MegauploadToolbar\tbuninstall.exe
c:\program files\MegauploadToolbar\toolbar.ini
c:\program files\MegauploadToolbar\uninstall.exe
c:\program files\Trend Micro
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-156
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-511
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-594
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-618
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-806
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-822
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-935
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-193540-721
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-193540-941
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-193617-489
c:\program files\Trend Micro\HijackThis\HijackThis.exe
c:\program files\Trend Micro\HijackThis\hijackthis.log
c:\programdata\Megaupload
c:\programdata\Megaupload\Megauper.exe
C:\ToolBar SD
c:\toolbar sd\AutrInf.cmd
c:\toolbar sd\Back.cmd
c:\toolbar sd\Backup-TB\Reg\HKCU_Run.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_BHO.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_Classes.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_Run.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_ToolBar.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_Uninstall.reg
c:\toolbar sd\Changelog ToolBar.txt
c:\toolbar sd\DemP.cmd
c:\toolbar sd\DirectFix.cmd
c:\toolbar sd\Discl_en.vbs
c:\toolbar sd\Discl_fr.vbs
c:\toolbar sd\Discl_sp.vbs
c:\toolbar sd\Doss.tbsd
c:\toolbar sd\Fich.cmd
c:\toolbar sd\FixExt.cmd
c:\toolbar sd\iNv.exe
c:\toolbar sd\Kill.cmd
c:\toolbar sd\Langues.cmd
c:\toolbar sd\Orph.egd
c:\toolbar sd\OsV.exe
c:\toolbar sd\paths.bat
c:\toolbar sd\pv.exe
c:\toolbar sd\Rech.cmd
c:\toolbar sd\RegP2.txt
c:\toolbar sd\RegP3.txt
c:\toolbar sd\RegP4.txt
c:\toolbar sd\RegP5.txt
c:\toolbar sd\RegPCU.txt
c:\toolbar sd\RegPLM.txt
c:\toolbar sd\RegTBSD.reg
c:\toolbar sd\RKit.lsd
c:\toolbar sd\RoGUeS.lsd
c:\toolbar sd\sed.exe
c:\toolbar sd\setpath.exe
c:\toolbar sd\ToolBarSD.cmd
c:\toolbar sd\ToolBarSD.ico
c:\users\Angélique\AppData\Roaming\MegauploadToolbar
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\__slider.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\bottom.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\bottom_left.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\bottom_right.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\connect.ico
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\dictionary2.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\dnload.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\dnloado.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\email_b.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\ErrorPageTemplate.css
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\ErrorPageTemplate_search.css
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\extend.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\extendi.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\extendo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred0.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred0_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred1.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred1_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred2.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred2_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred3.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred3_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred4.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred4_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\happyhour.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\happyhouri.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\happyhouro.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\help.gif
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\history.cfg
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\info.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\left.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\links.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\logo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\logoo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\marrow.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\megauploadtoolbartb0501.cfg
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\mv.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\powered_by_yahoo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\right.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\RotCats.txt
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search.gif
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search_fr.gif
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search_mag.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search_main.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\searcho.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\settings.cfg
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\slider.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\tab_icon.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\tablib.js
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\tabwelcome.html
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\top.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\top_left.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\top_right.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\upload.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\uploado.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\VidCats.txt
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\yahoo_search.gif
c:\windows\$ntunistalls\svchost.exe
c:\windows\_MSRSTRT.EXE
c:\windows\MegaManager.INI
c:\windows\System32\3361
c:\windows\System32\3361\mlog
c:\windows\System32\coh.cache
c:\windows\system32\drivers\senekaingdotpq.sys
c:\windows\system32\evorebez.ini
c:\windows\system32\msrstart.exe
c:\windows\System32\MSWINSCK.OCX
c:\windows\System32\pawovuda.dll
c:\windows\system32\senekaabqecjsi.dll
c:\windows\system32\senekafbqudupu.dat
c:\windows\system32\senekaicxbxjuh.dat
c:\windows\system32\senekaxsbvmfmj.dll
c:\windows\system32\senekaxtftrbps.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
-------\Service_SENEKA
-------\Service_Tcpipsrv
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-17 au 2009-03-17 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 13:00 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-17 13:00 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-16 18:49 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-16 18:40 --------- d-----w c:\programdata\Avira
2009-03-16 18:40 --------- d-----w c:\program files\Avira
2009-03-14 18:38 --------- d-----w c:\program files\Bonjour
2009-03-14 11:51 --------- d-----w c:\program files\Error Repair Professional
2009-03-14 11:49 --------- d-----w c:\program files\Combined Community Codec Pack
2009-03-14 10:17 --------- d-----w c:\users\Angélique\AppData\Roaming\Malwarebytes
2009-03-14 09:15 --------- d-----w c:\program files\Lavalys
2009-03-13 17:54 --------- d-----w c:\users\sophie\AppData\Roaming\Toshiba
2009-03-13 16:39 --------- d-----w c:\program files\CCleaner
2009-03-13 16:38 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-13 16:37 --------- d-----w c:\users\sophie\AppData\Roaming\Malwarebytes
2009-03-13 16:37 --------- d-----w c:\programdata\Malwarebytes
2009-03-13 16:37 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-06 15:58 --------- d-----w c:\program files\Alwil Software
2009-03-05 22:01 --------- d-----w c:\users\Angélique\AppData\Roaming\nidle
2009-03-05 21:57 --------- d-----w c:\program files\DivX
2009-03-05 21:46 --------- d-----w c:\program files\PCFriendly
2009-03-05 21:36 --------- d-----w c:\program files\Hotspot_Shield
2009-03-05 20:23 84,992 --sha-w c:\windows\System32\fedalajo.dll
2009-03-04 11:44 84,992 --sha-w c:\windows\System32\mowogova.dll
2009-03-03 18:01 84,992 --sha-w c:\windows\System32\hopipuwe.dll
2009-02-28 22:00 84,992 --sha-w c:\windows\System32\jajulaze.dll
2009-02-28 18:37 --------- d-----w c:\users\Angélique\AppData\Roaming\LimeWire
2009-02-21 15:03 --------- d-----w c:\users\sophie\AppData\Roaming\LimeWire
2009-02-15 23:14 --------- d-----w c:\program files\skyrocktbar
2009-02-15 17:43 --------- d-----w c:\program files\LimeWire
2009-02-15 16:50 --------- d-----w c:\users\Angélique\AppData\Roaming\AVS4YOU
2009-02-15 16:50 --------- d-----w c:\program files\AVS4YOU
2009-02-15 16:37 --------- d-----w c:\programdata\EmailNotifier
2009-01-23 18:27 --------- d-----w c:\users\Angélique\AppData\Roaming\DivX
2009-01-21 15:52 --------- d-----w c:\users\sophie\AppData\Roaming\DivX
2009-01-17 17:45 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-15 04:16 826,368 ----a-w c:\windows\System32\wininet.dll
2009-01-15 04:16 56,320 ----a-w c:\windows\System32\iesetup.dll
2009-01-15 04:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-15 04:15 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2008-12-12 02:16 174 --sha-w c:\program files\desktop.ini
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\temp\atmp8 ----
2009-03-05 23:00 1858 --a------ c:\temp\atmp8\ead.log
---- Directory of c:\users\Angélique\AppData\Roaming\nidle ----
2009-03-05 23:00 56832 --a------ c:\users\Angélique\AppData\Roaming\nidle\nidle.exe
---- Directory of c:\windows\$ntunistalls ----
2009-03-03 19:01 197120 ---hs---- c:\windows\$ntunistalls\svchost.exe
---- Directory of c:\windows\System32\aNI02 ----
2009-02-27 04:25 32768 --a------ c:\windows\System32\aNI02\aNI022328.exe
---- Directory of c:\windows\System32\MR ----
((((((((((((((((((((((((((((( SnapShot_2009-03-17_ 8.31.01.88 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-16 20:07:50 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-03-17 12:34:00 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-17 12:35:05 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-17 12:35:05 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-17 12:45:53 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-17 12:45:53 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-17 12:45:48 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-17 12:45:48 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-17 07:27:45 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-17 12:35:04 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-17 07:27:45 393,216 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 12:35:04 393,216 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-17 07:27:45 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-17 12:35:04 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-13 17:43:41 6,291,456 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-03-17 11:04:35 6,291,456 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-03-16 20:24:51 9,138 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
+ 2009-03-17 12:28:44 9,162 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
- 2009-03-16 20:24:51 84,774 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-17 12:28:44 84,910 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-16 20:13:25 57,980 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-17 12:28:39 58,284 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-02-12 02:01:00 158,311,812 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-03-17 07:57:01 159,075,655 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0f8b900a-324f-4f48-a4b4-8f184ec5ad8c}]
c:\windows\system32\zutozube.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-969A-2AB983EE729B}]
2008-06-03 14:52 2012632 --a------ c:\progra~1\SKYROC~1\SKYROC~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1232896]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-14 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-07 185896]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"snpstd"="c:\windows\vsnpstd.exe" [2005-10-11 339968]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdss.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\xcommsvr.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\[u]0/uautocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 2008-06-12 13:28 266497 c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 2008-05-18 10:14 5799936 c:\program files\eMule\eMule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
--a------ 2007-02-19 15:00 571024 c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-406981787-4262907449-3248825866-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2AADE598-D30B-4020-84C1-D45D536EE837}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CBD24638-2A19-4B78-A91C-F72D8E223730}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{5FF44E8C-063A-4EE9-818A-A8DFEEC41855}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{B7A716A7-4ED8-4B2A-BEC0-DA8881B3E345}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{3EF6132F-255C-4919-8131-11E3E1ED3FDC}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{1A7E7381-C340-4191-AA62-2BF35DDEAD47}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B0220275-8A2C-4283-878B-F693E66D88AF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{AC409A63-E931-4E4C-A2CB-6AAA883E4B4B}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F802DFD6-676A-4343-B415-F203C112B618}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C32D9118-011F-4B92-ACDE-FF855B0CDA91}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{E5E79935-E3F3-4E17-BB9F-268BB3A0FAE2}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{2A4CF6DD-F756-4D72-9B87-B9355F7ACDA8}"= UDP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{0638A894-EDA4-42FE-AB6D-020A2EAB2966}"= TCP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{B380569C-6A99-4C0E-970C-A1D0A43DA58E}"= UDP:c:\windows\System32\wininit.exe:wininit
"{AA27C693-EFD5-49A9-832B-A62B5E5D97DE}"= TCP:c:\windows\System32\wininit.exe:wininit
"{16FA3A40-E187-4724-A1B4-834D8351429B}"= UDP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{AC91D579-113C-4C12-AED3-FCAA0EE04884}"= TCP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{D81775A1-B7A7-45EB-BDFA-D8D90F767CC9}"= UDP:c:\windows\explorer.exe:Explorer
"{54A4E806-6CB9-4282-AC40-366C983AB977}"= TCP:c:\windows\explorer.exe:Explorer
"{0EF61965-D101-4AE0-96FA-1DCE2A0A9F75}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1BA8EB8C-FBF3-4BD4-8DAD-0B697016189C}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3C1EFE2C-5A9B-4AC9-9D16-D66D63E7E114}"= UDP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{C35AEF5A-C597-4FD5-98AF-0599E0491925}"= TCP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{A0C07B34-FA4A-4AD8-B0CA-01DD7BB44DFB}"= UDP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{82BFF3FC-F03F-4A45-8108-4D4D7B5699B9}"= TCP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{759FE909-AFB0-4340-98C4-E2F7DC93CECB}"= UDP:c:\combofix\NirCmd.cfexe:NirCmd
"{47A635DC-82BC-4083-816D-7200503E58B0}"= TCP:c:\combofix\NirCmd.cfexe:NirCmd
"{0F329B87-0929-413B-A1EE-1838CFCA42E6}"= UDP:c:\windows\System32\igfxpers.exe:igfxpers
"{B84D3E4A-584F-4FE2-9570-5CCB75B11FF6}"= TCP:c:\windows\System32\igfxpers.exe:igfxpers
"{634DEC58-1B08-420F-9AA0-3F4C9BAD984A}"= UDP:c:\windows\System32\mobsync.exe:mobsync
"{E7CE97ED-BA85-4D4C-8216-78EA6F9B1473}"= TCP:c:\windows\System32\mobsync.exe:mobsync
"{1401CA5E-8649-4D53-BE6B-350BFD908D86}"= UDP:c:\windows\System32\igfxtray.exe:igfxtray
"{4816D01E-01C8-4728-8B4C-40327168C0C7}"= TCP:c:\windows\System32\igfxtray.exe:igfxtray
"{E4E9ABFA-7968-45CA-88BF-1526017058EF}"= UDP:c:\windows\ehome\ehtray.exe:ehtray
"{E03B7B00-B8B4-4CDA-82D1-BD1DA045A0A5}"= TCP:c:\windows\ehome\ehtray.exe:ehtray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\nscagent.exe"= c:\windows\system32\config\systemprofile\AppData\Roaming\nscagent.exe:*:Enabled:Win32load
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-01-19 28224]
S4 CplIR;Embedded IR Driver;c:\windows\System32\drivers\CplIR.sys [2007-03-06 14848]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8956d3b-eee8-11dd-904d-001167714e6e}]
\shell\AutoRun\command - G:\AMCD.EXE
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
Toolbar-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
HKLM-Run-fae266ec - c:\windows\system32\zeberove.dll
HKLM-Run-CPMf9d15570 - c:\windows\system32\pawovuda.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr
FF - ProfilePath - c:\users\Angélique\AppData\Roaming\Mozilla\Firefox\Profiles\19mwtt7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-17 14:00:20
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-17 14:02:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-17 13:02:03
ComboFix2.txt 2009-03-17 07:32:06
ComboFix3.txt 2009-03-16 15:08:51
Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Après-CF: 3,640,422,400 octets libres
458 --- E O F --- 2009-02-20 10:56:48
Lancé depuis: c:\users\Angélique\Downloads\ComboFix.exe
Commutateurs utilisés :: c:\users\Angélique\Desktop\CFScript.txt
FILE ::
c:\windows\$ntunistalls\svchost.exe
c:\windows\_MSRSTRT.EXE
c:\windows\MegaManager.INI
c:\windows\System32\coh.cache
c:\windows\system32\config\systemprofile\AppData\Roaming\syssl.exe
c:\windows\system32\msrstart.exe
c:\windows\System32\MSWINSCK.OCX
c:\windows\System32\pawovuda.dll
c:\windows\System32\zeberove.dll
c:\windows\system32\zutozube.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\MEGAUP~2
c:\progra~1\MEGAUP~2\megauploadtoolbar.dll
c:\progra~1\MEGAUP~2\tbuninstall.exe
c:\progra~1\MEGAUP~2\toolbar.ini
c:\progra~1\MEGAUP~2\uninstall.exe
c:\program files\Conduit
c:\program files\Conduit\Community Alerts\Alert.dll
c:\program files\MegauploadToolbar\megauploadtoolbar.dll
c:\program files\MegauploadToolbar\tbuninstall.exe
c:\program files\MegauploadToolbar\toolbar.ini
c:\program files\MegauploadToolbar\uninstall.exe
c:\program files\Trend Micro
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-156
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-511
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-594
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-618
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-806
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-822
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-192034-935
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-193540-721
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-193540-941
c:\program files\Trend Micro\HijackThis\backups\backup-20090316-193617-489
c:\program files\Trend Micro\HijackThis\HijackThis.exe
c:\program files\Trend Micro\HijackThis\hijackthis.log
c:\programdata\Megaupload
c:\programdata\Megaupload\Megauper.exe
C:\ToolBar SD
c:\toolbar sd\AutrInf.cmd
c:\toolbar sd\Back.cmd
c:\toolbar sd\Backup-TB\Reg\HKCU_Run.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_BHO.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_Classes.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_Run.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_ToolBar.reg
c:\toolbar sd\Backup-TB\Reg\HKLM_Uninstall.reg
c:\toolbar sd\Changelog ToolBar.txt
c:\toolbar sd\DemP.cmd
c:\toolbar sd\DirectFix.cmd
c:\toolbar sd\Discl_en.vbs
c:\toolbar sd\Discl_fr.vbs
c:\toolbar sd\Discl_sp.vbs
c:\toolbar sd\Doss.tbsd
c:\toolbar sd\Fich.cmd
c:\toolbar sd\FixExt.cmd
c:\toolbar sd\iNv.exe
c:\toolbar sd\Kill.cmd
c:\toolbar sd\Langues.cmd
c:\toolbar sd\Orph.egd
c:\toolbar sd\OsV.exe
c:\toolbar sd\paths.bat
c:\toolbar sd\pv.exe
c:\toolbar sd\Rech.cmd
c:\toolbar sd\RegP2.txt
c:\toolbar sd\RegP3.txt
c:\toolbar sd\RegP4.txt
c:\toolbar sd\RegP5.txt
c:\toolbar sd\RegPCU.txt
c:\toolbar sd\RegPLM.txt
c:\toolbar sd\RegTBSD.reg
c:\toolbar sd\RKit.lsd
c:\toolbar sd\RoGUeS.lsd
c:\toolbar sd\sed.exe
c:\toolbar sd\setpath.exe
c:\toolbar sd\ToolBarSD.cmd
c:\toolbar sd\ToolBarSD.ico
c:\users\Angélique\AppData\Roaming\MegauploadToolbar
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\__slider.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\bottom.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\bottom_left.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\bottom_right.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\connect.ico
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\dictionary2.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\dnload.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\dnloado.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\email_b.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\ErrorPageTemplate.css
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\ErrorPageTemplate_search.css
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\extend.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\extendi.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\extendo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred0.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred0_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred1.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred1_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred2.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred2_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred3.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred3_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred4.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred4_5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\graphred5.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\happyhour.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\happyhouri.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\happyhouro.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\help.gif
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\history.cfg
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\info.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\left.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\links.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\logo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\logoo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\marrow.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\megauploadtoolbartb0501.cfg
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\mv.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\powered_by_yahoo.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\right.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\RotCats.txt
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search.gif
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search_fr.gif
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search_mag.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\search_main.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\searcho.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\settings.cfg
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\slider.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\tab_icon.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\tablib.js
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\tabwelcome.html
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\top.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\top_left.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\top_right.png
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\upload.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\uploado.bmp
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\VidCats.txt
c:\users\Angélique\AppData\Roaming\MegauploadToolbar\yahoo_search.gif
c:\windows\$ntunistalls\svchost.exe
c:\windows\_MSRSTRT.EXE
c:\windows\MegaManager.INI
c:\windows\System32\3361
c:\windows\System32\3361\mlog
c:\windows\System32\coh.cache
c:\windows\system32\drivers\senekaingdotpq.sys
c:\windows\system32\evorebez.ini
c:\windows\system32\msrstart.exe
c:\windows\System32\MSWINSCK.OCX
c:\windows\System32\pawovuda.dll
c:\windows\system32\senekaabqecjsi.dll
c:\windows\system32\senekafbqudupu.dat
c:\windows\system32\senekaicxbxjuh.dat
c:\windows\system32\senekaxsbvmfmj.dll
c:\windows\system32\senekaxtftrbps.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
-------\Service_SENEKA
-------\Service_Tcpipsrv
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-17 au 2009-03-17 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 13:00 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-17 13:00 3,670,016 --sha-w c:\users\Angélique\ntuser.dat
2009-03-16 18:49 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-16 18:40 --------- d-----w c:\programdata\Avira
2009-03-16 18:40 --------- d-----w c:\program files\Avira
2009-03-14 18:38 --------- d-----w c:\program files\Bonjour
2009-03-14 11:51 --------- d-----w c:\program files\Error Repair Professional
2009-03-14 11:49 --------- d-----w c:\program files\Combined Community Codec Pack
2009-03-14 10:17 --------- d-----w c:\users\Angélique\AppData\Roaming\Malwarebytes
2009-03-14 09:15 --------- d-----w c:\program files\Lavalys
2009-03-13 17:54 --------- d-----w c:\users\sophie\AppData\Roaming\Toshiba
2009-03-13 16:39 --------- d-----w c:\program files\CCleaner
2009-03-13 16:38 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-13 16:37 --------- d-----w c:\users\sophie\AppData\Roaming\Malwarebytes
2009-03-13 16:37 --------- d-----w c:\programdata\Malwarebytes
2009-03-13 16:37 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-06 15:58 --------- d-----w c:\program files\Alwil Software
2009-03-05 22:01 --------- d-----w c:\users\Angélique\AppData\Roaming\nidle
2009-03-05 21:57 --------- d-----w c:\program files\DivX
2009-03-05 21:46 --------- d-----w c:\program files\PCFriendly
2009-03-05 21:36 --------- d-----w c:\program files\Hotspot_Shield
2009-03-05 20:23 84,992 --sha-w c:\windows\System32\fedalajo.dll
2009-03-04 11:44 84,992 --sha-w c:\windows\System32\mowogova.dll
2009-03-03 18:01 84,992 --sha-w c:\windows\System32\hopipuwe.dll
2009-02-28 22:00 84,992 --sha-w c:\windows\System32\jajulaze.dll
2009-02-28 18:37 --------- d-----w c:\users\Angélique\AppData\Roaming\LimeWire
2009-02-21 15:03 --------- d-----w c:\users\sophie\AppData\Roaming\LimeWire
2009-02-15 23:14 --------- d-----w c:\program files\skyrocktbar
2009-02-15 17:43 --------- d-----w c:\program files\LimeWire
2009-02-15 16:50 --------- d-----w c:\users\Angélique\AppData\Roaming\AVS4YOU
2009-02-15 16:50 --------- d-----w c:\program files\AVS4YOU
2009-02-15 16:37 --------- d-----w c:\programdata\EmailNotifier
2009-01-23 18:27 --------- d-----w c:\users\Angélique\AppData\Roaming\DivX
2009-01-21 15:52 --------- d-----w c:\users\sophie\AppData\Roaming\DivX
2009-01-17 17:45 --------- d-----w c:\program files\Common Files\PX Storage Engine
2009-01-15 04:16 826,368 ----a-w c:\windows\System32\wininet.dll
2009-01-15 04:16 56,320 ----a-w c:\windows\System32\iesetup.dll
2009-01-15 04:16 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-01-15 04:15 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2008-12-12 02:16 174 --sha-w c:\program files\desktop.ini
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\temp\atmp8 ----
2009-03-05 23:00 1858 --a------ c:\temp\atmp8\ead.log
---- Directory of c:\users\Angélique\AppData\Roaming\nidle ----
2009-03-05 23:00 56832 --a------ c:\users\Angélique\AppData\Roaming\nidle\nidle.exe
---- Directory of c:\windows\$ntunistalls ----
2009-03-03 19:01 197120 ---hs---- c:\windows\$ntunistalls\svchost.exe
---- Directory of c:\windows\System32\aNI02 ----
2009-02-27 04:25 32768 --a------ c:\windows\System32\aNI02\aNI022328.exe
---- Directory of c:\windows\System32\MR ----
((((((((((((((((((((((((((((( SnapShot_2009-03-17_ 8.31.01.88 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-16 20:07:50 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2009-03-17 12:34:00 140,608 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-17 12:35:05 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-03-16 20:22:13 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-17 12:35:05 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-17 12:45:53 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat
+ 2009-03-17 12:45:53 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-16 20:23:15 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-17 12:45:48 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2009-03-17 12:45:48 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-17 07:27:45 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-17 12:35:04 49,152 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-17 07:27:45 393,216 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-17 12:35:04 393,216 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-17 07:27:45 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-17 12:35:04 65,536 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-13 17:43:41 6,291,456 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-03-17 11:04:35 6,291,456 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-03-16 20:24:51 9,138 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
+ 2009-03-17 12:28:44 9,162 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-406981787-4262907449-3248825866-1001_UserData.bin
- 2009-03-16 20:24:51 84,774 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-17 12:28:44 84,910 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-16 20:13:25 57,980 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-17 12:28:39 58,284 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-02-12 02:01:00 158,311,812 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-03-17 07:57:01 159,075,655 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0f8b900a-324f-4f48-a4b4-8f184ec5ad8c}]
c:\windows\system32\zutozube.dll [BU]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-969A-2AB983EE729B}]
2008-06-03 14:52 2012632 --a------ c:\progra~1\SKYROC~1\SKYROC~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A057A204-BACC-4D26-969A-2AB983EE729B}"= "c:\progra~1\SKYROC~1\SKYROC~1.DLL" [2008-06-03 2012632]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-969a-2ab983ee729b}]
[HKEY_CLASSES_ROOT\skyrocktbar.SKYROCKTBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1232896]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-14 39408]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-07 185896]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"snpstd"="c:\windows\vsnpstd.exe" [2005-10-11 339968]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-20 129560]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-20 141848]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 174872]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-20 154136]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-03 c:\windows\RtHDVCpl.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashDisp.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashserv.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Antivirus-ashSimpl.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avesvc.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdmcon.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdnagent.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdss.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdswitch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\DefWatch.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\xcommsvr.exe]
"Debugger"=c:\windows\system32\alg.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\[u]0/uautocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
--a------ 2008-06-12 13:28 266497 c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 2008-05-18 10:14 5799936 c:\program files\eMule\eMule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toshiba Registration]
--a------ 2007-02-19 15:00 571024 c:\program files\TOSHIBA\Registration\ToshibaRegistration.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-406981787-4262907449-3248825866-1000]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2AADE598-D30B-4020-84C1-D45D536EE837}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CBD24638-2A19-4B78-A91C-F72D8E223730}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{5FF44E8C-063A-4EE9-818A-A8DFEEC41855}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{B7A716A7-4ED8-4B2A-BEC0-DA8881B3E345}"= UDP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{3EF6132F-255C-4919-8131-11E3E1ED3FDC}"= TCP:c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{1A7E7381-C340-4191-AA62-2BF35DDEAD47}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{B0220275-8A2C-4283-878B-F693E66D88AF}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{AC409A63-E931-4E4C-A2CB-6AAA883E4B4B}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F802DFD6-676A-4343-B415-F203C112B618}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C32D9118-011F-4B92-ACDE-FF855B0CDA91}"= UDP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{E5E79935-E3F3-4E17-BB9F-268BB3A0FAE2}"= TCP:c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:Veoh Web Player
"{2A4CF6DD-F756-4D72-9B87-B9355F7ACDA8}"= UDP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{0638A894-EDA4-42FE-AB6D-020A2EAB2966}"= TCP:c:\program files\Orange\Deskboard\Deskboard.exe:deskboard
"{B380569C-6A99-4C0E-970C-A1D0A43DA58E}"= UDP:c:\windows\System32\wininit.exe:wininit
"{AA27C693-EFD5-49A9-832B-A62B5E5D97DE}"= TCP:c:\windows\System32\wininit.exe:wininit
"{16FA3A40-E187-4724-A1B4-834D8351429B}"= UDP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{AC91D579-113C-4C12-AED3-FCAA0EE04884}"= TCP:c:\program files\Orange\Systray\SystrayApp.exe:SystrayApp
"{D81775A1-B7A7-45EB-BDFA-D8D90F767CC9}"= UDP:c:\windows\explorer.exe:Explorer
"{54A4E806-6CB9-4282-AC40-366C983AB977}"= TCP:c:\windows\explorer.exe:Explorer
"{0EF61965-D101-4AE0-96FA-1DCE2A0A9F75}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1BA8EB8C-FBF3-4BD4-8DAD-0B697016189C}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3C1EFE2C-5A9B-4AC9-9D16-D66D63E7E114}"= UDP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{C35AEF5A-C597-4FD5-98AF-0599E0491925}"= TCP:c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe:AlertModule
"{A0C07B34-FA4A-4AD8-B0CA-01DD7BB44DFB}"= UDP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{82BFF3FC-F03F-4A45-8108-4D4D7B5699B9}"= TCP:c:\windows\RtHDVCpl.exe:RtHDVCpl
"{759FE909-AFB0-4340-98C4-E2F7DC93CECB}"= UDP:c:\combofix\NirCmd.cfexe:NirCmd
"{47A635DC-82BC-4083-816D-7200503E58B0}"= TCP:c:\combofix\NirCmd.cfexe:NirCmd
"{0F329B87-0929-413B-A1EE-1838CFCA42E6}"= UDP:c:\windows\System32\igfxpers.exe:igfxpers
"{B84D3E4A-584F-4FE2-9570-5CCB75B11FF6}"= TCP:c:\windows\System32\igfxpers.exe:igfxpers
"{634DEC58-1B08-420F-9AA0-3F4C9BAD984A}"= UDP:c:\windows\System32\mobsync.exe:mobsync
"{E7CE97ED-BA85-4D4C-8216-78EA6F9B1473}"= TCP:c:\windows\System32\mobsync.exe:mobsync
"{1401CA5E-8649-4D53-BE6B-350BFD908D86}"= UDP:c:\windows\System32\igfxtray.exe:igfxtray
"{4816D01E-01C8-4728-8B4C-40327168C0C7}"= TCP:c:\windows\System32\igfxtray.exe:igfxtray
"{E4E9ABFA-7968-45CA-88BF-1526017058EF}"= UDP:c:\windows\ehome\ehtray.exe:ehtray
"{E03B7B00-B8B4-4CDA-82D1-BD1DA045A0A5}"= TCP:c:\windows\ehome\ehtray.exe:ehtray
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"= c:\program files\Orange\Connectivity\ConnectivityManager.exe:*:enabled:CSS
"c:\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\nscagent.exe"= c:\windows\system32\config\systemprofile\AppData\Roaming\nscagent.exe:*:Enabled:Win32load
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [2008-01-19 28224]
S4 CplIR;Embedded IR Driver;c:\windows\System32\drivers\CplIR.sys [2007-03-06 14848]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8956d3b-eee8-11dd-904d-001167714e6e}]
\shell\AutoRun\command - G:\AMCD.EXE
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
Toolbar-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - c:\progra~1\MEGAUP~2\MEGAUP~1.DLL
HKLM-Run-fae266ec - c:\windows\system32\zeberove.dll
HKLM-Run-CPMf9d15570 - c:\windows\system32\pawovuda.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr
FF - ProfilePath - c:\users\Angélique\AppData\Roaming\Mozilla\Firefox\Profiles\19mwtt7n.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-17 14:00:20
Windows 6.0.6000 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\progra~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\windows\System32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\System32\WUDFHost.exe
c:\windows\System32\conime.exe
c:\program files\Synaptics\SynTP\SynTPEnh.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
c:\windows\ehome\ehmsas.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-17 14:02:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-17 13:02:03
ComboFix2.txt 2009-03-17 07:32:06
ComboFix3.txt 2009-03-16 15:08:51
Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Après-CF: 3,640,422,400 octets libres
458 --- E O F --- 2009-02-20 10:56:48
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:04:57, on 17/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Orange\systray\systrayapp.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Angélique\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0f8b900a-324f-4f48-a4b4-8f184ec5ad8c} - C:\Windows\system32\zutozube.dll (file missing)
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [snpstd] C:\Windows\vsnpstd.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
Scan saved at 14:04:57, on 17/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Orange\systray\systrayapp.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Angélique\Downloads\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0f8b900a-324f-4f48-a4b4-8f184ec5ad8c} - C:\Windows\system32\zutozube.dll (file missing)
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Skyrock Toolbar - {A057A204-BACC-4D26-969A-2AB983EE729B} - C:\PROGRA~1\SKYROC~1\SKYROC~1.DLL
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [snpstd] C:\Windows\vsnpstd.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
;)
je sais pas ce que vous avez fais avec le pc ..
l' infection regresse mais elle a tendance a revenir , je commenence a y voir plus clair ;)
met malewarebytes a jours et lance un scan rapide , n oublie pas de "supprimer la selection" a la fin du scan et de poster le rapport bien sur ;)
courage Laura
je sais pas ce que vous avez fais avec le pc ..
l' infection regresse mais elle a tendance a revenir , je commenence a y voir plus clair ;)
met malewarebytes a jours et lance un scan rapide , n oublie pas de "supprimer la selection" a la fin du scan et de poster le rapport bien sur ;)
courage Laura