Win32/rootkit ODG
Résolu/Fermé13 réponses
Narco!4
Messages postés
2385
Date d'inscription
dimanche 25 janvier 2009
Statut
Contributeur
Dernière intervention
25 octobre 2012
467
30 juin 2009 à 20:36
30 juin 2009 à 20:36
Bonjour,
télécharge GenProc http://www.genproc.com/GenProc.exe
double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
télécharge GenProc http://www.genproc.com/GenProc.exe
double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
Voilà :
Rapport GenProc 2.598 [3] - 01/07/2009 à 1:11:41
@ Windows Vista Service Pack 1 - Mode normal
@ Internet Explorer (7.0.6001.18000) [Navigateur par défaut]
# Etape 1/ Télécharge :
- WORT http://pc-system.fr/ (dj QUIOU) sur le Bureau.
Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** Romain *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[3]" sur ton bureau).
# Etape 2/
Double-clique sur le fichier WORT.exe et sélectionne le Bureau à l'aide du bouton "Parcourir". Suis les instructions et double-clique sur le fichier Wareout Removal Tool.bat qui vient d'être créé sur le Bureau. Sélectionne l'option 1 et valide par entrée.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste, dans la même réponse :
- Le contenu du rapport WORT_report.txt situé dans C:\Wort ;
- Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;
- Un nouveau rapport GenProc ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
~~ Arguments de la procédure ~~
# Détections [3] GenProc 2.598 01/07/2009 à 1:11:44
WareOut:le 01/07/2009 à 1:11:48
[HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters\interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------
~~ Fin à 1:12:20 ~~
Rapport GenProc 2.598 [3] - 01/07/2009 à 1:11:41
@ Windows Vista Service Pack 1 - Mode normal
@ Internet Explorer (7.0.6001.18000) [Navigateur par défaut]
# Etape 1/ Télécharge :
- WORT http://pc-system.fr/ (dj QUIOU) sur le Bureau.
Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; Choisis ta session courante *** Romain *** (pour retrouver le rapport, clique sur le raccourci "Rapport GenProc[3]" sur ton bureau).
# Etape 2/
Double-clique sur le fichier WORT.exe et sélectionne le Bureau à l'aide du bouton "Parcourir". Suis les instructions et double-clique sur le fichier Wareout Removal Tool.bat qui vient d'être créé sur le Bureau. Sélectionne l'option 1 et valide par entrée.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste, dans la même réponse :
- Le contenu du rapport WORT_report.txt situé dans C:\Wort ;
- Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;
- Un nouveau rapport GenProc ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
~~ Arguments de la procédure ~~
# Détections [3] GenProc 2.598 01/07/2009 à 1:11:44
WareOut:le 01/07/2009 à 1:11:48
[HKEY_LOCAL_MACHINE\system\controlset001\services\tcpip\parameters\interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
----------------------------------------------------------------------
Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------
~~ Fin à 1:12:20 ~~
Narco!4
Messages postés
2385
Date d'inscription
dimanche 25 janvier 2009
Statut
Contributeur
Dernière intervention
25 octobre 2012
467
1 juil. 2009 à 01:15
1 juil. 2009 à 01:15
suit ces manips ;)
===== Rapport WareOut Removal Tool =====
version 3.2
analyse effectuée le 01/07/2009 à 13:17:15,44
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\AppData\Roaming\ ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\Bureau\ ~~~~
~~~~ Recherche de détournement de DNS ~~~~
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8348BA9-2476-4B56-8229-460498461837}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{D8348BA9-2476-4B56-8229-460498461837}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{D8348BA9-2476-4B56-8229-460498461837}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
~~~~ Recherche du Rootkit kd???.exe ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\AppData\Local\Temp\ ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\Start Menu\Programs\ ~~~~
~~~~ Nettoyage du registre ~~~~
~~~~ Tentative de réparation des entrées suivantes: ~~~~
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"
[HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]
~~~~ Vérification: ~~~~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
_________________________________
développé par http://pc-system.fr
_________________________________
Rapport GenProc 2.598 [4] - 01/07/2009 à 13:27:09
@ Windows Vista Service Pack 1 - Mode normal
@ Internet Explorer (7.0.6001.18000) [Navigateur par défaut]
~~ ECHEC DU TELECHARGEMENT DE MBR.EXE ~~
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
# Etape 1/ Télécharge :
ToolsCleaner! http://pc-system.fr/ (A.Rothstein & Dj QUIOU) sur ton Bureau.
# Etape 2/
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport C:\TCleaner.txt
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
# Etape 3/
Poste un rapport NanoScan https://www.micro-astuce.com/securite/NanoScan-Panda.php
~~~~ INFORMATION COMPLEMENTAIRE ~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:28:31, on 01/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\GenProc\outil\Romain_GenProc.exe
C:\Windows\system32\NOTEPAD.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service Google Update (gupdate1c9b0b335a8c7c6) (gupdate1c9b0b335a8c7c6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: SessionLauncher - Unknown owner - C:\Users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
version 3.2
analyse effectuée le 01/07/2009 à 13:17:15,44
Résultats de l'analyse :
========================
~~~~ Recherche d'infections dans C:\ ~~~~
~~~~ Recherche d'infections dans C:\Program Files\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~
~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\AppData\Roaming\ ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\Bureau\ ~~~~
~~~~ Recherche de détournement de DNS ~~~~
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8348BA9-2476-4B56-8229-460498461837}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{D8348BA9-2476-4B56-8229-460498461837}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{B1D253E1-0545-40A2-9B07-897D366BA524}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{D8348BA9-2476-4B56-8229-460498461837}]
NameServer REG_SZ 85.255.112.190,85.255.112.232
~~~~ Recherche du Rootkit kd???.exe ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\AppData\Local\Temp\ ~~~~
~~~~ Recherche d'infections dans C:\Users\Romain\Start Menu\Programs\ ~~~~
~~~~ Nettoyage du registre ~~~~
~~~~ Tentative de réparation des entrées suivantes: ~~~~
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"
[HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]
~~~~ Vérification: ~~~~
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System REG_SZ
_________________________________
développé par http://pc-system.fr
_________________________________
Rapport GenProc 2.598 [4] - 01/07/2009 à 13:27:09
@ Windows Vista Service Pack 1 - Mode normal
@ Internet Explorer (7.0.6001.18000) [Navigateur par défaut]
~~ ECHEC DU TELECHARGEMENT DE MBR.EXE ~~
GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :
# Etape 1/ Télécharge :
ToolsCleaner! http://pc-system.fr/ (A.Rothstein & Dj QUIOU) sur ton Bureau.
# Etape 2/
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport C:\TCleaner.txt
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
# Etape 3/
Poste un rapport NanoScan https://www.micro-astuce.com/securite/NanoScan-Panda.php
~~~~ INFORMATION COMPLEMENTAIRE ~~~~
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:28:31, on 01/07/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\cmd.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\GenProc\outil\Romain_GenProc.exe
C:\Windows\system32\NOTEPAD.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://fr.gdark.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.gdark.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Service Google Update (gupdate1c9b0b335a8c7c6) (gupdate1c9b0b335a8c7c6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
O23 - Service: SessionLauncher - Unknown owner - C:\Users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Narco!4
Messages postés
2385
Date d'inscription
dimanche 25 janvier 2009
Statut
Contributeur
Dernière intervention
25 octobre 2012
467
1 juil. 2009 à 13:39
1 juil. 2009 à 13:39
# Etape 1/ Télécharge :
ToolsCleaner! http://pc-system.fr/ (A.Rothstein & Dj QUIOU) sur ton Bureau.
# Etape 2/
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport C:\TCleaner.txt
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
# Etape 3/
Poste un rapport NanoScan https://www.micro-astuce.com/securite/NanoScan-Panda.php
ToolsCleaner! http://pc-system.fr/ (A.Rothstein & Dj QUIOU) sur ton Bureau.
# Etape 2/
- Double-clique sur ToolsCleaner2.exe pour le lancer.
- Clique sur Recherche et laisse le scan agir.
- Clique sur Suppression pour finaliser.
- Tu peux, si tu le souhaites, te servir des Options Facultatives.
- Clique sur Quitter pour obtenir le rapport C:\TCleaner.txt
- Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
# Etape 3/
Poste un rapport NanoScan https://www.micro-astuce.com/securite/NanoScan-Panda.php
destroyer67
Messages postés
7
Date d'inscription
lundi 11 août 2008
Statut
Membre
Dernière intervention
16 octobre 2009
1 juil. 2009 à 15:36
1 juil. 2009 à 15:36
ANALYSIS: 2009-07-01 15:21:55
PROTECTIONS: 1
MALWARE: 8
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Windows Defender 1.1.1505.0 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@xiti[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@ad.yieldmanager[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@weborama[1].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@smartadserver[2].txt
00818975 Trj/Nabload.DMH Virus/Trojan No 0 Yes No C:\Windows\System32\oobe\info\resources\startoffice.exe
01054371 W32/TDSS.BF.worm Virus/Worm No 0 Yes No C:\Windows\System32\gxvxcvmnrnunqeckdecybgsxwxciswphnmhxo.dll
01054371 W32/TDSS.BF.worm Virus/Worm Yes 1 No No globalroot\systemroot\system32\gxvxcvmnrnunqeckdecybgsxwxciswphnmhxo.dll
01055526 W32/TDSS.BF.worm Virus/Worm No 0 Yes No C:\Windows\System32\gxvxcvxrdsajpdphxvtxrdcxckwepcxugsbsx.dll
01055526 W32/TDSS.BF.worm Virus/Worm Yes 1 No No globalroot\systemroot\system32\gxvxcvxrdsajpdphxvtxrdcxckwepcxugsbsx.dll
05139431 Generic Worm Virus/Worm No 0 Yes No C:\Program Files\ESET\ESET Smart Security\nodlogin.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location �9�8���9
;===================================================================================================================================================================================
No C:\Windows\System32\drivers\gxvxcyrxbwtqxiqjqttppulmriskrwqymxnbb.sys �9�8���9
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description �9�8���9
;===================================================================================================================================================================================
;===================================================================================================================================================================================
PROTECTIONS: 1
MALWARE: 8
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Windows Defender 1.1.1505.0 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@xiti[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@ad.yieldmanager[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@weborama[1].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\Romain\AppData\Roaming\Microsoft\Windows\Cookies\romain@smartadserver[2].txt
00818975 Trj/Nabload.DMH Virus/Trojan No 0 Yes No C:\Windows\System32\oobe\info\resources\startoffice.exe
01054371 W32/TDSS.BF.worm Virus/Worm No 0 Yes No C:\Windows\System32\gxvxcvmnrnunqeckdecybgsxwxciswphnmhxo.dll
01054371 W32/TDSS.BF.worm Virus/Worm Yes 1 No No globalroot\systemroot\system32\gxvxcvmnrnunqeckdecybgsxwxciswphnmhxo.dll
01055526 W32/TDSS.BF.worm Virus/Worm No 0 Yes No C:\Windows\System32\gxvxcvxrdsajpdphxvtxrdcxckwepcxugsbsx.dll
01055526 W32/TDSS.BF.worm Virus/Worm Yes 1 No No globalroot\systemroot\system32\gxvxcvxrdsajpdphxvtxrdcxckwepcxugsbsx.dll
05139431 Generic Worm Virus/Worm No 0 Yes No C:\Program Files\ESET\ESET Smart Security\nodlogin.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location �9�8���9
;===================================================================================================================================================================================
No C:\Windows\System32\drivers\gxvxcyrxbwtqxiqjqttppulmriskrwqymxnbb.sys �9�8���9
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description �9�8���9
;===================================================================================================================================================================================
;===================================================================================================================================================================================
[ Rapport ToolsCleaner version 2.3.7 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\GenProc: trouvé !
C:\Rsit: trouvé !
C:\WORT: trouvé !
C:\GenProc\outil\hijackthis.log: trouvé !
C:\GenProc\Page\GenProc[*].html: trouvé !
C:\Program Files\Trend Micro\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\hijackthis.log: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\Users\Romain\Desktop\HijackThis.lnk: trouvé !
C:\Users\Romain\Desktop\HJTInstall.exe: trouvé !
C:\Users\Romain\Desktop\WareOut Removal Tool.bat: trouvé !
C:\Users\Romain\Desktop\Genproc - Raccourci.lnk: trouvé !
C:\Users\Romain\Desktop\WORT.exe: trouvé !
C:\Users\Romain\Desktop\WORT: trouvé !
C:\Users\Romain\Desktop\Nettoyage\HijackThis.lnk: trouvé !
---------------------------------
--> Suppression:
C:\Program Files\Trend Micro\HijackThis.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\Romain\Desktop\HijackThis.lnk: supprimé !
C:\Users\Romain\Desktop\HJTInstall.exe: supprimé !
C:\Users\Romain\Desktop\WareOut Removal Tool.bat: supprimé !
C:\Users\Romain\Desktop\Nettoyage\HijackThis.lnk: supprimé !
C:\GenProc\outil\hijackthis.log: supprimé !
C:\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\hijackthis.log: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\Romain\Desktop\Genproc - Raccourci.lnk: supprimé !
C:\Users\Romain\Desktop\WORT.exe: supprimé !
C:\GenProc: ERREUR DE SUPPRESSION !!
C:\Rsit: supprimé !
C:\WORT: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
C:\Users\Romain\Desktop\WORT: supprimé !
Fichiers temporaires nettoyés !
--> Recherche:
C:\GenProc: trouvé !
C:\Rsit: trouvé !
C:\WORT: trouvé !
C:\GenProc\outil\hijackthis.log: trouvé !
C:\GenProc\Page\GenProc[*].html: trouvé !
C:\Program Files\Trend Micro\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\hijackthis.log: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
C:\Users\Romain\Desktop\HijackThis.lnk: trouvé !
C:\Users\Romain\Desktop\HJTInstall.exe: trouvé !
C:\Users\Romain\Desktop\WareOut Removal Tool.bat: trouvé !
C:\Users\Romain\Desktop\Genproc - Raccourci.lnk: trouvé !
C:\Users\Romain\Desktop\WORT.exe: trouvé !
C:\Users\Romain\Desktop\WORT: trouvé !
C:\Users\Romain\Desktop\Nettoyage\HijackThis.lnk: trouvé !
---------------------------------
--> Suppression:
C:\Program Files\Trend Micro\HijackThis.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\Romain\Desktop\HijackThis.lnk: supprimé !
C:\Users\Romain\Desktop\HJTInstall.exe: supprimé !
C:\Users\Romain\Desktop\WareOut Removal Tool.bat: supprimé !
C:\Users\Romain\Desktop\Nettoyage\HijackThis.lnk: supprimé !
C:\GenProc\outil\hijackthis.log: supprimé !
C:\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\hijackthis.log: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\Romain\Desktop\Genproc - Raccourci.lnk: supprimé !
C:\Users\Romain\Desktop\WORT.exe: supprimé !
C:\GenProc: ERREUR DE SUPPRESSION !!
C:\Rsit: supprimé !
C:\WORT: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
C:\Users\Romain\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
C:\Users\Romain\Desktop\WORT: supprimé !
Fichiers temporaires nettoyés !
Narco!4
Messages postés
2385
Date d'inscription
dimanche 25 janvier 2009
Statut
Contributeur
Dernière intervention
25 octobre 2012
467
1 juil. 2009 à 17:42
1 juil. 2009 à 17:42
[*] Télécharge combofix (sUBs) http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton Bureau
[*] Double clique combofix.exe et suis les instructions.
[*] Installe la console de récupération si proposé et continue.
[*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
[*] Double clique combofix.exe et suis les instructions.
[*] Installe la console de récupération si proposé et continue.
[*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
destroyer67
Messages postés
7
Date d'inscription
lundi 11 août 2008
Statut
Membre
Dernière intervention
16 octobre 2009
1 juil. 2009 à 19:09
1 juil. 2009 à 19:09
Il me dit : combix a cessé de fonctionner .... comme quan dje veux lancer Hijackthis le même probleme ..
Je fais comment ?
Je fais comment ?
Narco!4
Messages postés
2385
Date d'inscription
dimanche 25 janvier 2009
Statut
Contributeur
Dernière intervention
25 octobre 2012
467
1 juil. 2009 à 19:27
1 juil. 2009 à 19:27
essaie en mode sans echec
destroyer67
Messages postés
7
Date d'inscription
lundi 11 août 2008
Statut
Membre
Dernière intervention
16 octobre 2009
2 juil. 2009 à 00:24
2 juil. 2009 à 00:24
ComboFix 09-07-01.01 - Romain 01/07/2009 19:50.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.936 [GMT 2:00]
Lancé depuis: c:\users\Romain\Desktop\ComboFix.exe
AV: avast! antivirus 4.7.1098 [VPS 090630-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: BitDefender AntiSpam *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\is-8M7H6.exe
c:\windows\system32\drivers\gxvxcyrxbwtqxiqjqttppulmriskrwqymxnbb.sys
c:\windows\system32\gxvxccount
c:\windows\system32\gxvxcvmnrnunqeckdecybgsxwxciswphnmhxo.dll
c:\windows\system32\gxvxcvxrdsajpdphxvtxrdcxckwepcxugsbsx.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
-------\Legacy_GXVXCSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-01 au 2009-07-01 ))))))))))))))))))))))))))))))))))))
.
2009-07-01 17:16 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-07-01 17:16 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-07-01 14:02 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2009-07-01 14:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-01 12:15 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-07-01 12:15 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-07-01 12:15 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-07-01 12:15 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-07-01 12:15 . 2009-02-05 20:06 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-07-01 12:14 . 2009-07-01 12:14 -------- d-----w- c:\program files\Alwil Software
2009-07-01 11:44 . 2008-06-19 15:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-07-01 11:44 . 2009-07-01 11:44 -------- d-----w- c:\program files\Panda Security
2009-06-30 23:02 . 2009-06-30 23:02 -------- d-----w- C:\UAC
2009-06-30 23:01 . 2009-07-01 11:41 -------- d-----w- C:\GenProc
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\programdata\NOS
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\program files\NOS
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\programdata\Emjysoft
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\users\Romain\AppData\Roaming\Emjysoft
2009-06-06 15:19 . 2009-06-18 23:08 -------- d-----w- c:\programdata\Electronic Arts
2009-06-06 15:17 . 2008-09-05 00:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-06 15:17 . 2009-06-06 15:17 10134 ----a-r- c:\users\Romain\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-06 15:17 . 2009-06-06 15:17 -------- d-----w- c:\program files\Microsoft WSE
2009-06-06 15:07 . 2009-06-06 15:18 -------- d-----w- c:\program files\Electronic Arts
2009-06-05 11:00 . 2009-06-05 11:02 7 ----a-w- c:\windows\sbacknt.bin
2009-06-05 10:59 . 2009-06-05 11:02 152904 ----a-w- c:\windows\system32\vghd.scr
2009-06-05 10:59 . 2009-06-05 11:06 -------- d-----w- c:\users\Romain\AppData\Roaming\vghd
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iPod
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iTunes
2009-06-03 22:12 . 2009-06-03 22:13 -------- d-----w- c:\program files\QuickTime
2009-06-03 22:04 . 2009-06-03 22:04 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 18:06 . 2007-11-02 10:02 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-01 18:05 . 2007-11-02 12:30 -------- d-----w- c:\programdata\Microsoft Help
2009-07-01 17:11 . 2008-10-19 17:12 -------- d-----w- c:\users\Romain\AppData\Roaming\uTorrent
2009-07-01 11:41 . 2008-10-07 16:31 -------- d-----w- c:\program files\Trend Micro
2009-06-30 15:39 . 2008-10-07 16:58 -------- d-----w- c:\users\Romain\AppData\Roaming\LimeWire
2009-06-27 11:59 . 2009-05-18 20:44 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-21 18:54 . 2007-11-02 10:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-20 21:33 . 2008-12-15 16:04 -------- d-----w- c:\program files\iPhone Tunnel Suite 2.7 BETA
2009-06-20 18:00 . 2008-12-06 12:58 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-19 08:08 . 2008-10-07 17:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-18 23:12 . 2008-10-07 17:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-18 09:01 . 2006-11-02 15:48 681712 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-18 09:01 . 2006-11-02 15:48 128882 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-16 15:28 . 2009-02-15 17:39 -------- d-----w- c:\users\Romain\AppData\Roaming\DiskAid
2009-06-10 15:44 . 2008-10-07 14:56 80846 ----a-w- c:\users\Romain\AppData\Roaming\nvModes.dat
2009-06-08 18:56 . 2009-01-30 21:07 -------- d-----w- c:\program files\MSN Messenger
2009-06-08 18:42 . 2008-10-08 15:54 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-06 18:57 . 2008-11-11 17:54 -------- d-----w- c:\users\Romain\AppData\Roaming\Microgaming
2009-06-06 14:44 . 2009-03-12 18:21 -------- d-----w- c:\program files\Yahoo!
2009-06-06 12:06 . 2009-01-12 16:33 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE760.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75F.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75E.tmp
2009-06-03 22:20 . 2008-10-13 18:43 -------- d-----w- c:\programdata\Apple
2009-06-03 22:16 . 2008-10-13 18:43 -------- d-----w- c:\program files\Common Files\Apple
2009-06-03 17:04 . 2009-02-02 22:00 -------- d-----w- c:\program files\LimeWire
2009-05-29 23:22 . 2009-03-31 15:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-29 18:00 . 2008-10-09 18:17 3371383 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-29 11:36 . 2009-05-29 11:36 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-29 11:36 . 2009-05-29 11:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-26 11:20 . 2008-10-07 16:53 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2008-10-07 16:53 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-18 20:56 . 2007-11-02 12:41 -------- d-----w- c:\program files\Java
2009-05-17 17:20 . 2007-11-02 09:56 -------- d-----w- c:\program files\Google
2009-05-16 21:59 . 2008-10-07 14:56 -------- d-----w- c:\users\Romain\AppData\Roaming\Sony Corporation
2009-05-16 21:59 . 2007-11-02 12:36 -------- d-----w- c:\program files\Sony
2009-05-14 18:22 . 2008-11-26 22:10 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-05-13 18:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-06 19:31 . 2008-10-07 14:56 160480 ----a-w- c:\users\Romain\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-05 19:25 . 2008-10-07 21:29 -------- d-----w- c:\program files\Microsoft Works
2009-05-04 15:29 . 2009-04-15 17:36 -------- d-----w- c:\users\Romain\AppData\Roaming\U3
2009-04-24 16:05 . 2009-07-01 14:01 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-07-01 14:01 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-07-01 14:01 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-02-13 19:30 . 2009-02-13 19:30 23 --sha-w- c:\windows\System32\edacded0_x.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" /Minimized
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe"
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7DA4246B-1404-480D-92B6-E51E876D76F2}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F26427AA-9D7D-4191-AAA9-12266E99B7D1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BDE2623B-1711-4FBF-B28B-45FF09E99526}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{905D9AE4-3175-47D5-ACDF-DC55AC39E9A7}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{6BD22369-8512-4E12-AFA7-AADA2856B05B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{4D448602-C5DE-4E34-BCB2-0903AE72E35B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{32D31176-3F51-4E5C-8F53-71A514F12C3B}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= UDP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"UDP Query User{72A793D4-8069-46D7-BA6A-E48A5D422378}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= TCP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"TCP Query User{113F926D-4412-4674-9C8B-341F6F0CD64C}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= UDP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"UDP Query User{DD83DC34-65BF-4C0D-9673-64B141B5D318}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= TCP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"{E2936296-A90E-4B5E-B02D-620542763F23}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{3043FF13-988F-475F-9227-81357BB2FB4C}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{05D773F9-46B0-4B25-B947-694F19C69B5A}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{C114FF4C-7624-405F-B045-AE338684A1D3}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{310A8ED4-20B8-42B1-BAD4-5E2C3E46598F}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"{00314549-BA53-407C-8950-D2F5FA15FA08}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"TCP Query User{1313A507-6EF5-40F3-8A05-DB8E2838F299}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{2992D4DA-8686-4BA0-9354-DE9AC67BED05}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{89B9615C-723C-4AC2-BECC-B1E27D06DC50}c:\\program files\\pando networks\\pando\\pando.exe"= UDP:c:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{58A2EB3B-FD5A-45B9-8761-64F71078F2C0}c:\\program files\\pando networks\\pando\\pando.exe"= TCP:c:\program files\pando networks\pando\pando.exe:pando
"{FDAF74A7-198D-45D9-B45F-8AD448950A00}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{CB07C5DB-B574-42E5-BD8D-CFD697C07F88}"= UDP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{40698FDB-5209-4270-9146-3CE286110BA2}"= TCP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{938AD13A-211F-460D-81D4-D6F426F0703A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{B5C2B195-D145-4A8B-8C5D-90DD155B461A}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{48D2B7D2-45BC-4C05-8181-5B5C3D018377}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BDA4C13-9301-4D73-842C-8B8CA392AA03}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{17975F4E-F547-4D45-B825-9B76C257637F}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D48D10EC-D27F-4911-8A1C-A0BB1C7DE553}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [01/07/2009 13:44 28544]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [01/07/2009 19:16 114768]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [06/02/2009 14:23 106208]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11/09/2007 01:45 124832]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [01/07/2009 19:16 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [01/07/2009 14:15 51792]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [06/02/2009 14:23 727720]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [06/02/2009 14:24 38240]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [31/03/2009 17:22 194832]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [02/11/2007 19:46 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [02/11/2007 19:46 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [02/11/2007 19:46 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [02/11/2007 19:46 812544]
S2 gupdate1c9b0b335a8c7c6;Service Google Update (gupdate1c9b0b335a8c7c6);c:\program files\Google\Update\GoogleUpdate.exe [29/03/2009 23:13 133104]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 15:53 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 15:52 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 15:52 166384]
S2 SessionLauncher;SessionLauncher;c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe --> c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [02/11/2007 13:56 28464]
S3 MBAMDrvService;MBAMDrvService;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 15:53 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 15:52 1083888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contenu du dossier 'Tâches planifiées'
2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-01 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 11:14]
2009-06-30 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
2009-07-01 c:\windows\Tasks\Malwarebytes' Scheduled Update for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://fr.gdark.com
uSearchMigratedDefaultURL = hxxp://fr.gdark.com/search.php?cx=partner-pub-7902900401080901%3Ae94ctf-nqmg&cof=FORID%3A10&ie=UTF-8&q={searchTerms}
mStart Page = hxxp://fr.gdark.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://fr.gdark.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-01 20:08
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(300)
c:\windows\system32\btncopy.dll
c:\program files\WinSCP\DragExt.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\stacsv.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\conime.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\dllhost.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2009-07-01 20:17 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-01 18:17
Avant-CF: 80 861 376 512 octets libres
Après-CF: 82 549 321 728 octets libres
279 --- E O F --- 2009-07-01 16:11
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.936 [GMT 2:00]
Lancé depuis: c:\users\Romain\Desktop\ComboFix.exe
AV: avast! antivirus 4.7.1098 [VPS 090630-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: BitDefender AntiSpam *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\is-8M7H6.exe
c:\windows\system32\drivers\gxvxcyrxbwtqxiqjqttppulmriskrwqymxnbb.sys
c:\windows\system32\gxvxccount
c:\windows\system32\gxvxcvmnrnunqeckdecybgsxwxciswphnmhxo.dll
c:\windows\system32\gxvxcvxrdsajpdphxvtxrdcxckwepcxugsbsx.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GXVXCSERV.SYS
-------\Legacy_GXVXCSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-01 au 2009-07-01 ))))))))))))))))))))))))))))))))))))
.
2009-07-01 17:16 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-07-01 17:16 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-07-01 14:02 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2009-07-01 14:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-01 12:15 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-07-01 12:15 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-07-01 12:15 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-07-01 12:15 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-07-01 12:15 . 2009-02-05 20:06 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-07-01 12:14 . 2009-07-01 12:14 -------- d-----w- c:\program files\Alwil Software
2009-07-01 11:44 . 2008-06-19 15:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-07-01 11:44 . 2009-07-01 11:44 -------- d-----w- c:\program files\Panda Security
2009-06-30 23:02 . 2009-06-30 23:02 -------- d-----w- C:\UAC
2009-06-30 23:01 . 2009-07-01 11:41 -------- d-----w- C:\GenProc
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\programdata\NOS
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\program files\NOS
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\programdata\Emjysoft
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\users\Romain\AppData\Roaming\Emjysoft
2009-06-06 15:19 . 2009-06-18 23:08 -------- d-----w- c:\programdata\Electronic Arts
2009-06-06 15:17 . 2008-09-05 00:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-06 15:17 . 2009-06-06 15:17 10134 ----a-r- c:\users\Romain\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-06 15:17 . 2009-06-06 15:17 -------- d-----w- c:\program files\Microsoft WSE
2009-06-06 15:07 . 2009-06-06 15:18 -------- d-----w- c:\program files\Electronic Arts
2009-06-05 11:00 . 2009-06-05 11:02 7 ----a-w- c:\windows\sbacknt.bin
2009-06-05 10:59 . 2009-06-05 11:02 152904 ----a-w- c:\windows\system32\vghd.scr
2009-06-05 10:59 . 2009-06-05 11:06 -------- d-----w- c:\users\Romain\AppData\Roaming\vghd
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iPod
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iTunes
2009-06-03 22:12 . 2009-06-03 22:13 -------- d-----w- c:\program files\QuickTime
2009-06-03 22:04 . 2009-06-03 22:04 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-01 18:06 . 2007-11-02 10:02 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-01 18:05 . 2007-11-02 12:30 -------- d-----w- c:\programdata\Microsoft Help
2009-07-01 17:11 . 2008-10-19 17:12 -------- d-----w- c:\users\Romain\AppData\Roaming\uTorrent
2009-07-01 11:41 . 2008-10-07 16:31 -------- d-----w- c:\program files\Trend Micro
2009-06-30 15:39 . 2008-10-07 16:58 -------- d-----w- c:\users\Romain\AppData\Roaming\LimeWire
2009-06-27 11:59 . 2009-05-18 20:44 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-21 18:54 . 2007-11-02 10:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-20 21:33 . 2008-12-15 16:04 -------- d-----w- c:\program files\iPhone Tunnel Suite 2.7 BETA
2009-06-20 18:00 . 2008-12-06 12:58 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-19 08:08 . 2008-10-07 17:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-18 23:12 . 2008-10-07 17:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-18 09:01 . 2006-11-02 15:48 681712 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-18 09:01 . 2006-11-02 15:48 128882 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-16 15:28 . 2009-02-15 17:39 -------- d-----w- c:\users\Romain\AppData\Roaming\DiskAid
2009-06-10 15:44 . 2008-10-07 14:56 80846 ----a-w- c:\users\Romain\AppData\Roaming\nvModes.dat
2009-06-08 18:56 . 2009-01-30 21:07 -------- d-----w- c:\program files\MSN Messenger
2009-06-08 18:42 . 2008-10-08 15:54 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-06 18:57 . 2008-11-11 17:54 -------- d-----w- c:\users\Romain\AppData\Roaming\Microgaming
2009-06-06 14:44 . 2009-03-12 18:21 -------- d-----w- c:\program files\Yahoo!
2009-06-06 12:06 . 2009-01-12 16:33 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE760.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75F.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75E.tmp
2009-06-03 22:20 . 2008-10-13 18:43 -------- d-----w- c:\programdata\Apple
2009-06-03 22:16 . 2008-10-13 18:43 -------- d-----w- c:\program files\Common Files\Apple
2009-06-03 17:04 . 2009-02-02 22:00 -------- d-----w- c:\program files\LimeWire
2009-05-29 23:22 . 2009-03-31 15:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-29 18:00 . 2008-10-09 18:17 3371383 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-29 11:36 . 2009-05-29 11:36 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-29 11:36 . 2009-05-29 11:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-26 11:20 . 2008-10-07 16:53 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2008-10-07 16:53 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-18 20:56 . 2007-11-02 12:41 -------- d-----w- c:\program files\Java
2009-05-17 17:20 . 2007-11-02 09:56 -------- d-----w- c:\program files\Google
2009-05-16 21:59 . 2008-10-07 14:56 -------- d-----w- c:\users\Romain\AppData\Roaming\Sony Corporation
2009-05-16 21:59 . 2007-11-02 12:36 -------- d-----w- c:\program files\Sony
2009-05-14 18:22 . 2008-11-26 22:10 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-05-13 18:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-06 19:31 . 2008-10-07 14:56 160480 ----a-w- c:\users\Romain\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-05 19:25 . 2008-10-07 21:29 -------- d-----w- c:\program files\Microsoft Works
2009-05-04 15:29 . 2009-04-15 17:36 -------- d-----w- c:\users\Romain\AppData\Roaming\U3
2009-04-24 16:05 . 2009-07-01 14:01 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-07-01 14:01 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-07-01 14:01 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-02-13 19:30 . 2009-02-13 19:30 23 --sha-w- c:\windows\System32\edacded0_x.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" /Minimized
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe"
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7DA4246B-1404-480D-92B6-E51E876D76F2}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F26427AA-9D7D-4191-AAA9-12266E99B7D1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BDE2623B-1711-4FBF-B28B-45FF09E99526}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{905D9AE4-3175-47D5-ACDF-DC55AC39E9A7}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{6BD22369-8512-4E12-AFA7-AADA2856B05B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{4D448602-C5DE-4E34-BCB2-0903AE72E35B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{32D31176-3F51-4E5C-8F53-71A514F12C3B}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= UDP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"UDP Query User{72A793D4-8069-46D7-BA6A-E48A5D422378}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= TCP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"TCP Query User{113F926D-4412-4674-9C8B-341F6F0CD64C}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= UDP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"UDP Query User{DD83DC34-65BF-4C0D-9673-64B141B5D318}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= TCP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"{E2936296-A90E-4B5E-B02D-620542763F23}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{3043FF13-988F-475F-9227-81357BB2FB4C}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{05D773F9-46B0-4B25-B947-694F19C69B5A}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{C114FF4C-7624-405F-B045-AE338684A1D3}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{310A8ED4-20B8-42B1-BAD4-5E2C3E46598F}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"{00314549-BA53-407C-8950-D2F5FA15FA08}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"TCP Query User{1313A507-6EF5-40F3-8A05-DB8E2838F299}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{2992D4DA-8686-4BA0-9354-DE9AC67BED05}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{89B9615C-723C-4AC2-BECC-B1E27D06DC50}c:\\program files\\pando networks\\pando\\pando.exe"= UDP:c:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{58A2EB3B-FD5A-45B9-8761-64F71078F2C0}c:\\program files\\pando networks\\pando\\pando.exe"= TCP:c:\program files\pando networks\pando\pando.exe:pando
"{FDAF74A7-198D-45D9-B45F-8AD448950A00}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{CB07C5DB-B574-42E5-BD8D-CFD697C07F88}"= UDP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{40698FDB-5209-4270-9146-3CE286110BA2}"= TCP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{938AD13A-211F-460D-81D4-D6F426F0703A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{B5C2B195-D145-4A8B-8C5D-90DD155B461A}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{48D2B7D2-45BC-4C05-8181-5B5C3D018377}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BDA4C13-9301-4D73-842C-8B8CA392AA03}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{17975F4E-F547-4D45-B825-9B76C257637F}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D48D10EC-D27F-4911-8A1C-A0BB1C7DE553}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 pavboot;pavboot;c:\windows\System32\drivers\pavboot.sys [01/07/2009 13:44 28544]
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [01/07/2009 19:16 114768]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [06/02/2009 14:23 106208]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11/09/2007 01:45 124832]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [01/07/2009 19:16 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [01/07/2009 14:15 51792]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [06/02/2009 14:23 727720]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [06/02/2009 14:24 38240]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [31/03/2009 17:22 194832]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [02/11/2007 19:46 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [02/11/2007 19:46 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [02/11/2007 19:46 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [02/11/2007 19:46 812544]
S2 gupdate1c9b0b335a8c7c6;Service Google Update (gupdate1c9b0b335a8c7c6);c:\program files\Google\Update\GoogleUpdate.exe [29/03/2009 23:13 133104]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 15:53 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 15:52 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 15:52 166384]
S2 SessionLauncher;SessionLauncher;c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe --> c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [02/11/2007 13:56 28464]
S3 MBAMDrvService;MBAMDrvService;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 15:53 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 15:52 1083888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contenu du dossier 'Tâches planifiées'
2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-01 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 11:14]
2009-06-30 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
2009-07-01 c:\windows\Tasks\Malwarebytes' Scheduled Update for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://fr.gdark.com
uSearchMigratedDefaultURL = hxxp://fr.gdark.com/search.php?cx=partner-pub-7902900401080901%3Ae94ctf-nqmg&cof=FORID%3A10&ie=UTF-8&q={searchTerms}
mStart Page = hxxp://fr.gdark.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://fr.gdark.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-01 20:08
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(300)
c:\windows\system32\btncopy.dll
c:\program files\WinSCP\DragExt.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\stacsv.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\System32\conime.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\dllhost.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2009-07-01 20:17 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-01 18:17
Avant-CF: 80 861 376 512 octets libres
Après-CF: 82 549 321 728 octets libres
279 --- E O F --- 2009-07-01 16:11
destroyer67
Messages postés
7
Date d'inscription
lundi 11 août 2008
Statut
Membre
Dernière intervention
16 octobre 2009
2 juil. 2009 à 10:48
2 juil. 2009 à 10:48
jai du faire une restauration systeme après exécution de combofix car mon ordinateur redémarrer tout seul avant de rentrer mon mot de passe même en mode sans echec ....
Voilà le nouveau après la restauration systeme :
ComboFix 09-07-01.04 - Romain 02/07/2009 13:11.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.1147 [GMT 2:00]
Lancé depuis: c:\users\Romain\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: BitDefender AntiSpam *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\13f470.msi
c:\windows\Installer\1a01e8.msi
c:\windows\Installer\57964e.msi
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-02 au 2009-07-02 ))))))))))))))))))))))))))))))))))))
.
2009-07-02 11:17 . 2009-07-02 11:17 -------- d-----w- c:\users\Romain\AppData\Local\temp
2009-07-01 14:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-01 12:14 . 2009-07-02 10:37 -------- d-----w- c:\program files\Alwil Software
2009-06-30 23:02 . 2009-06-30 23:02 -------- d-----w- C:\UAC
2009-06-30 23:01 . 2009-07-01 11:41 -------- d-----w- C:\GenProc
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\programdata\NOS
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\program files\NOS
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\programdata\Emjysoft
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\users\Romain\AppData\Roaming\Emjysoft
2009-06-06 15:19 . 2009-06-18 23:08 -------- d-----w- c:\programdata\Electronic Arts
2009-06-06 15:17 . 2008-09-05 00:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-06 15:17 . 2009-06-06 15:17 10134 ----a-r- c:\users\Romain\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-06 15:17 . 2009-06-06 15:17 -------- d-----w- c:\program files\Microsoft WSE
2009-06-06 15:07 . 2009-06-06 15:18 -------- d-----w- c:\program files\Electronic Arts
2009-06-05 11:00 . 2009-06-05 11:02 7 ----a-w- c:\windows\sbacknt.bin
2009-06-05 10:59 . 2009-06-05 11:02 152904 ----a-w- c:\windows\system32\vghd.scr
2009-06-05 10:59 . 2009-06-05 11:06 -------- d-----w- c:\users\Romain\AppData\Roaming\vghd
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iPod
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iTunes
2009-06-03 22:12 . 2009-06-03 22:13 -------- d-----w- c:\program files\QuickTime
2009-06-03 22:04 . 2009-06-03 22:04 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 10:34 . 2007-11-02 10:02 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-01 22:38 . 2009-03-19 09:34 -------- d-----w- c:\program files\ESET
2009-07-01 18:05 . 2007-11-02 12:30 -------- d-----w- c:\programdata\Microsoft Help
2009-07-01 17:11 . 2008-10-19 17:12 -------- d-----w- c:\users\Romain\AppData\Roaming\uTorrent
2009-07-01 11:41 . 2008-10-07 16:31 -------- d-----w- c:\program files\Trend Micro
2009-06-30 15:39 . 2008-10-07 16:58 -------- d-----w- c:\users\Romain\AppData\Roaming\LimeWire
2009-06-27 11:59 . 2009-05-18 20:44 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-21 18:54 . 2007-11-02 10:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-20 21:33 . 2008-12-15 16:04 -------- d-----w- c:\program files\iPhone Tunnel Suite 2.7 BETA
2009-06-20 18:00 . 2008-12-06 12:58 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-18 23:12 . 2008-10-07 17:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-18 09:01 . 2006-11-02 15:48 681712 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-18 09:01 . 2006-11-02 15:48 128882 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-16 15:28 . 2009-02-15 17:39 -------- d-----w- c:\users\Romain\AppData\Roaming\DiskAid
2009-06-10 15:44 . 2008-10-07 14:56 80846 ----a-w- c:\users\Romain\AppData\Roaming\nvModes.dat
2009-06-08 18:56 . 2009-01-30 21:07 -------- d-----w- c:\program files\MSN Messenger
2009-06-08 18:42 . 2008-10-08 15:54 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-06 18:57 . 2008-11-11 17:54 -------- d-----w- c:\users\Romain\AppData\Roaming\Microgaming
2009-06-06 12:06 . 2009-01-12 16:33 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE760.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75F.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75E.tmp
2009-06-03 22:20 . 2008-10-13 18:43 -------- d-----w- c:\programdata\Apple
2009-06-03 22:16 . 2008-10-13 18:43 -------- d-----w- c:\program files\Common Files\Apple
2009-06-03 17:04 . 2009-02-02 22:00 -------- d-----w- c:\program files\LimeWire
2009-05-29 23:22 . 2009-03-31 15:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-29 18:00 . 2008-10-09 18:17 3371383 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-29 11:36 . 2009-05-29 11:36 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-29 11:36 . 2009-05-29 11:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-26 11:20 . 2008-10-07 16:53 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2008-10-07 16:53 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-18 20:56 . 2007-11-02 12:41 -------- d-----w- c:\program files\Java
2009-05-17 17:20 . 2007-11-02 09:56 -------- d-----w- c:\program files\Google
2009-05-16 21:59 . 2008-10-07 14:56 -------- d-----w- c:\users\Romain\AppData\Roaming\Sony Corporation
2009-05-16 21:59 . 2007-11-02 12:36 -------- d-----w- c:\program files\Sony
2009-05-14 18:22 . 2008-11-26 22:10 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-05-13 18:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-06 19:31 . 2008-10-07 14:56 160480 ----a-w- c:\users\Romain\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-05 19:25 . 2008-10-07 21:29 -------- d-----w- c:\program files\Microsoft Works
2009-05-04 15:29 . 2009-04-15 17:36 -------- d-----w- c:\users\Romain\AppData\Roaming\U3
2009-04-24 16:05 . 2009-07-01 14:01 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-07-01 14:01 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-07-01 14:01 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-02-13 19:30 . 2009-02-13 19:30 23 --sha-w- c:\windows\System32\edacded0_x.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" /Minimized
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe"
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"combofix"=c:\windows\system32\CF6410.exe /c c:\combofix\Combobatch.bat
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7DA4246B-1404-480D-92B6-E51E876D76F2}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F26427AA-9D7D-4191-AAA9-12266E99B7D1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BDE2623B-1711-4FBF-B28B-45FF09E99526}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{905D9AE4-3175-47D5-ACDF-DC55AC39E9A7}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{6BD22369-8512-4E12-AFA7-AADA2856B05B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{4D448602-C5DE-4E34-BCB2-0903AE72E35B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{32D31176-3F51-4E5C-8F53-71A514F12C3B}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= UDP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"UDP Query User{72A793D4-8069-46D7-BA6A-E48A5D422378}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= TCP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"TCP Query User{113F926D-4412-4674-9C8B-341F6F0CD64C}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= UDP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"UDP Query User{DD83DC34-65BF-4C0D-9673-64B141B5D318}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= TCP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"{E2936296-A90E-4B5E-B02D-620542763F23}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{3043FF13-988F-475F-9227-81357BB2FB4C}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{05D773F9-46B0-4B25-B947-694F19C69B5A}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{C114FF4C-7624-405F-B045-AE338684A1D3}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{310A8ED4-20B8-42B1-BAD4-5E2C3E46598F}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"{00314549-BA53-407C-8950-D2F5FA15FA08}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"TCP Query User{1313A507-6EF5-40F3-8A05-DB8E2838F299}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{2992D4DA-8686-4BA0-9354-DE9AC67BED05}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{89B9615C-723C-4AC2-BECC-B1E27D06DC50}c:\\program files\\pando networks\\pando\\pando.exe"= UDP:c:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{58A2EB3B-FD5A-45B9-8761-64F71078F2C0}c:\\program files\\pando networks\\pando\\pando.exe"= TCP:c:\program files\pando networks\pando\pando.exe:pando
"{FDAF74A7-198D-45D9-B45F-8AD448950A00}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{CB07C5DB-B574-42E5-BD8D-CFD697C07F88}"= UDP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{40698FDB-5209-4270-9146-3CE286110BA2}"= TCP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{938AD13A-211F-460D-81D4-D6F426F0703A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{B5C2B195-D145-4A8B-8C5D-90DD155B461A}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{48D2B7D2-45BC-4C05-8181-5B5C3D018377}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BDA4C13-9301-4D73-842C-8B8CA392AA03}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{17975F4E-F547-4D45-B825-9B76C257637F}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D48D10EC-D27F-4911-8A1C-A0BB1C7DE553}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [06/02/2009 14:23 106208]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11/09/2007 01:45 124832]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [06/02/2009 14:23 727720]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [06/02/2009 14:24 38240]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [31/03/2009 17:22 194832]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [02/11/2007 19:46 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [02/11/2007 19:46 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [02/11/2007 19:46 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [02/11/2007 19:46 812544]
S2 gupdate1c9b0b335a8c7c6;Service Google Update (gupdate1c9b0b335a8c7c6);c:\program files\Google\Update\GoogleUpdate.exe [29/03/2009 23:13 133104]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 15:53 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 15:52 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 15:52 166384]
S2 SessionLauncher;SessionLauncher;c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe --> c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [02/11/2007 13:56 28464]
S3 MBAMDrvService;MBAMDrvService;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 15:53 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 15:52 1083888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contenu du dossier 'Tâches planifiées'
2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-02 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 11:14]
2009-06-30 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
2009-07-01 c:\windows\Tasks\Malwarebytes' Scheduled Update for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://fr.gdark.com
uSearchMigratedDefaultURL = hxxp://fr.gdark.com/search.php?cx=partner-pub-7902900401080901%3Ae94ctf-nqmg&cof=FORID%3A10&ie=UTF-8&q={searchTerms}
mStart Page = hxxp://fr.gdark.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://fr.gdark.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-02 13:17
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2009-07-02 13:21
ComboFix-quarantined-files.txt 2009-07-02 11:21
ComboFix2.txt 2009-07-01 18:17
Avant-CF: 82 550 820 864 octets libres
Après-CF: 82 458 218 496 octets libres
232 --- E O F --- 2009-07-01 16:11
ComboFix 09-07-01.04 - Romain 02/07/2009 13:11.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.1147 [GMT 2:00]
Lancé depuis: c:\users\Romain\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: BitDefender AntiSpam *disabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\13f470.msi
c:\windows\Installer\1a01e8.msi
c:\windows\Installer\57964e.msi
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-02 au 2009-07-02 ))))))))))))))))))))))))))))))))))))
.
2009-07-02 11:17 . 2009-07-02 11:17 -------- d-----w- c:\users\Romain\AppData\Local\temp
2009-07-01 14:02 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-07-01 12:14 . 2009-07-02 10:37 -------- d-----w- c:\program files\Alwil Software
2009-06-30 23:02 . 2009-06-30 23:02 -------- d-----w- C:\UAC
2009-06-30 23:01 . 2009-07-01 11:41 -------- d-----w- C:\GenProc
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\programdata\NOS
2009-06-14 20:32 . 2009-06-14 20:55 -------- d-----w- c:\program files\NOS
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\programdata\Emjysoft
2009-06-14 16:27 . 2009-06-14 16:27 -------- d-----w- c:\users\Romain\AppData\Roaming\Emjysoft
2009-06-06 15:19 . 2009-06-18 23:08 -------- d-----w- c:\programdata\Electronic Arts
2009-06-06 15:17 . 2008-09-05 00:22 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-06 15:17 . 2009-06-06 15:17 10134 ----a-r- c:\users\Romain\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-06 15:17 . 2009-06-06 15:17 -------- d-----w- c:\program files\Microsoft WSE
2009-06-06 15:07 . 2009-06-06 15:18 -------- d-----w- c:\program files\Electronic Arts
2009-06-05 11:00 . 2009-06-05 11:02 7 ----a-w- c:\windows\sbacknt.bin
2009-06-05 10:59 . 2009-06-05 11:02 152904 ----a-w- c:\windows\system32\vghd.scr
2009-06-05 10:59 . 2009-06-05 11:06 -------- d-----w- c:\users\Romain\AppData\Roaming\vghd
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iPod
2009-06-03 22:16 . 2009-06-03 22:16 -------- d-----w- c:\program files\iTunes
2009-06-03 22:12 . 2009-06-03 22:13 -------- d-----w- c:\program files\QuickTime
2009-06-03 22:04 . 2009-06-03 22:04 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-02 10:34 . 2007-11-02 10:02 12 ----a-w- c:\windows\bthservsdp.dat
2009-07-01 22:38 . 2009-03-19 09:34 -------- d-----w- c:\program files\ESET
2009-07-01 18:05 . 2007-11-02 12:30 -------- d-----w- c:\programdata\Microsoft Help
2009-07-01 17:11 . 2008-10-19 17:12 -------- d-----w- c:\users\Romain\AppData\Roaming\uTorrent
2009-07-01 11:41 . 2008-10-07 16:31 -------- d-----w- c:\program files\Trend Micro
2009-06-30 15:39 . 2008-10-07 16:58 -------- d-----w- c:\users\Romain\AppData\Roaming\LimeWire
2009-06-27 11:59 . 2009-05-18 20:44 362240 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-06-21 18:54 . 2007-11-02 10:57 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-20 21:33 . 2008-12-15 16:04 -------- d-----w- c:\program files\iPhone Tunnel Suite 2.7 BETA
2009-06-20 18:00 . 2008-12-06 12:58 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-06-18 23:12 . 2008-10-07 17:28 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-06-18 09:01 . 2006-11-02 15:48 681712 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-18 09:01 . 2006-11-02 15:48 128882 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-16 15:28 . 2009-02-15 17:39 -------- d-----w- c:\users\Romain\AppData\Roaming\DiskAid
2009-06-10 15:44 . 2008-10-07 14:56 80846 ----a-w- c:\users\Romain\AppData\Roaming\nvModes.dat
2009-06-08 18:56 . 2009-01-30 21:07 -------- d-----w- c:\program files\MSN Messenger
2009-06-08 18:42 . 2008-10-08 15:54 -------- d-----w- c:\program files\Messenger Plus! Live
2009-06-06 18:57 . 2008-11-11 17:54 -------- d-----w- c:\users\Romain\AppData\Roaming\Microgaming
2009-06-06 12:06 . 2009-01-12 16:33 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE760.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75F.tmp
2009-06-06 12:06 . 2009-06-06 12:06 0 ----a-w- c:\windows\system32\RENE75E.tmp
2009-06-03 22:20 . 2008-10-13 18:43 -------- d-----w- c:\programdata\Apple
2009-06-03 22:16 . 2008-10-13 18:43 -------- d-----w- c:\program files\Common Files\Apple
2009-06-03 17:04 . 2009-02-02 22:00 -------- d-----w- c:\program files\LimeWire
2009-05-29 23:22 . 2009-03-31 15:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-29 18:00 . 2008-10-09 18:17 3371383 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-29 11:36 . 2009-05-29 11:36 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-29 11:36 . 2009-05-29 11:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-26 11:20 . 2008-10-07 16:53 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:19 . 2008-10-07 16:53 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-18 20:56 . 2007-11-02 12:41 -------- d-----w- c:\program files\Java
2009-05-17 17:20 . 2007-11-02 09:56 -------- d-----w- c:\program files\Google
2009-05-16 21:59 . 2008-10-07 14:56 -------- d-----w- c:\users\Romain\AppData\Roaming\Sony Corporation
2009-05-16 21:59 . 2007-11-02 12:36 -------- d-----w- c:\program files\Sony
2009-05-14 18:22 . 2008-11-26 22:10 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-05-13 18:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-06 19:31 . 2008-10-07 14:56 160480 ----a-w- c:\users\Romain\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-05 19:25 . 2008-10-07 21:29 -------- d-----w- c:\program files\Microsoft Works
2009-05-04 15:29 . 2009-04-15 17:36 -------- d-----w- c:\users\Romain\AppData\Roaming\U3
2009-04-24 16:05 . 2009-07-01 14:01 827904 ----a-w- c:\windows\system32\wininet.dll
2009-04-24 16:02 . 2009-07-01 14:01 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-24 13:44 . 2009-07-01 14:01 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-02-13 19:30 . 2009-02-13 19:30 23 --sha-w- c:\windows\System32\edacded0_x.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ehTray.exe"=c:\windows\ehome\ehTray.exe
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" /Minimized
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" /background
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe"
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"combofix"=c:\windows\system32\CF6410.exe /c c:\combofix\Combobatch.bat
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{7DA4246B-1404-480D-92B6-E51E876D76F2}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{F26427AA-9D7D-4191-AAA9-12266E99B7D1}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{BDE2623B-1711-4FBF-B28B-45FF09E99526}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{905D9AE4-3175-47D5-ACDF-DC55AC39E9A7}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{6BD22369-8512-4E12-AFA7-AADA2856B05B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{4D448602-C5DE-4E34-BCB2-0903AE72E35B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{32D31176-3F51-4E5C-8F53-71A514F12C3B}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= UDP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"UDP Query User{72A793D4-8069-46D7-BA6A-E48A5D422378}c:\\program files\\common files\\roxio shared\\10.0\\sharedcom\\roxwatchtray10.exe"= TCP:c:\program files\common files\roxio shared\10.0\sharedcom\roxwatchtray10.exe:RoxMMTrayApp Module
"TCP Query User{113F926D-4412-4674-9C8B-341F6F0CD64C}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= UDP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"UDP Query User{DD83DC34-65BF-4C0D-9673-64B141B5D318}c:\\program files\\iphone tunnel suite 2.7 beta\\itunnel\\itunnel.exe"= TCP:c:\program files\iphone tunnel suite 2.7 beta\itunnel\itunnel.exe:iTunnel
"{E2936296-A90E-4B5E-B02D-620542763F23}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{3043FF13-988F-475F-9227-81357BB2FB4C}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\RM.exe:Render Manager
"{05D773F9-46B0-4B25-B947-694F19C69B5A}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{C114FF4C-7624-405F-B045-AE338684A1D3}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\Studio.exe:Studio
"{310A8ED4-20B8-42B1-BAD4-5E2C3E46598F}"= UDP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"{00314549-BA53-407C-8950-D2F5FA15FA08}"= TCP:c:\program files\Pinnacle\Studio 12\Programs\umi.exe:umi
"TCP Query User{1313A507-6EF5-40F3-8A05-DB8E2838F299}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{2992D4DA-8686-4BA0-9354-DE9AC67BED05}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{89B9615C-723C-4AC2-BECC-B1E27D06DC50}c:\\program files\\pando networks\\pando\\pando.exe"= UDP:c:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{58A2EB3B-FD5A-45B9-8761-64F71078F2C0}c:\\program files\\pando networks\\pando\\pando.exe"= TCP:c:\program files\pando networks\pando\pando.exe:pando
"{FDAF74A7-198D-45D9-B45F-8AD448950A00}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{CB07C5DB-B574-42E5-BD8D-CFD697C07F88}"= UDP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{40698FDB-5209-4270-9146-3CE286110BA2}"= TCP:g:\romain\Logiciels\LimeWire\LimeWire.exe:LimeWire
"{938AD13A-211F-460D-81D4-D6F426F0703A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{B5C2B195-D145-4A8B-8C5D-90DD155B461A}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{48D2B7D2-45BC-4C05-8181-5B5C3D018377}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{3BDA4C13-9301-4D73-842C-8B8CA392AA03}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{17975F4E-F547-4D45-B825-9B76C257637F}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D48D10EC-D27F-4911-8A1C-A0BB1C7DE553}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [06/02/2009 14:23 106208]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [11/09/2007 01:45 124832]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [06/02/2009 14:23 727720]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [06/02/2009 14:24 38240]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [31/03/2009 17:22 194832]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [02/11/2007 19:46 75008]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [02/11/2007 19:46 43904]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [02/11/2007 19:46 9344]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [02/11/2007 19:46 812544]
S2 gupdate1c9b0b335a8c7c6;Service Google Update (gupdate1c9b0b335a8c7c6);c:\program files\Google\Update\GoogleUpdate.exe [29/03/2009 23:13 133104]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 15:53 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 15:52 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 15:52 166384]
S2 SessionLauncher;SessionLauncher;c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe --> c:\users\Romain\AppData\Local\Temp\DX9\SessionLauncher.exe [?]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\System32\drivers\btwl2cap.sys [02/11/2007 13:56 28464]
S3 MBAMDrvService;MBAMDrvService;c:\windows\System32\drivers\mbam.sys [07/10/2008 18:53 19096]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 15:53 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 15:52 1083888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contenu du dossier 'Tâches planifiées'
2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-29 21:13]
2009-07-02 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 11:14]
2009-06-30 c:\windows\Tasks\Malwarebytes' Scheduled Scan for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
2009-07-01 c:\windows\Tasks\Malwarebytes' Scheduled Update for Romain.job
- c:\program files\Malwarebytes' Anti-Malware\mbam.exe [2009-03-31 11:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://fr.gdark.com
uSearchMigratedDefaultURL = hxxp://fr.gdark.com/search.php?cx=partner-pub-7902900401080901%3Ae94ctf-nqmg&cof=FORID%3A10&ie=UTF-8&q={searchTerms}
mStart Page = hxxp://fr.gdark.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://fr.gdark.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-02 13:17
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2009-07-02 13:21
ComboFix-quarantined-files.txt 2009-07-02 11:21
ComboFix2.txt 2009-07-01 18:17
Avant-CF: 82 550 820 864 octets libres
Après-CF: 82 458 218 496 octets libres
232 --- E O F --- 2009-07-01 16:11