On pirate mon msn - Page 2

Précédent
  • 1
  • 2
  1. blacstroumpf
     
    bonjour,
    Le lien n a pas marché alors j ai fait autrement j'espère que ça ira.
    Voici le rapport et bonne journée
    ComboFix 09-07-21.03 - jc 22/07/2009 7:59.4.2 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1023.700 [GMT 2:00]
    Running from: c:\documents and settings\jc\Bureau\ComboFix.exe
    AV: avast! antivirus 4.8.1335 [VPS 090721-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((( Files Created from 2009-06-22 to 2009-07-22 )))))))))))))))))))))))))))))))
    .

    2009-07-21 06:23 . 2009-07-21 06:23 -------- d-----w- c:\documents and settings\jc\Application Data\Ahead
    2009-07-09 07:01 . 2009-07-09 07:01 -------- d-----w- c:\documents and settings\jc\Local Settings\Application Data\Help
    2009-07-06 17:49 . 2009-07-06 17:49 604416 ----a-w- c:\windows\system32\TUProgSt.exe
    2009-07-06 17:49 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
    2009-07-06 17:49 . 2009-07-06 17:49 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
    2009-07-06 17:49 . 2009-07-06 17:49 -------- d-----w- c:\documents and settings\jc\Application Data\TuneUp Software
    2009-07-06 17:49 . 2009-07-06 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
    2009-07-06 17:49 . 2009-07-06 17:50 -------- d-----w- c:\program files\TuneUp Utilities 2009
    2009-07-06 17:48 . 2009-07-06 17:48 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
    2009-07-06 14:12 . 2009-07-06 14:12 -------- d-sh--w- c:\documents and settings\jc\PrivacIE
    2009-07-06 14:08 . 2009-07-06 14:08 -------- d-sh--w- c:\documents and settings\jc\IETldCache
    2009-07-06 10:24 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
    2009-07-06 10:24 . 2009-07-06 10:24 -------- d-----w- c:\windows\ie8updates
    2009-07-06 10:23 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
    2009-07-06 10:23 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
    2009-07-06 10:20 . 2009-07-06 10:23 -------- dc-h--w- c:\windows\ie8
    2009-07-06 05:14 . 2009-07-20 14:23 -------- d-----w- c:\program files\trend micro
    2009-07-06 05:14 . 2009-07-06 05:14 -------- d-----w- C:\rsit
    2009-07-04 10:17 . 2009-07-21 06:18 -------- d-----w- c:\program files\MessenPass
    2009-07-04 10:17 . 2009-07-04 10:17 39424 ----a-w- c:\windows\zipinst.exe
    2009-07-03 12:19 . 2009-07-03 12:19 -------- d-----w- C:\Gen5
    2009-07-02 20:24 . 2009-07-02 20:25 -------- d-----w- c:\program files\eMule

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-07-21 06:19 . 2008-11-25 22:13 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-07-21 06:19 . 2009-04-07 18:23 -------- d-----w- c:\program files\Fichiers communs\Mapserv
    2009-07-21 06:19 . 2009-04-29 07:34 -------- d-----w- c:\documents and settings\jc\Application Data\PTV AG
    2009-07-21 06:18 . 2009-03-29 18:03 -------- d-----w- c:\program files\INFORAD
    2009-07-02 17:29 . 2009-02-26 22:23 -------- d-----w- c:\documents and settings\jc\Application Data\dvdcss
    2009-06-16 14:40 . 2002-08-30 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
    2009-06-16 14:40 . 2002-08-30 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-06-12 21:51 . 2002-08-30 12:00 72474 ----a-w- c:\windows\system32\perfc00C.dat
    2009-06-12 21:51 . 2002-08-30 12:00 461318 ----a-w- c:\windows\system32\perfh00C.dat
    2009-06-03 19:10 . 2005-08-30 04:03 1297408 ----a-w- c:\windows\system32\quartz.dll
    2009-05-13 05:04 . 2006-06-23 12:28 915456 ----a-w- c:\windows\system32\wininet.dll
    2009-05-07 15:33 . 2002-08-29 10:44 348672 ----a-w- c:\windows\system32\localspl.dll
    2008-12-09 08:41 . 2008-12-09 08:41 274432 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
    2009-06-12 06:34 . 2008-12-07 18:36 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-07-13_05.51.23 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-07-22 05:08 . 2009-07-22 05:08 16384 c:\windows\Temp\Perflib_Perfdata_724.dat
    - 2008-12-08 20:17 . 2008-12-08 20:17 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
    + 2008-12-08 20:17 . 2009-07-21 06:16 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
    + 2009-06-16 14:40 . 2009-06-16 14:40 81920 c:\windows\system32\dllcache\fontsub.dll
    - 2008-11-25 14:13 . 2009-06-11 07:14 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
    + 2009-06-16 14:40 . 2009-06-16 14:40 119808 c:\windows\system32\dllcache\t2embed.dll
    + 2008-11-27 15:33 . 2009-07-14 14:19 295606 c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A81300000003}\SC_Reader.exe
    - 2008-11-27 15:33 . 2009-07-02 05:18 295606 c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A81300000003}\SC_Reader.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-11-25 14:13 . 2009-06-11 07:14 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
    + 2008-11-25 14:13 . 2009-07-15 21:18 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
    + 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
    + 2008-05-07 05:11 . 2009-06-03 19:10 1297408 c:\windows\system32\dllcache\quartz.dll
    + 2009-07-14 14:18 . 2009-07-14 14:18 1711616 c:\windows\Installer\19547b4.msp
    + 2009-06-30 09:30 . 2009-06-30 09:30 5520384 c:\windows\Installer\1188946.msp
    + 2008-11-28 18:16 . 2009-07-07 15:10 24539592 c:\windows\system32\MRT.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
    "H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 1211176]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-28 68856]
    "Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2004-04-23 77824]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "EPSON Stylus DX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-07 98304]
    "DataLayer"="c:\program files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe" [2005-09-06 820736]
    "PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 176128]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
    "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "c:\\Program Files\\eMule\\emule.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [09/06/2009 20:09 114768]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/06/2009 20:09 20560]
    R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [19/12/2008 12:26 55136]
    R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [06/07/2009 19:49 604416]
    S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [08/12/2008 18:01 533344]
    S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [27/11/2008 17:10 33752]
    S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 09:34 216232]
    S3 MEGAUSB0101;MegawinMa100;c:\windows\system32\drivers\usbscan.sys [16/12/2008 17:31 15104]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-07-22 c:\windows\Tasks\Maintenance en 1 clic.job
    - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:42]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.fr/
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\documents and settings\jc\Application Data\Mozilla\Firefox\Profiles\w9k3rgtc.default\
    FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-07-22 08:02
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
    "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(3168)
    c:\program files\Logitech\Profiler\LWEHook.dll
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2009-07-22 8:04
    ComboFix-quarantined-files.txt 2009-07-22 06:04
    ComboFix2.txt 2009-07-21 05:33
    ComboFix3.txt 2009-07-13 06:07
    ComboFix4.txt 2009-07-13 05:52

    Pre-Run: 102 385 893 376 octets libres
    Post-Run: 102 354 833 408 octets libres

    188 --- E O F --- 2009-07-15 21:18
    0
  2. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Bonjour,

    les vacances ne sont pas propices à des réponses rapides.

    fais ceci :

    Télécharge SysProt ( de swatkat ) sur ton bureau :

    http://homepages.slingshot.co.nz/~crutches/SysProt/SysProt.e­xe

    !! Déconnecte toi, ferme toutes tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

    * double clique sur "SysProt.exe" pour lancer l'outil .

    * clique sur l'onglet "log" :

    > coche toutes les cases présentes dans l'encadré "Write to log" .

    * Puis clique sur le bouton en bas à droite [Create Log] .

    * le scan démarre , laisse travailler l'outil ( même si il semble avoir planté ...)

    > Au bout d'un moment, une fenêtre va apparaitre : laisse bien "Scan all drives " coché et clique sur [Start] .

    > patiente de nouveau ... attends le message de fin indiquant la creation du rapport et clique sur "OK"

    * ferme SysProt et copie/colle le contenu du rapport "SysProtLog.txt" qui a été sauvegardé sur ton bureau dans ta prochaine réponse ...
    0
  3. jfkpresident Messages postés 13877 Statut Contributeur sécurité 1 175
     
    Vincent ,ton lien n'est pas valide ....
    0
  4. Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
     
    Re,

    merci jfk.

    le lien valide :

    http://homepages.slingshot.co.nz/~crutches/SysProt/SysProt.exe
    0
Précédent
  • 1
  • 2