On pirate mon msn - Page 2

Précédent
  • 1
  • 2
blacstroumpf
 
bonjour,
Le lien n a pas marché alors j ai fait autrement j'espère que ça ira.
Voici le rapport et bonne journée
ComboFix 09-07-21.03 - jc 22/07/2009 7:59.4.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1023.700 [GMT 2:00]
Running from: c:\documents and settings\jc\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090721-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-06-22 to 2009-07-22 )))))))))))))))))))))))))))))))
.

2009-07-21 06:23 . 2009-07-21 06:23 -------- d-----w- c:\documents and settings\jc\Application Data\Ahead
2009-07-09 07:01 . 2009-07-09 07:01 -------- d-----w- c:\documents and settings\jc\Local Settings\Application Data\Help
2009-07-06 17:49 . 2009-07-06 17:49 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2009-07-06 17:49 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2009-07-06 17:49 . 2009-07-06 17:49 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-07-06 17:49 . 2009-07-06 17:49 -------- d-----w- c:\documents and settings\jc\Application Data\TuneUp Software
2009-07-06 17:49 . 2009-07-06 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-07-06 17:49 . 2009-07-06 17:50 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-07-06 17:48 . 2009-07-06 17:48 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-07-06 14:12 . 2009-07-06 14:12 -------- d-sh--w- c:\documents and settings\jc\PrivacIE
2009-07-06 14:08 . 2009-07-06 14:08 -------- d-sh--w- c:\documents and settings\jc\IETldCache
2009-07-06 10:24 . 2009-06-02 10:12 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-07-06 10:24 . 2009-07-06 10:24 -------- d-----w- c:\windows\ie8updates
2009-07-06 10:23 . 2009-04-30 21:16 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-07-06 10:23 . 2009-04-30 21:16 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-06 10:20 . 2009-07-06 10:23 -------- dc-h--w- c:\windows\ie8
2009-07-06 05:14 . 2009-07-20 14:23 -------- d-----w- c:\program files\trend micro
2009-07-06 05:14 . 2009-07-06 05:14 -------- d-----w- C:\rsit
2009-07-04 10:17 . 2009-07-21 06:18 -------- d-----w- c:\program files\MessenPass
2009-07-04 10:17 . 2009-07-04 10:17 39424 ----a-w- c:\windows\zipinst.exe
2009-07-03 12:19 . 2009-07-03 12:19 -------- d-----w- C:\Gen5
2009-07-02 20:24 . 2009-07-02 20:25 -------- d-----w- c:\program files\eMule

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-21 06:19 . 2008-11-25 22:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-21 06:19 . 2009-04-07 18:23 -------- d-----w- c:\program files\Fichiers communs\Mapserv
2009-07-21 06:19 . 2009-04-29 07:34 -------- d-----w- c:\documents and settings\jc\Application Data\PTV AG
2009-07-21 06:18 . 2009-03-29 18:03 -------- d-----w- c:\program files\INFORAD
2009-07-02 17:29 . 2009-02-26 22:23 -------- d-----w- c:\documents and settings\jc\Application Data\dvdcss
2009-06-16 14:40 . 2002-08-30 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2002-08-30 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 21:51 . 2002-08-30 12:00 72474 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-12 21:51 . 2002-08-30 12:00 461318 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-03 19:10 . 2005-08-30 04:03 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-05-13 05:04 . 2006-06-23 12:28 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:33 . 2002-08-29 10:44 348672 ----a-w- c:\windows\system32\localspl.dll
2008-12-09 08:41 . 2008-12-09 08:41 274432 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2009-06-12 06:34 . 2008-12-07 18:36 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-13_05.51.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-22 05:08 . 2009-07-22 05:08 16384 c:\windows\Temp\Perflib_Perfdata_724.dat
- 2008-12-08 20:17 . 2008-12-08 20:17 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2008-12-08 20:17 . 2009-07-21 06:16 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-06-16 14:40 . 2009-06-16 14:40 81920 c:\windows\system32\dllcache\fontsub.dll
- 2008-11-25 14:13 . 2009-06-11 07:14 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-06-16 14:40 . 2009-06-16 14:40 119808 c:\windows\system32\dllcache\t2embed.dll
+ 2008-11-27 15:33 . 2009-07-14 14:19 295606 c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A81300000003}\SC_Reader.exe
- 2008-11-27 15:33 . 2009-07-02 05:18 295606 c:\windows\Installer\{AC76BA86-7AD7-1036-7B44-A81300000003}\SC_Reader.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-11-25 14:13 . 2009-06-11 07:14 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-11-25 14:13 . 2009-07-15 21:18 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2008-05-07 05:11 . 2009-06-03 19:10 1297408 c:\windows\system32\dllcache\quartz.dll
+ 2009-07-14 14:18 . 2009-07-14 14:18 1711616 c:\windows\Installer\19547b4.msp
+ 2009-06-30 09:30 . 2009-06-30 09:30 5520384 c:\windows\Installer\1188946.msp
+ 2008-11-28 18:16 . 2009-07-07 15:10 24539592 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-12-02 3882312]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 1211176]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-28 68856]
"Start WingMan Profiler"="c:\program files\Logitech\Profiler\lwemon.exe" [2004-04-23 77824]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-11 1961984]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"EPSON Stylus DX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.EXE" [2005-03-07 98304]
"DataLayer"="c:\program files\Fichiers communs\PCSuite\DataLayer\DataLayer.exe" [2005-09-06 820736]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2005-06-29 176128]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\eMule\\emule.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [09/06/2009 20:09 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/06/2009 20:09 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [19/12/2008 12:26 55136]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [06/07/2009 19:49 604416]
S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [08/12/2008 18:01 533344]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [27/11/2008 17:10 33752]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 09:34 216232]
S3 MEGAUSB0101;MegawinMa100;c:\windows\system32\drivers\usbscan.sys [16/12/2008 17:31 15104]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-22 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\jc\Application Data\Mozilla\Firefox\Profiles\w9k3rgtc.default\
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-22 08:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\System32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3168)
c:\program files\Logitech\Profiler\LWEHook.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-22 8:04
ComboFix-quarantined-files.txt 2009-07-22 06:04
ComboFix2.txt 2009-07-21 05:33
ComboFix3.txt 2009-07-13 06:07
ComboFix4.txt 2009-07-13 05:52

Pre-Run: 102 385 893 376 octets libres
Post-Run: 102 354 833 408 octets libres

188 --- E O F --- 2009-07-15 21:18
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Bonjour,

les vacances ne sont pas propices à des réponses rapides.

fais ceci :

Télécharge SysProt ( de swatkat ) sur ton bureau :

http://homepages.slingshot.co.nz/~crutches/SysProt/SysProt.e­xe

!! Déconnecte toi, ferme toutes tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

* double clique sur "SysProt.exe" pour lancer l'outil .

* clique sur l'onglet "log" :

> coche toutes les cases présentes dans l'encadré "Write to log" .

* Puis clique sur le bouton en bas à droite [Create Log] .

* le scan démarre , laisse travailler l'outil ( même si il semble avoir planté ...)

> Au bout d'un moment, une fenêtre va apparaitre : laisse bien "Scan all drives " coché et clique sur [Start] .

> patiente de nouveau ... attends le message de fin indiquant la creation du rapport et clique sur "OK"

* ferme SysProt et copie/colle le contenu du rapport "SysProtLog.txt" qui a été sauvegardé sur ton bureau dans ta prochaine réponse ...
0
jfkpresident Messages postés 13877 Statut Contributeur sécurité 1 175
 
Vincent ,ton lien n'est pas valide ....
0
Lyonnais92 Messages postés 25708 Statut Contributeur sécurité 1 537
 
Re,

merci jfk.

le lien valide :

http://homepages.slingshot.co.nz/~crutches/SysProt/SysProt.exe
0
Précédent
  • 1
  • 2