A voir également:
- Trojan
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Anti trojan - Télécharger - Antivirus & Antimalwares
- Trojan b901 system32 win config 34 ✓ - Forum Virus
- Csrss.exe trojan fr ✓ - Forum Virus
- Trojan win32 - Forum Virus
32 réponses
voici le rapport de combofix le dernier que tu m'a demandé je vais faire le reste tt de suite
ComboFix 09-07-27.02 - Dominique Cavuoto 28/07/2009 12:36.2.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.447.131 [GMT 2:00]
Running from: c:\documents and settings\Dominique Cavuoto\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Dominique Cavuoto\Bureau\CFscript.txt
AV: avast! antivirus 4.8.1335 [VPS 090727-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Drivers\nyoht.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_tsxrw
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-28 )))))))))))))))))))))))))))))))
.
2009-07-27 08:18 . 2009-07-27 08:34 -------- d-----w- c:\program files\Navilog1
2009-07-27 08:17 . 2009-07-27 08:17 -------- d-----w- c:\program files\AskBardis
2009-07-27 08:13 . 2009-07-27 08:13 -------- d-----w- c:\program files\CCleaner
2009-07-27 08:06 . 2009-07-27 08:09 -------- d-----w- C:\ToolBar SD
2009-07-27 07:43 . 2009-07-27 07:46 -------- d-----w- C:\rsit
2009-07-24 08:34 . 2009-07-24 08:34 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
2009-07-16 08:08 . 2009-07-16 08:08 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
2009-07-10 15:14 . 2009-07-10 15:13 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1\itstv.exe
2009-07-07 15:31 . 2009-07-07 15:31 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0\itstv.exe
2009-07-02 07:59 . 2009-07-03 05:41 -------- d-----w- C:\!KillBox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 10:44 . 2009-03-23 16:56 -------- d-----w- c:\program files\DNA
2009-07-28 10:44 . 2009-03-23 16:56 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\DNA
2009-07-28 10:12 . 2009-07-28 10:12 1726 ----a-w- c:\program files\xrvrzsb.txt
2009-07-28 10:05 . 2008-10-08 14:52 -------- d-----w- c:\program files\EoRezo
2009-07-28 09:12 . 2007-02-01 15:06 -------- d-----w- c:\program files\Mozilla Thunderbird Beta 2
2009-07-28 09:01 . 2008-10-08 14:52 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo
2009-07-28 05:31 . 2008-10-19 14:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-27 19:22 . 2007-10-26 05:23 -------- d-----w- c:\program files\Trend Micro
2009-07-27 13:28 . 2008-10-19 14:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-27 10:56 . 2009-04-15 15:25 -------- d-----w- c:\program files\LucasArts
2009-07-27 10:56 . 2006-11-17 10:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 09:58 . 2008-10-20 06:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-24 05:28 . 2009-04-24 17:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-18 07:34 . 2009-05-15 14:45 -------- d-----w- c:\program files\free-downloads.net
2009-07-17 17:56 . 2009-03-23 17:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Azureus
2009-07-13 11:36 . 2008-10-20 06:59 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2008-10-20 06:59 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-10 10:54 . 2009-04-24 16:57 -------- d-----w- c:\program files\Windows Live
2009-07-10 10:14 . 2007-10-17 15:30 43536 ----a-w- c:\documents and settings\Dominique Cavuoto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-25 05:58 . 2009-06-25 05:58 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9\itstv.exe
2009-06-17 12:39 . 2009-06-17 12:39 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8\itstv.exe
2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-09 15:57 . 2009-06-09 15:56 -------- d-----w- c:\program files\Google
2009-06-09 12:16 . 2009-06-09 12:16 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
2009-06-06 15:17 . 2009-06-05 16:14 -------- d-----w- c:\program files\Studio-Scrap
2009-06-06 14:06 . 2009-06-05 16:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Studio-Scrap2
2009-06-05 16:31 . 2009-06-05 15:02 -------- d-----w- c:\program files\InstStudio-Scrap
2009-06-03 19:10 . 2006-03-02 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-03 17:07 . 2009-06-03 17:07 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
2009-06-01 16:26 . 2009-06-01 16:26 -------- d-----w- c:\program files\EA GAMES
2009-05-31 06:31 . 2009-04-26 08:23 -------- d-----w- c:\program files\UBISOFT
2009-05-27 07:09 . 2009-05-27 07:09 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
2009-05-16 06:42 . 2009-05-16 06:42 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4\itstv.exe
2009-05-08 18:03 . 2009-05-08 18:03 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3\itstv.exe
2009-05-07 15:33 . 2006-03-02 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 19:26 . 2009-04-25 08:04 258408 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-23 15:20 . 2008-12-22 19:16 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-28_08.42.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-28 10:43 . 2009-07-28 10:43 16384 c:\windows\Temp\Perflib_Perfdata_238.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-07-18 07:35 2215960 ----a-w- c:\program files\free-downloads.net\tbfre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-23 321344]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-06-25 1578736]
"eMuleAutoStart"="d:\programs\eMule V0.48a\eMule\emule.exe" [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2000-10-16 32768]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-01-21 185896]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-06-30 2376928]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-03-17 157552]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-06-16 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2005-10-31 163840]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-03-02 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programs\\eMule V0.48a\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11280:TCP"= 11280:TCP:BitComet 11280 TCP
"11280:UDP"= 11280:UDP:BitComet 11280 UDP
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [16/05/2009 20:57 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [16/05/2009 20:57 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/06/2009 09:14 114768]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [24/04/2009 18:54 10240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/06/2009 09:14 20560]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX2000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [25/04/2009 10:07 30560]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [22/06/2006 20:23 808448]
S2 gupdate1c9e91accb640cc;Service Google Update (gupdate1c9e91accb640cc);c:\program files\Google\Update\GoogleUpdate.exe [09/06/2009 17:56 133104]
S3 DCamUSBNovatek;CI-8330 USB Video Camera;c:\windows\system32\drivers\nvtcam.sys [28/01/2007 12:53 79872]
S3 jbridgep;jbridgep;\??\c:\docume~1\DOMINI~1\LOCALS~1\Temp\jbridgep.sys --> c:\docume~1\DOMINI~1\LOCALS~1\Temp\jbridgep.sys [?]
S4 Aapiwdsnfsra;Aapiwdsnfsra; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-07-28 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-19 14:35]
2009-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
2009-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.talti.com
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - d:\programs\OFFICE11\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\
FF - prefs.js: browser.search.selectedEngine - Kiwee Live Search
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - plugin: c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin2.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin3.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin4.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin5.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin6.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin7.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-28 12:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3788)
c:\windows\system32\SSSensor.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Sygate\SPF\Smc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-07-28 12:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-28 10:50
ComboFix2.txt 2009-07-28 08:45
Pre-Run: 23 739 383 808 octets libres
Post-Run: 23 632 265 216 octets libres
209 --- E O F --- 2009-07-23 06:14
ComboFix 09-07-27.02 - Dominique Cavuoto 28/07/2009 12:36.2.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.447.131 [GMT 2:00]
Running from: c:\documents and settings\Dominique Cavuoto\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Dominique Cavuoto\Bureau\CFscript.txt
AV: avast! antivirus 4.8.1335 [VPS 090727-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Drivers\nyoht.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_tsxrw
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-28 )))))))))))))))))))))))))))))))
.
2009-07-27 08:18 . 2009-07-27 08:34 -------- d-----w- c:\program files\Navilog1
2009-07-27 08:17 . 2009-07-27 08:17 -------- d-----w- c:\program files\AskBardis
2009-07-27 08:13 . 2009-07-27 08:13 -------- d-----w- c:\program files\CCleaner
2009-07-27 08:06 . 2009-07-27 08:09 -------- d-----w- C:\ToolBar SD
2009-07-27 07:43 . 2009-07-27 07:46 -------- d-----w- C:\rsit
2009-07-24 08:34 . 2009-07-24 08:34 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
2009-07-16 08:08 . 2009-07-16 08:08 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
2009-07-10 15:14 . 2009-07-10 15:13 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1\itstv.exe
2009-07-07 15:31 . 2009-07-07 15:31 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0\itstv.exe
2009-07-02 07:59 . 2009-07-03 05:41 -------- d-----w- C:\!KillBox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 10:44 . 2009-03-23 16:56 -------- d-----w- c:\program files\DNA
2009-07-28 10:44 . 2009-03-23 16:56 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\DNA
2009-07-28 10:12 . 2009-07-28 10:12 1726 ----a-w- c:\program files\xrvrzsb.txt
2009-07-28 10:05 . 2008-10-08 14:52 -------- d-----w- c:\program files\EoRezo
2009-07-28 09:12 . 2007-02-01 15:06 -------- d-----w- c:\program files\Mozilla Thunderbird Beta 2
2009-07-28 09:01 . 2008-10-08 14:52 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo
2009-07-28 05:31 . 2008-10-19 14:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-27 19:22 . 2007-10-26 05:23 -------- d-----w- c:\program files\Trend Micro
2009-07-27 13:28 . 2008-10-19 14:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-27 10:56 . 2009-04-15 15:25 -------- d-----w- c:\program files\LucasArts
2009-07-27 10:56 . 2006-11-17 10:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 09:58 . 2008-10-20 06:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-24 05:28 . 2009-04-24 17:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-18 07:34 . 2009-05-15 14:45 -------- d-----w- c:\program files\free-downloads.net
2009-07-17 17:56 . 2009-03-23 17:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Azureus
2009-07-13 11:36 . 2008-10-20 06:59 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2008-10-20 06:59 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-10 10:54 . 2009-04-24 16:57 -------- d-----w- c:\program files\Windows Live
2009-07-10 10:14 . 2007-10-17 15:30 43536 ----a-w- c:\documents and settings\Dominique Cavuoto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-25 05:58 . 2009-06-25 05:58 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9\itstv.exe
2009-06-17 12:39 . 2009-06-17 12:39 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8\itstv.exe
2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-09 15:57 . 2009-06-09 15:56 -------- d-----w- c:\program files\Google
2009-06-09 12:16 . 2009-06-09 12:16 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
2009-06-06 15:17 . 2009-06-05 16:14 -------- d-----w- c:\program files\Studio-Scrap
2009-06-06 14:06 . 2009-06-05 16:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Studio-Scrap2
2009-06-05 16:31 . 2009-06-05 15:02 -------- d-----w- c:\program files\InstStudio-Scrap
2009-06-03 19:10 . 2006-03-02 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-03 17:07 . 2009-06-03 17:07 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
2009-06-01 16:26 . 2009-06-01 16:26 -------- d-----w- c:\program files\EA GAMES
2009-05-31 06:31 . 2009-04-26 08:23 -------- d-----w- c:\program files\UBISOFT
2009-05-27 07:09 . 2009-05-27 07:09 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
2009-05-16 06:42 . 2009-05-16 06:42 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4\itstv.exe
2009-05-08 18:03 . 2009-05-08 18:03 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3\itstv.exe
2009-05-07 15:33 . 2006-03-02 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 19:26 . 2009-04-25 08:04 258408 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-23 15:20 . 2008-12-22 19:16 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-28_08.42.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-28 10:43 . 2009-07-28 10:43 16384 c:\windows\Temp\Perflib_Perfdata_238.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-07-18 07:35 2215960 ----a-w- c:\program files\free-downloads.net\tbfre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-23 321344]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-06-25 1578736]
"eMuleAutoStart"="d:\programs\eMule V0.48a\eMule\emule.exe" [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2000-10-16 32768]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-01-21 185896]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-06-30 2376928]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-03-17 157552]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-06-16 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2005-10-31 163840]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-03-02 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programs\\eMule V0.48a\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11280:TCP"= 11280:TCP:BitComet 11280 TCP
"11280:UDP"= 11280:UDP:BitComet 11280 UDP
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [16/05/2009 20:57 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [16/05/2009 20:57 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/06/2009 09:14 114768]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [24/04/2009 18:54 10240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/06/2009 09:14 20560]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX2000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [25/04/2009 10:07 30560]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [22/06/2006 20:23 808448]
S2 gupdate1c9e91accb640cc;Service Google Update (gupdate1c9e91accb640cc);c:\program files\Google\Update\GoogleUpdate.exe [09/06/2009 17:56 133104]
S3 DCamUSBNovatek;CI-8330 USB Video Camera;c:\windows\system32\drivers\nvtcam.sys [28/01/2007 12:53 79872]
S3 jbridgep;jbridgep;\??\c:\docume~1\DOMINI~1\LOCALS~1\Temp\jbridgep.sys --> c:\docume~1\DOMINI~1\LOCALS~1\Temp\jbridgep.sys [?]
S4 Aapiwdsnfsra;Aapiwdsnfsra; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-07-28 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-19 14:35]
2009-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
2009-07-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.talti.com
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - d:\programs\OFFICE11\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\
FF - prefs.js: browser.search.selectedEngine - Kiwee Live Search
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - plugin: c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin2.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin3.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin4.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin5.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin6.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin7.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-28 12:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3788)
c:\windows\system32\SSSensor.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Sygate\SPF\Smc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-07-28 12:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-28 10:50
ComboFix2.txt 2009-07-28 08:45
Pre-Run: 23 739 383 808 octets libres
Post-Run: 23 632 265 216 octets libres
209 --- E O F --- 2009-07-23 06:14
hello
désolé de tarder a poster, juste pour te remercier de ton coup de main et pour dire que pour l'instant tt est revenu a la normale plus d'alerte de la part d'avast pas de ralentissement particulier tt est ok
merci encore :)
Peace
Benn
désolé de tarder a poster, juste pour te remercier de ton coup de main et pour dire que pour l'instant tt est revenu a la normale plus d'alerte de la part d'avast pas de ralentissement particulier tt est ok
merci encore :)
Peace
Benn
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 24/06/2009 à 7:10 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 8:29:34, 30/07/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: SONATA2 | Utilisateur actuel: Dominique Cavuoto
.
Administrateur: Administrateur
Administrateur: Dominique Cavuoto
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité *Desactive*
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCU\Software\EoRezo
/!\ NON SUPPRIMÉ - HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKCU\Software\VB and VBA Program Settings\eurobarre
HKU\S-1-5-21-1060284298-308236825-839522115-1004\Software\Binary Noise\mPlayer\kiwee_toolbar_installer.exe
HKCU\Software\AGI
/!\ NON SUPPRIMÉ - HKLM\Software\AGI
.
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\cmhost.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\ConfMedia.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\db
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoStats
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\host.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\user.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\db\cat.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop\config.xml
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop\eoDesktop.html
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop\userConfig.xml
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoStats\eoStats.txt
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Download
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\help_config.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\unins000.dat
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\unins000.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\user_config.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\user_profil.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eobrowserpub
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eoengine
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eobrowserpub\1.0.0.1
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eoengine\9.1.0.0
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.1
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.2
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.2\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome.manifest
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome.manifest.dev
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\install.rdf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\install.rdf.bak
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome\ajtoolbar.jar
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\ask.gif
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\ask.src
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\config.dat
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\config.dat.bak
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\contents.rdf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\snipit.js
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\manifest.mf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\zigbert.rsa
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\zigbert.sf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\bar\Settings
C:\Program Files\AskBarDis\bar\Settings\prevCfg2.htm
C:\Program Files\AskBarDis
C:\Program Files\EoRezo\ConfMedia.cyp
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\eoEngine.url
C:\Program Files\EoRezo\EoMultiLanguage.dll
C:\Program Files\EoRezo\EoRezoComm.dll
C:\Program Files\EoRezo\EoRezoImg_17.dll
C:\Program Files\EoRezo\EoRezoImg_19.dll
C:\Program Files\EoRezo\EoRezoImg_20.dll
C:\Program Files\EoRezo\EoRezoImg_21.dll
C:\Program Files\EoRezo\EoRezoImg_22.dll
C:\Program Files\EoRezo\EoRezoImg_23.dll
C:\Program Files\EoRezo\EoRezoTools_16.dll
C:\Program Files\EoRezo\EoRezoTools_17.dll
C:\Program Files\EoRezo\EoRezoTools_18.dll
C:\Program Files\EoRezo\EoRezoTools_20.dll
C:\Program Files\EoRezo\EoRezoTools_21.dll
C:\Program Files\EoRezo\EoRezoTools_26.dll
C:\Program Files\EoRezo\EoRezoTools_27.dll
C:\Program Files\EoRezo\EoRezoTools_28.dll
C:\Program Files\EoRezo\EoRezoTools_29.dll
C:\Program Files\EoRezo\EoRezoTools_30.dll
C:\Program Files\EoRezo\FreeImage.dll
C:\Program Files\EoRezo\Host.cyp
C:\Program Files\EoRezo\lang
C:\Program Files\EoRezo\MngInstaller.dll
C:\Program Files\EoRezo\unins000.dat
C:\Program Files\EoRezo\unins000.exe
C:\Program Files\EoRezo\user.cyp
C:\Program Files\EoRezo\EoAdv\atl90.dll
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
C:\Program Files\EoRezo\EoAdv\mfc90.dll
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.ATL.manifest
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.CRT.manifest
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.MFC.manifest
C:\Program Files\EoRezo\EoAdv\msvcr90.dll
C:\Program Files\EoRezo\lang\ihm_eoclock.xml
C:\Program Files\EoRezo\lang\ihm_eoengine.xml
C:\Program Files\EoRezo\lang\ihm_eonet.xml
C:\Program Files\EoRezo\lang\ihm_eorezotools.xml
C:\Program Files\EoRezo\lang\ihm_eosudoku.xml
C:\Program Files\EoRezo\lang\ihm_eoweather.xml
C:\Program Files\EoRezo\lang\lang_en.xml
C:\Program Files\EoRezo\lang\lang_es.xml
C:\Program Files\EoRezo\lang\lang_fr.xml
C:\Program Files\EoRezo\lang\lang_it.xml
C:\Program Files\EoRezo
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\config
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\KiweeToolbar
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\logs
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\config\userconfig.cfg
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\KiweeToolbar\config
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\KiweeToolbar\config\appuserconfig.cfg
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\logs\pyagcore.log
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.0.12 *
Nom du profil: 3h2fjo45.default (Dominique Cavuoto)
.
(Prefs.js) user_pref("browser.search.selectedEngine", "Kiwee Live Search");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.12");
.
.
* Internet Explorer Version 6.0.2900.5512 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
C:\Documents and Settings\Dominique Cavuoto\.housecall6.6\patch.exe
.
===================================
.
11791 Octet(s) - C:\Ad-Report-CLEAN.log
.
0 Fichier(s) - C:\DOCUME~1\DOMINI~1\LOCALS~1\Temp
1 Fichier(s) - C:\WINDOWS\Temp
.
34 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
68 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 8:50:30 | 30/07/2009
.
============== E.O.F ==============
.
ComboFix 09-07-29.03 - Dominique Cavuoto 30/07/2009 8:14.3.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.447.196 [GMT 2:00]
Running from: c:\documents and settings\Dominique Cavuoto\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Dominique Cavuoto\Bureau\CFscript.txt
AV: avast! antivirus 4.8.1335 [VPS 090729-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
"c:\docume~1\DOMINI~1\LOCALS~1\Temp\jbridgep.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_JBRIDGEP
-------\Service_jbridgep
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-30 )))))))))))))))))))))))))))))))
.
2009-07-28 11:19 . 2009-07-28 12:25 -------- d-----w- c:\program files\Ad-remover
2009-07-27 08:18 . 2009-07-27 08:34 -------- d-----w- c:\program files\Navilog1
2009-07-27 08:17 . 2009-07-27 08:17 -------- d-----w- c:\program files\AskBardis
2009-07-27 08:13 . 2009-07-27 08:13 -------- d-----w- c:\program files\CCleaner
2009-07-27 08:06 . 2009-07-27 08:09 -------- d-----w- C:\ToolBar SD
2009-07-27 07:43 . 2009-07-27 07:46 -------- d-----w- C:\rsit
2009-07-24 08:34 . 2009-07-24 08:34 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
2009-07-16 08:08 . 2009-07-16 08:08 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
2009-07-10 15:14 . 2009-07-10 15:13 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1\itstv.exe
2009-07-07 15:31 . 2009-07-07 15:31 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0\itstv.exe
2009-07-02 07:59 . 2009-07-03 05:41 -------- d-----w- C:\!KillBox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-30 06:21 . 2009-03-23 16:56 -------- d-----w- c:\program files\DNA
2009-07-30 06:21 . 2009-03-23 16:56 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\DNA
2009-07-30 06:11 . 2007-02-01 15:06 -------- d-----w- c:\program files\Mozilla Thunderbird Beta 2
2009-07-28 10:12 . 2009-07-28 10:12 1726 ----a-w- c:\program files\xrvrzsb.txt
2009-07-28 10:05 . 2008-10-08 14:52 -------- d-----w- c:\program files\EoRezo
2009-07-28 09:01 . 2008-10-08 14:52 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo
2009-07-28 05:31 . 2008-10-19 14:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-27 19:22 . 2007-10-26 05:23 -------- d-----w- c:\program files\Trend Micro
2009-07-27 13:28 . 2008-10-19 14:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-27 10:56 . 2009-04-15 15:25 -------- d-----w- c:\program files\LucasArts
2009-07-27 10:56 . 2006-11-17 10:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 09:58 . 2008-10-20 06:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-24 05:28 . 2009-04-24 17:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-18 07:34 . 2009-05-15 14:45 -------- d-----w- c:\program files\free-downloads.net
2009-07-17 17:56 . 2009-03-23 17:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Azureus
2009-07-13 11:36 . 2008-10-20 06:59 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2008-10-20 06:59 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-10 10:54 . 2009-04-24 16:57 -------- d-----w- c:\program files\Windows Live
2009-07-10 10:14 . 2007-10-17 15:30 43536 ----a-w- c:\documents and settings\Dominique Cavuoto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 16:50 . 2006-03-02 12:00 670720 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 05:58 . 2009-06-25 05:58 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9\itstv.exe
2009-06-17 12:39 . 2009-06-17 12:39 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8\itstv.exe
2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-09 15:57 . 2009-06-09 15:56 -------- d-----w- c:\program files\Google
2009-06-09 12:16 . 2009-06-09 12:16 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
2009-06-06 15:17 . 2009-06-05 16:14 -------- d-----w- c:\program files\Studio-Scrap
2009-06-06 14:06 . 2009-06-05 16:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Studio-Scrap2
2009-06-05 16:31 . 2009-06-05 15:02 -------- d-----w- c:\program files\InstStudio-Scrap
2009-06-03 19:10 . 2006-03-02 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-03 17:07 . 2009-06-03 17:07 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
2009-06-01 16:26 . 2009-06-01 16:26 -------- d-----w- c:\program files\EA GAMES
2009-05-31 06:31 . 2009-04-26 08:23 -------- d-----w- c:\program files\UBISOFT
2009-05-27 07:09 . 2009-05-27 07:09 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
2009-05-16 06:42 . 2009-05-16 06:42 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4\itstv.exe
2009-05-08 18:03 . 2009-05-08 18:03 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3\itstv.exe
2009-05-07 15:33 . 2006-03-02 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 19:26 . 2009-04-25 08:04 258408 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-23 15:20 . 2008-12-22 19:16 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-28_08.42.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-30 06:21 . 2009-07-30 06:21 16384 c:\windows\Temp\Perflib_Perfdata_1a0.dat
- 2009-04-29 06:03 . 2008-07-08 13:03 18296 c:\windows\system32\spmsg.dll
+ 2009-04-29 06:03 . 2009-05-26 11:40 18296 c:\windows\system32\spmsg.dll
- 2009-02-20 08:10 . 2009-04-29 04:34 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2009-02-20 08:10 . 2009-06-26 16:50 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2006-03-02 12:00 . 2009-06-26 16:50 621056 c:\windows\system32\urlmon.dll
- 2006-03-02 12:00 . 2009-04-29 04:34 621056 c:\windows\system32\urlmon.dll
+ 2008-04-21 06:43 . 2009-06-26 16:50 670720 c:\windows\system32\dllcache\wininet.dll
- 2008-04-21 06:43 . 2009-04-29 04:34 670720 c:\windows\system32\dllcache\wininet.dll
+ 2008-06-26 08:13 . 2009-06-26 16:50 621056 c:\windows\system32\dllcache\urlmon.dll
- 2008-06-26 08:13 . 2009-04-29 04:34 621056 c:\windows\system32\dllcache\urlmon.dll
+ 2006-03-02 12:00 . 2009-07-18 16:03 1510400 c:\windows\system32\shdocvw.dll
+ 2006-03-02 12:00 . 2009-07-18 16:03 3090432 c:\windows\system32\mshtml.dll
+ 2008-06-26 08:13 . 2009-07-18 16:03 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-04-21 06:43 . 2009-07-18 16:03 3090432 c:\windows\system32\dllcache\mshtml.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-07-18 07:35 2215960 ----a-w- c:\program files\free-downloads.net\tbfre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-23 321344]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-06-25 1578736]
"eMuleAutoStart"="d:\programs\eMule V0.48a\eMule\emule.exe" [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2000-10-16 32768]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-01-21 185896]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-06-30 2376928]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-03-17 157552]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-06-16 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2005-10-31 163840]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-03-02 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programs\\eMule V0.48a\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11280:TCP"= 11280:TCP:BitComet 11280 TCP
"11280:UDP"= 11280:UDP:BitComet 11280 UDP
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [16/05/2009 20:57 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [16/05/2009 20:57 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/06/2009 09:14 114768]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [24/04/2009 18:54 10240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/06/2009 09:14 20560]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX2000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [25/04/2009 10:07 30560]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [22/06/2006 20:23 808448]
S2 gupdate1c9e91accb640cc;Service Google Update (gupdate1c9e91accb640cc);c:\program files\Google\Update\GoogleUpdate.exe [09/06/2009 17:56 133104]
S3 DCamUSBNovatek;CI-8330 USB Video Camera;c:\windows\system32\drivers\nvtcam.sys [28/01/2007 12:53 79872]
S4 Aapiwdsnfsra;Aapiwdsnfsra; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-07-30 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-19 14:35]
2009-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
2009-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.talti.com
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - d:\programs\OFFICE11\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\
FF - prefs.js: browser.search.selectedEngine - Kiwee Live Search
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - plugin: c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin2.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin3.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin4.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin5.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin6.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin7.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-30 08:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2348)
c:\windows\system32\SSSensor.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Sygate\SPF\Smc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-30 8:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-30 06:26
ComboFix2.txt 2009-07-28 10:50
ComboFix3.txt 2009-07-28 08:45
Pre-Run: 23 451 357 184 octets libres
Post-Run: 23 424 212 992 octets libres
227 --- E O F --- 2009-07-30 06:02
======= RAPPORT D'AD-REMOVER 1.1.4.5_O | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 24/06/2009 à 7:10 PM
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 8:29:34, 30/07/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: SONATA2 | Utilisateur actuel: Dominique Cavuoto
.
Administrateur: Administrateur
Administrateur: Dominique Cavuoto
N'est pas administrateur: HelpAssistant *Desactive*
N'est pas administrateur: Invité *Desactive*
N'est pas administrateur: SUPPORT_388945a0 *Desactive*
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
HKCU\Software\EoRezo
/!\ NON SUPPRIMÉ - HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKCU\Software\VB and VBA Program Settings\eurobarre
HKU\S-1-5-21-1060284298-308236825-839522115-1004\Software\Binary Noise\mPlayer\kiwee_toolbar_installer.exe
HKCU\Software\AGI
/!\ NON SUPPRIMÉ - HKLM\Software\AGI
.
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\cmhost.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\ConfMedia.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\db
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoStats
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\host.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\user.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\db\cat.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop\config.xml
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop\eoDesktop.html
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoDesktop\userConfig.xml
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\eoStats\eoStats.txt
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Download
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\help_config.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\unins000.dat
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\unins000.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\user_config.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\user_profil.cyp
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eobrowserpub
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eoengine
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eobrowserpub\1.0.0.1
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\eoengine\9.1.0.0
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.1
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.2
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.2\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
C:\DOCUME~1\DOMINI~1\APPLIC~1\EoRezo
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome.manifest
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome.manifest.dev
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\install.rdf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\install.rdf.bak
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome\ajtoolbar.jar
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\ask.gif
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\ask.src
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\config.dat
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\config.dat.bak
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\contents.rdf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\snipit.js
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\manifest.mf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\zigbert.rsa
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\zigbert.sf
C:\DOCUME~1\DOMINI~1\APPLIC~1\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\bar\Settings
C:\Program Files\AskBarDis\bar\Settings\prevCfg2.htm
C:\Program Files\AskBarDis
C:\Program Files\EoRezo\ConfMedia.cyp
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\eoEngine.url
C:\Program Files\EoRezo\EoMultiLanguage.dll
C:\Program Files\EoRezo\EoRezoComm.dll
C:\Program Files\EoRezo\EoRezoImg_17.dll
C:\Program Files\EoRezo\EoRezoImg_19.dll
C:\Program Files\EoRezo\EoRezoImg_20.dll
C:\Program Files\EoRezo\EoRezoImg_21.dll
C:\Program Files\EoRezo\EoRezoImg_22.dll
C:\Program Files\EoRezo\EoRezoImg_23.dll
C:\Program Files\EoRezo\EoRezoTools_16.dll
C:\Program Files\EoRezo\EoRezoTools_17.dll
C:\Program Files\EoRezo\EoRezoTools_18.dll
C:\Program Files\EoRezo\EoRezoTools_20.dll
C:\Program Files\EoRezo\EoRezoTools_21.dll
C:\Program Files\EoRezo\EoRezoTools_26.dll
C:\Program Files\EoRezo\EoRezoTools_27.dll
C:\Program Files\EoRezo\EoRezoTools_28.dll
C:\Program Files\EoRezo\EoRezoTools_29.dll
C:\Program Files\EoRezo\EoRezoTools_30.dll
C:\Program Files\EoRezo\FreeImage.dll
C:\Program Files\EoRezo\Host.cyp
C:\Program Files\EoRezo\lang
C:\Program Files\EoRezo\MngInstaller.dll
C:\Program Files\EoRezo\unins000.dat
C:\Program Files\EoRezo\unins000.exe
C:\Program Files\EoRezo\user.cyp
C:\Program Files\EoRezo\EoAdv\atl90.dll
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\EoRezoBho.old
C:\Program Files\EoRezo\EoAdv\mfc90.dll
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.ATL.manifest
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.CRT.manifest
C:\Program Files\EoRezo\EoAdv\Microsoft.VC90.MFC.manifest
C:\Program Files\EoRezo\EoAdv\msvcr90.dll
C:\Program Files\EoRezo\lang\ihm_eoclock.xml
C:\Program Files\EoRezo\lang\ihm_eoengine.xml
C:\Program Files\EoRezo\lang\ihm_eonet.xml
C:\Program Files\EoRezo\lang\ihm_eorezotools.xml
C:\Program Files\EoRezo\lang\ihm_eosudoku.xml
C:\Program Files\EoRezo\lang\ihm_eoweather.xml
C:\Program Files\EoRezo\lang\lang_en.xml
C:\Program Files\EoRezo\lang\lang_es.xml
C:\Program Files\EoRezo\lang\lang_fr.xml
C:\Program Files\EoRezo\lang\lang_it.xml
C:\Program Files\EoRezo
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\config
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\KiweeToolbar
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\logs
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\config\userconfig.cfg
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\KiweeToolbar\config
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\KiweeToolbar\config\appuserconfig.cfg
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi\logs\pyagcore.log
C:\DOCUME~1\DOMINI~1\APPLIC~1\Agi
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
* Mozilla FireFox Version 3.0.12 *
Nom du profil: 3h2fjo45.default (Dominique Cavuoto)
.
(Prefs.js) user_pref("browser.search.selectedEngine", "Kiwee Live Search");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.12");
.
.
* Internet Explorer Version 6.0.2900.5512 *
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
============== Suspect (Cracks, Serials ... ) ==============
.
C:\Documents and Settings\Dominique Cavuoto\.housecall6.6\patch.exe
.
===================================
.
11791 Octet(s) - C:\Ad-Report-CLEAN.log
.
0 Fichier(s) - C:\DOCUME~1\DOMINI~1\LOCALS~1\Temp
1 Fichier(s) - C:\WINDOWS\Temp
.
34 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
68 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 8:50:30 | 30/07/2009
.
============== E.O.F ==============
.
ComboFix 09-07-29.03 - Dominique Cavuoto 30/07/2009 8:14.3.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.447.196 [GMT 2:00]
Running from: c:\documents and settings\Dominique Cavuoto\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Dominique Cavuoto\Bureau\CFscript.txt
AV: avast! antivirus 4.8.1335 [VPS 090729-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
"c:\docume~1\DOMINI~1\LOCALS~1\Temp\jbridgep.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_JBRIDGEP
-------\Service_jbridgep
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-30 )))))))))))))))))))))))))))))))
.
2009-07-28 11:19 . 2009-07-28 12:25 -------- d-----w- c:\program files\Ad-remover
2009-07-27 08:18 . 2009-07-27 08:34 -------- d-----w- c:\program files\Navilog1
2009-07-27 08:17 . 2009-07-27 08:17 -------- d-----w- c:\program files\AskBardis
2009-07-27 08:13 . 2009-07-27 08:13 -------- d-----w- c:\program files\CCleaner
2009-07-27 08:06 . 2009-07-27 08:09 -------- d-----w- C:\ToolBar SD
2009-07-27 07:43 . 2009-07-27 07:46 -------- d-----w- C:\rsit
2009-07-24 08:34 . 2009-07-24 08:34 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.3\itstv.exe
2009-07-16 08:08 . 2009-07-16 08:08 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.2\itstv.exe
2009-07-10 15:14 . 2009-07-10 15:13 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.1\itstv.exe
2009-07-07 15:31 . 2009-07-07 15:31 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.1.0\itstv.exe
2009-07-02 07:59 . 2009-07-03 05:41 -------- d-----w- C:\!KillBox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-30 06:21 . 2009-03-23 16:56 -------- d-----w- c:\program files\DNA
2009-07-30 06:21 . 2009-03-23 16:56 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\DNA
2009-07-30 06:11 . 2007-02-01 15:06 -------- d-----w- c:\program files\Mozilla Thunderbird Beta 2
2009-07-28 10:12 . 2009-07-28 10:12 1726 ----a-w- c:\program files\xrvrzsb.txt
2009-07-28 10:05 . 2008-10-08 14:52 -------- d-----w- c:\program files\EoRezo
2009-07-28 09:01 . 2008-10-08 14:52 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo
2009-07-28 05:31 . 2008-10-19 14:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-27 19:22 . 2007-10-26 05:23 -------- d-----w- c:\program files\Trend Micro
2009-07-27 13:28 . 2008-10-19 14:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-27 10:56 . 2009-04-15 15:25 -------- d-----w- c:\program files\LucasArts
2009-07-27 10:56 . 2006-11-17 10:22 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-27 09:58 . 2008-10-20 06:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-24 05:28 . 2009-04-24 17:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-18 07:34 . 2009-05-15 14:45 -------- d-----w- c:\program files\free-downloads.net
2009-07-17 17:56 . 2009-03-23 17:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Azureus
2009-07-13 11:36 . 2008-10-20 06:59 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 11:36 . 2008-10-20 06:59 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-10 10:54 . 2009-04-24 16:57 -------- d-----w- c:\program files\Windows Live
2009-07-10 10:14 . 2007-10-17 15:30 43536 ----a-w- c:\documents and settings\Dominique Cavuoto\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-26 16:50 . 2006-03-02 12:00 670720 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 05:58 . 2009-06-25 05:58 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.9\itstv.exe
2009-06-17 12:39 . 2009-06-17 12:39 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.8\itstv.exe
2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-09 15:57 . 2009-06-09 15:56 -------- d-----w- c:\program files\Google
2009-06-09 12:16 . 2009-06-09 12:16 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.7\itstv.exe
2009-06-06 15:17 . 2009-06-05 16:14 -------- d-----w- c:\program files\Studio-Scrap
2009-06-06 14:06 . 2009-06-05 16:15 -------- d-----w- c:\documents and settings\Dominique Cavuoto\Application Data\Studio-Scrap2
2009-06-05 16:31 . 2009-06-05 15:02 -------- d-----w- c:\program files\InstStudio-Scrap
2009-06-03 19:10 . 2006-03-02 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-06-03 17:07 . 2009-06-03 17:07 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.6\itstv.exe
2009-06-01 16:26 . 2009-06-01 16:26 -------- d-----w- c:\program files\EA GAMES
2009-05-31 06:31 . 2009-04-26 08:23 -------- d-----w- c:\program files\UBISOFT
2009-05-27 07:09 . 2009-05-27 07:09 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
2009-05-16 06:42 . 2009-05-16 06:42 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.4\itstv.exe
2009-05-08 18:03 . 2009-05-08 18:03 20480 ----a-w- c:\documents and settings\Dominique Cavuoto\Application Data\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.3\itstv.exe
2009-05-07 15:33 . 2006-03-02 12:00 348672 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 19:26 . 2009-04-25 08:04 258408 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-23 15:20 . 2008-12-22 19:16 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-28_08.42.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-30 06:21 . 2009-07-30 06:21 16384 c:\windows\Temp\Perflib_Perfdata_1a0.dat
- 2009-04-29 06:03 . 2008-07-08 13:03 18296 c:\windows\system32\spmsg.dll
+ 2009-04-29 06:03 . 2009-05-26 11:40 18296 c:\windows\system32\spmsg.dll
- 2009-02-20 08:10 . 2009-04-29 04:34 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2009-02-20 08:10 . 2009-06-26 16:50 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2006-03-02 12:00 . 2009-06-26 16:50 621056 c:\windows\system32\urlmon.dll
- 2006-03-02 12:00 . 2009-04-29 04:34 621056 c:\windows\system32\urlmon.dll
+ 2008-04-21 06:43 . 2009-06-26 16:50 670720 c:\windows\system32\dllcache\wininet.dll
- 2008-04-21 06:43 . 2009-04-29 04:34 670720 c:\windows\system32\dllcache\wininet.dll
+ 2008-06-26 08:13 . 2009-06-26 16:50 621056 c:\windows\system32\dllcache\urlmon.dll
- 2008-06-26 08:13 . 2009-04-29 04:34 621056 c:\windows\system32\dllcache\urlmon.dll
+ 2006-03-02 12:00 . 2009-07-18 16:03 1510400 c:\windows\system32\shdocvw.dll
+ 2006-03-02 12:00 . 2009-07-18 16:03 3090432 c:\windows\system32\mshtml.dll
+ 2008-06-26 08:13 . 2009-07-18 16:03 1510400 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-04-21 06:43 . 2009-07-18 16:03 3090432 c:\windows\system32\dllcache\mshtml.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2009-07-18 07:35 2215960 ----a-w- c:\program files\free-downloads.net\tbfre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2009-07-18 2215960]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 139264]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-03-23 321344]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-06-25 1578736]
"eMuleAutoStart"="d:\programs\eMule V0.48a\eMule\emule.exe" [2009-02-22 5668864]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2000-10-16 32768]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-01-21 185896]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-06-30 2376928]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2009-03-17 157552]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-06-16 53248]
"S3Trayp"="S3trayp.exe" - c:\windows\system32\S3Trayp.exe [2005-10-31 163840]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-03-02 577536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programs\\eMule V0.48a\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11280:TCP"= 11280:TCP:BitComet 11280 TCP
"11280:UDP"= 11280:UDP:BitComet 11280 UDP
R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [16/05/2009 20:57 140800]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [16/05/2009 20:57 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [21/06/2009 09:14 114768]
R2 AGWinService;AG Windows Service;c:\program files\AGI\common\win32\pythonservice.exe [24/04/2009 18:54 10240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [21/06/2009 09:14 20560]
R3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX2000/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [25/04/2009 10:07 30560]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [22/06/2006 20:23 808448]
S2 gupdate1c9e91accb640cc;Service Google Update (gupdate1c9e91accb640cc);c:\program files\Google\Update\GoogleUpdate.exe [09/06/2009 17:56 133104]
S3 DCamUSBNovatek;CI-8330 USB Video Camera;c:\windows\system32\drivers\nvtcam.sys [28/01/2007 12:53 79872]
S4 Aapiwdsnfsra;Aapiwdsnfsra; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-07-30 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-19 14:35]
2009-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
2009-07-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-09 15:56]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.talti.com
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - d:\programs\OFFICE11\EXCEL.EXE/3000
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\
FF - prefs.js: browser.search.selectedEngine - Kiwee Live Search
FF - prefs.js: keyword.URL - hxxp://kwtb.search.imgag.com/?c=GNKIW29193&sbs=1&sc=2&f=web&vernum=1.0&uid=&did=f8d4a70c-98e2-4081-901d-01bf93043ede&q=
FF - plugin: c:\documents and settings\Dominique Cavuoto\Application Data\Mozilla\Firefox\Profiles\3h2fjo45.default\extensions\{bb628310-0ab7-11db-9cd8-0800200c9a66}\plugins\nphardwaredetection.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin2.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin3.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin4.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin5.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin6.dll
FF - plugin: d:\programs\Quick Time\Plugins\npqtplugin7.dll
---- FIREFOX POLICIES ----
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-30 08:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2348)
c:\windows\system32\SSSensor.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Sygate\SPF\Smc.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-30 8:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-30 06:26
ComboFix2.txt 2009-07-28 10:50
ComboFix3.txt 2009-07-28 08:45
Pre-Run: 23 451 357 184 octets libres
Post-Run: 23 424 212 992 octets libres
227 --- E O F --- 2009-07-30 06:02
Logfile of random's system information tool 1.06 (written by random/random)
Run by Dominique Cavuoto at 2009-07-30 11:07:59
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 22 GB (45%) free of 50 GB
Total RAM: 447 MB (7% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:30, on 30/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
D:\Programs\eMule V0.48a\eMule\emule.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird Beta 2\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dominique Cavuoto\Bureau\logiciels trojan\RSIT.exe
C:\Program Files\trend micro\Dominique Cavuoto.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [eMuleAutoStart] D:\Programs\eMule V0.48a\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Programs\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1c9e91accb640cc) (gupdate1c9e91accb640cc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - D:\Programs\Nero\Nero v7.2.3b + Keygen\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Run by Dominique Cavuoto at 2009-07-30 11:07:59
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 22 GB (45%) free of 50 GB
Total RAM: 447 MB (7% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:08:30, on 30/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
D:\Programs\eMule V0.48a\eMule\emule.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird Beta 2\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dominique Cavuoto\Bureau\logiciels trojan\RSIT.exe
C:\Program Files\trend micro\Dominique Cavuoto.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfre0.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [eMuleAutoStart] D:\Programs\eMule V0.48a\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Programs\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1c9e91accb640cc) (gupdate1c9e91accb640cc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - D:\Programs\Nero\Nero v7.2.3b + Keygen\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
ok le rapport est incomplet de rsit :) mais bon sur cette partie
sinon mets a jour internet explorer avec la version 7 ou 8
et
Mettre a jour java:
https://javara.fr.malavida.com/indows
Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.
si cela ne fonctionne pas
https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80
tu peux désinstaller les vieilles versions.
______________
lance tool cleaner pour virer ce qui a été utilisé:
https://www.commentcamarche.net/telecharger/
______________
désactive ta restauration puis redemarre ton pc puis réactive la:
https://www.informatruc.com
voilà c'est bon
pour protéger gratos ton ordi
https://www.commentcamarche.net/telecharger/
mettre un antivirus
ANTIVIR ou AVG8 ou (AVAST)
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
MALWAREBYTE ANTIMALWARE + SPYBOT
+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
--------
un pare feu :
(celui de Windows) ou mieux COMODO ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)
http://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-e(...)
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
https://www.commentcamarche.net/telecharger/ 157 zonealarm
-----------
CCLEANER pour effacer les traces de surf
sinon mets a jour internet explorer avec la version 7 ou 8
et
Mettre a jour java:
https://javara.fr.malavida.com/indows
Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
Double-clique sur le répertoire JavaRa obtenu.
Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
Clique sur Search For Updates.
Sélectionne Update Using jucheck.exe puis clique sur Search.
Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
(c:\JavaRa.log)
Ferme l'application.
si cela ne fonctionne pas
https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80
tu peux désinstaller les vieilles versions.
______________
lance tool cleaner pour virer ce qui a été utilisé:
https://www.commentcamarche.net/telecharger/
______________
désactive ta restauration puis redemarre ton pc puis réactive la:
https://www.informatruc.com
voilà c'est bon
pour protéger gratos ton ordi
https://www.commentcamarche.net/telecharger/
mettre un antivirus
ANTIVIR ou AVG8 ou (AVAST)
https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
-------------
des anti-espions :
MALWAREBYTE ANTIMALWARE + SPYBOT
+
SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...
--------
un pare feu :
(celui de Windows) ou mieux COMODO ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)
http://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-e(...)
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
https://www.commentcamarche.net/telecharger/ 157 zonealarm
-----------
CCLEANER pour effacer les traces de surf
Logfile of random's system information tool 1.06 (written by random/random)
Run by Dominique Cavuoto at 2009-07-30 11:32:13
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 23 GB (45%) free of 50 GB
Total RAM: 447 MB (14% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:34, on 30/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
D:\Programs\eMule V0.48a\eMule\emule.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird Beta 2\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dominique Cavuoto\Bureau\logiciels trojan\RSIT.exe
C:\Program Files\trend micro\Dominique Cavuoto.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [eMuleAutoStart] D:\Programs\eMule V0.48a\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Programs\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1c9e91accb640cc) (gupdate1c9e91accb640cc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - D:\Programs\Nero\Nero v7.2.3b + Keygen\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Run by Dominique Cavuoto at 2009-07-30 11:32:13
Microsoft Windows XP Professionnel Service Pack 3
System drive C: has 23 GB (45%) free of 50 GB
Total RAM: 447 MB (14% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:34, on 30/07/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\rmctrl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
D:\Programs\eMule V0.48a\eMule\emule.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Thunderbird Beta 2\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dominique Cavuoto\Bureau\logiciels trojan\RSIT.exe
C:\Program Files\trend micro\Dominique Cavuoto.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - C:\Program Files\Xi\NetTransport 2\NTIEHelper.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [S3Trayp] S3trayp.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\system32\rmctrl.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [eMuleAutoStart] D:\Programs\eMule V0.48a\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Programs\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1c9e91accb640cc) (gupdate1c9e91accb640cc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - D:\Programs\Nero\Nero v7.2.3b + Keygen\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe