Win 32 - Page 2

  1. Le scan me dit qu'il est impossible de faire la mise à jour , vérifier les paramétres proxy
    0
    1. je réessaye , on vera bien si sa marche , j'espere que tu est toujours là ...
      0
      1. cela ne marche toujour pas , le scan en ligne
        0
        1. le site ne marche pas , quand je veut faire la mise à jour , peut etre que je peut te posté le rapport de spyware terminator ?
          0
          1. Contributeur
            [*] Télécharge combofix (sUBs) http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton Bureau
            [*] Double clique combofix.exe et suis les instructions.
            [*] Installe la console de récupération si proposé et continue.
            [*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

            NOTE : Le rapport se trouve également ici : C:\Combofix.txt
            0
            1. voila le rapport :

              ComboFix 09-08-01.06 - Sonia 02/08/2009 13:42.1.2 - NTFSx86
              Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.2942.1875 [GMT 2:00]
              Running from: c:\users\Sonia\Desktop\ComboFix.exe
              SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
              .

              ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              c:\$recycle.bin\S-1-5-21-2373954164-2419952531-494492721-500
              c:\$recycle.bin\S-1-5-21-2908564048-2523520018-2590238898-500
              c:\$recycle.bin\S-1-5-21-379578684-575248035-2863804450-1000

              .
              ((((((((((((((((((((((((( Files Created from 2009-07-02 to 2009-08-02 )))))))))))))))))))))))))))))))
              .

              2009-08-02 11:31 . 2009-08-02 11:31 -------- d-----w- c:\programdata\Apple
              2009-08-02 11:31 . 2009-08-02 11:31 -------- d-----w- c:\program files\Apple Software Update
              2009-08-02 10:33 . 2007-05-02 14:31 90624 ----a-w- c:\windows\system32\nmwcdcls.dll
              2009-08-02 10:33 . 2009-08-02 10:33 -------- d-----w- c:\program files\DIFX
              2009-08-02 10:33 . 2007-09-17 13:53 21632 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
              2009-08-02 10:33 . 2009-08-02 10:33 -------- dc----w- c:\windows\system32\DRVSTORE
              2009-08-02 10:32 . 2009-03-20 08:01 90112 ----a-w- c:\windows\system32\drivers\ss_bbus.sys
              2009-08-02 10:32 . 2009-03-20 08:01 14976 ----a-w- c:\windows\system32\drivers\ss_bmdfl.sys
              2009-08-02 10:32 . 2009-03-20 08:01 121856 ----a-w- c:\windows\system32\drivers\ss_bmdm.sys
              2009-08-02 10:32 . 2009-03-20 08:01 12160 ----a-w- c:\windows\system32\drivers\ss_bwhnt.sys
              2009-08-02 10:32 . 2009-03-20 08:01 12160 ----a-w- c:\windows\system32\drivers\ss_bwh.sys
              2009-08-02 10:32 . 2009-03-20 08:01 12160 ----a-w- c:\windows\system32\drivers\ss_bcmnt.sys
              2009-08-02 10:32 . 2009-03-20 08:01 12160 ----a-w- c:\windows\system32\drivers\ss_bcm.sys
              2009-08-02 10:32 . 2009-03-31 07:39 36608 ----a-w- c:\windows\system32\FsUsbExDisk.Sys
              2009-08-02 10:32 . 2009-03-31 07:39 233472 ----a-w- c:\windows\system32\FsUsbExService.Exe
              2009-08-02 10:32 . 2009-03-31 07:39 110592 ----a-w- c:\windows\system32\FsUsbExDevice.Dll
              2009-08-02 10:31 . 2009-08-02 10:31 -------- d-----w- c:\program files\MarkAny
              2009-08-02 10:29 . 2009-08-02 10:29 -------- d-----w- c:\users\Sonia\AppData\Local\Downloaded Installations
              2009-08-01 22:34 . 2009-08-01 22:34 -------- d-----w- c:\windows\Sun
              2009-08-01 21:59 . 2009-08-01 21:59 -------- d-----w- c:\program files\ESET
              2009-08-01 21:30 . 2009-08-01 21:30 -------- d-----w- c:\program files\Trend Micro
              2009-08-01 21:14 . 2009-08-02 07:34 -------- d-----w- C:\ToolBar SD
              2009-08-01 20:58 . 2009-08-01 21:11 -------- d-----w- c:\program files\Navilog1
              2009-08-01 20:33 . 2009-08-02 11:24 -------- d-----w- C:\FindyKill
              2009-08-01 20:30 . 2009-08-01 20:44 -------- d-----w- C:\GenProc
              2009-08-01 19:58 . 2009-08-01 19:58 -------- d-----w- c:\users\Sonia\AppData\Local\HP
              2009-08-01 19:05 . 2009-08-01 19:05 -------- d-----w- c:\program files\4Media
              2009-08-01 14:51 . 2009-08-01 14:51 -------- d-----w- c:\users\Sonia\AppData\Roaming\WindSolutions
              2009-07-31 16:43 . 2009-07-31 16:43 -------- dcsh--w- c:\program files\Common Files\WindowsLiveInstaller
              2009-07-31 16:43 . 2009-07-31 16:43 -------- d-----w- c:\program files\Windows Live
              2009-07-31 16:42 . 2009-07-31 16:55 -------- d-----w- c:\programdata\WLInstaller
              2009-07-27 20:45 . 2009-07-27 20:45 -------- d-----w- c:\users\Sonia\AppData\Roaming\Spacejock Software
              2009-07-27 18:06 . 2009-07-29 18:58 -------- d-----w- c:\users\Sonia\AppData\Roaming\IDM
              2009-07-27 11:52 . 2009-07-27 11:52 -------- d-----w- c:\program files\FP
              2009-07-27 11:03 . 2009-07-29 18:58 -------- d-----w- c:\users\Sonia\AppData\Roaming\DMCache
              2009-07-26 19:06 . 2009-07-26 19:06 -------- d-----w- c:\users\Sonia\AppData\Roaming\BitSpirit
              2009-07-26 18:34 . 2009-07-26 18:34 -------- d-----w- c:\users\Sonia\AppData\Local\Ares
              2009-07-24 14:09 . 2009-07-24 14:09 -------- d-----w- c:\programdata\Azureus
              2009-07-24 14:09 . 2009-08-01 21:15 -------- d-----w- c:\users\Sonia\AppData\Roaming\Azureus
              2009-07-24 13:46 . 2009-07-24 13:46 -------- d-----w- c:\program files\DivX
              2009-07-23 11:34 . 2009-07-31 08:26 -------- d-----w- c:\programdata\eMule
              2009-07-23 11:34 . 2009-07-31 08:26 -------- d-----w- c:\users\Sonia\AppData\Local\eMule
              2009-07-22 12:33 . 2009-07-22 12:33 -------- d-----w- c:\users\Sonia\AppData\Local\Deployment
              2009-07-22 12:33 . 2009-07-22 12:33 -------- d-----w- c:\users\Sonia\AppData\Local\Apps
              2009-07-20 19:06 . 2009-07-21 11:36 -------- d-----w- c:\program files\Free Download Manager
              2009-07-20 14:30 . 2009-07-24 13:47 -------- d-----w- c:\program files\Google
              2009-07-20 14:02 . 2009-07-22 10:57 -------- d-----w- c:\programdata\NOS
              2009-07-20 14:02 . 2009-07-22 10:57 -------- d-----w- c:\program files\NOS
              2009-07-09 15:54 . 2009-07-09 15:54 -------- d-----w- c:\programdata\PC Suite
              2009-07-09 15:54 . 2009-07-09 15:54 -------- d-----w- c:\users\Sonia\AppData\Roaming\PC Suite
              2009-07-04 17:38 . 2009-08-02 10:33 -------- d-----w- c:\program files\PC Connectivity Solution

              .
              (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2009-08-02 11:22 . 2008-08-26 20:24 442628 ----a-w- c:\windows\system32\perfc00C.dat
              2009-08-02 11:22 . 2008-08-26 20:24 1621466 ----a-w- c:\windows\system32\perfh00C.dat
              2009-08-02 10:33 . 2008-12-25 07:57 -------- d-----w- c:\program files\Samsung
              2009-08-02 10:31 . 2008-08-26 10:56 -------- d--h--w- c:\program files\InstallShield Installation Information
              2009-08-02 10:21 . 2008-12-25 12:14 -------- d-----w- c:\program files\Spyware Terminator
              2009-08-02 10:19 . 2009-02-06 10:17 -------- d-----w- c:\users\Sonia\AppData\Roaming\vlc
              2009-08-02 10:19 . 2009-06-08 10:46 -------- d-----w- c:\users\Sonia\AppData\Roaming\dvdcss
              2009-08-02 10:19 . 2008-12-27 12:54 -------- d-----w- c:\programdata\Spybot - Search & Destroy
              2009-08-02 10:19 . 2008-12-26 16:03 -------- d-----w- c:\program files\DAEMON Tools Toolbar
              2009-08-02 10:19 . 2008-12-25 12:14 -------- d-----w- c:\programdata\Spyware Terminator
              2009-08-02 10:19 . 2008-08-26 11:06 -------- d-----w- c:\programdata\muvee Technologies
              2009-08-02 08:03 . 2008-12-25 12:14 -------- d-----w- c:\users\Sonia\AppData\Roaming\Spyware Terminator
              2009-07-12 13:09 . 2008-12-26 09:31 330 ----a-w- c:\users\Sonia\AppData\Roaming\wklnhst.dat
              2009-07-04 17:39 . 2009-01-15 19:08 -------- d-----w- c:\users\Sonia\AppData\Roaming\Samsung
              2008-08-26 20:38 . 2008-08-26 20:38 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
              .

              ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* empty entries & legit default entries are not shown
              REGEDIT4

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
              "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2008-07-03 972080]
              "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
              "E06FXLRD_1771734"="c:\program files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE" [2005-06-04 301776]
              "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
              "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-04-02 102400]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
              "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
              "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
              "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
              "HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
              "DPService"="c:\program files\HP\DVDPlay\DPService.exe" [2008-06-11 90112]
              "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
              "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
              "EnableLUA"= 0 (0x0)
              "EnableUIADesktopToggle"= 0 (0x0)
              "HideFastUserSwitching"= 0 (0x0)

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
              "aux"=wdmaud.drv

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
              @="Service"

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
              "DisableMonitoring"=dword:00000001

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
              "DisableMonitoring"=dword:00000001

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
              "DisableMonitoring"=dword:00000001

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
              "AntiSpywareOverride"=dword:00000001

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
              "{A49E70DD-C56A-4CBA-836A-81F7233A523E}"= c:\program files\HP\DVDPlay\DVDPlay.exe:DVD Play
              "{50F67E86-7DDD-4527-81CB-F3A6865A0983}"= c:\program files\HP\DVDPlay\DPService.exe:DVD Play Resident Program
              "{63A82F3F-D06E-4A04-A85C-EE77EAB60F63}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
              "{39E9487A-3C78-4188-B2EB-CE27480D5148}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
              "{78F6AE29-AF79-4926-9FEA-E98D3C23CDEE}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
              "{C3C65A77-0B0B-46E3-B5C6-18C0769E71BE}"= UDP:c:\program files\Samsung\Samsung New PC Studio\npsasvr.exe:KTF MUSIC AoD Server
              "{EC7E058A-38C5-4E87-8112-AED9D742A2AA}"= TCP:c:\program files\Samsung\Samsung New PC Studio\npsasvr.exe:KTF MUSIC AoD Server
              "{295FE4C7-ABD9-4113-ADCC-A4E8DDBB0D79}"= UDP:c:\program files\Samsung\Samsung New PC Studio\npsvsvr.exe:KTF MUSIC VoD Server
              "{E92AE534-36AF-4638-968F-616B57CD5D12}"= TCP:c:\program files\Samsung\Samsung New PC Studio\npsvsvr.exe:KTF MUSIC VoD Server

              R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [25/12/2008 14:14 142464]
              R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 04:33 21504]
              R2 FsUsbExService;FsUsbExService;c:\windows\System32\FsUsbExService.Exe [02/08/2009 12:32 233472]
              R3 FsUsbExDisk;FsUsbExDisk;c:\windows\System32\FsUsbExDisk.Sys [02/08/2009 12:32 36608]
              R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\System32\drivers\ss_bbus.sys [02/08/2009 12:32 90112]
              R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\System32\drivers\ss_bmdfl.sys [02/08/2009 12:32 14976]
              R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\System32\drivers\ss_bmdm.sys [02/08/2009 12:32 121856]
              S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\magix\Common\Database\bin\fbserver.exe [03/02/2009 22:32 1527900]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
              LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
              ezSharedSvc
              .
              Contents of the 'Scheduled Tasks' folder

              2009-08-02 c:\windows\Tasks\User_Feed_Synchronization-{6CE793BF-5885-41FE-B86D-17CC3087304E}.job
              - c:\windows\system32\msfeedssync.exe [2008-01-21 02:34]
              .
              - - - - ORPHANS REMOVED - - - -

              HKLM-Run-NPSStartup - (no file)

              .
              ------- Supplementary Scan -------
              .
              uStart Page = hxxp://www.google.fr/
              mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=84&bd=Presario&pf=cndt
              IE: &Recherche AOL Toolbar - c:\programdata\AOL\ieToolbar\resources\fr-FR\local\search.html
              TCP: {1EA064FB-4276-4940-9BED-AD107A98E568} = 62.201.129.99
              .

              **************************************************************************

              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2009-08-02 13:46
              Windows 6.0.6001 Service Pack 1 NTFS

              scanning hidden processes ...

              scanning hidden autostart entries ...

              scanning hidden files ...

              scan completed successfully
              hidden files: 0

              **************************************************************************
              .
              --------------------- LOCKED REGISTRY KEYS ---------------------

              [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
              @Denied: (A) (Users)
              @Denied: (A) (Everyone)
              @Allowed: (B 1 2 3 4 5) (S-1-5-20)
              "BlindDial"=dword:00000000
              .
              --------------------- DLLs Loaded Under Running Processes ---------------------

              - - - - - - - > 'Explorer.exe'(2392)
              c:\program files\Samsung\Samsung New PC Studio\NPSArbiter.dll
              c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              .
              Completion time: 2009-08-02 13:48
              ComboFix-quarantined-files.txt 2009-08-02 11:48

              Pre-Run: 214 243 618 816 octets libres
              Post-Run: 214 364 299 264 octets libres

              185
              0
              1. arrivé à 99 % le site me dit qu'il y a eu une erreur :/
                0
                1. personne ne peut m'aider
                  0
                  1. Contributeur sécurité
                    Hello à tous,

                    @Narco4: Si tu trouves une info ou deux ici...

                    Bonne continuation.
                    Bye.
                    0
                    Précédent
                    • 1
                    • 2