Aidez-moi ! Virus !
Résolu
Fred-du-81
Messages postés
212
Date d'inscription
Statut
Membre
Dernière intervention
-
Fred-du-81 Messages postés 212 Date d'inscription Statut Membre Dernière intervention -
Fred-du-81 Messages postés 212 Date d'inscription Statut Membre Dernière intervention -
Bonjour,
j'ai un virus qui se lance a chaque démarrage de mon PC c'est quelquechose genre gmlidrtgdmxm.exe et il lance une sorte d'analyse antivirus et je ne peut plus ouvrir le gestionnaire des taches ( il le ferme ) pareil pour mon ativirus ... Comment faire ?
j'ai un virus qui se lance a chaque démarrage de mon PC c'est quelquechose genre gmlidrtgdmxm.exe et il lance une sorte d'analyse antivirus et je ne peut plus ouvrir le gestionnaire des taches ( il le ferme ) pareil pour mon ativirus ... Comment faire ?
A voir également:
- Aidez-moi ! Virus !
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Undisclosed-recipients virus - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Altruistic virus ✓ - Forum Antivirus
34 réponses
Voila :
ComboFix 10-02-07.02 - HP_Propriétaire 07/02/2010 20:41:30.1.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1534.1135 [GMT 1:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Fast Browser Search
c:\windows\system32\ps2.bat
D:\Autorun.inf
Z:\install.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-07 au 2010-02-07 ))))))))))))))))))))))))))))))))))))
.
2010-02-07 13:57 . 2010-02-07 13:57 -------- d-----w- C:\ERDNT
2010-01-30 12:46 . 2010-01-30 12:46 -------- d-----w- c:\windows\system32\xlive
2010-01-30 12:46 . 2010-01-30 12:47 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-30 12:45 . 2010-01-30 12:45 -------- d-----w- c:\windows\6833245EDD86479A882A8360D62C8194.TMP
2010-01-30 12:31 . 2010-01-30 12:31 -------- d-----w- c:\program files\Eidos
2010-01-30 12:23 . 2010-01-30 12:23 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-30 12:21 . 2010-01-30 12:22 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-01-30 08:09 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 08:09 . 2010-01-30 08:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 08:09 . 2010-01-30 08:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-30 08:09 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-30 07:56 . 2010-01-30 07:56 -------- d-----w- C:\_OTM
2010-01-30 07:45 . 2010-01-30 07:49 -------- d-----w- C:\rsit
2010-01-23 23:25 . 2010-01-23 23:27 -------- d-----w- c:\program files\NVIDIA Corporation
2010-01-23 23:25 . 2010-01-12 04:03 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-23 23:25 . 2010-01-12 04:03 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-23 23:25 . 2010-01-12 04:03 14458880 ----a-w- c:\windows\system32\nvoglnt.dll
2010-01-23 23:25 . 2010-01-12 04:03 4104192 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-23 23:25 . 2010-01-12 04:03 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-23 23:25 . 2010-01-12 04:03 182888 ----a-w- c:\windows\system32\nvcodins.dll
2010-01-23 23:25 . 2010-01-12 04:03 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-23 23:25 . 2010-01-12 04:03 11632640 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-23 23:25 . 2010-01-12 04:03 1081344 ----a-w- c:\windows\system32\nvapi.dll
2010-01-23 23:25 . 2010-01-12 04:03 2283526 ----a-w- c:\windows\system32\nvdata.bin
2010-01-18 22:08 . 2010-01-18 22:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2010-01-16 10:44 . 2010-01-16 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2010-01-13 11:23 . 2009-11-21 15:58 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 14:09 . 2009-12-28 13:34 -------- d-----w- c:\program files\Steam
2010-01-31 09:12 . 2009-04-07 12:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-30 12:45 . 2008-12-08 17:38 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2010-01-30 12:31 . 2005-01-02 04:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-30 12:23 . 2009-11-28 12:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-30 07:49 . 2009-04-07 10:45 -------- d-----w- c:\program files\trend micro
2010-01-29 19:36 . 2009-04-08 15:19 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-01-29 19:36 . 2009-04-08 09:45 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-01-24 01:17 . 2009-04-25 10:24 -------- d-----w- c:\program files\Warcraft III
2010-01-24 00:50 . 2009-04-25 10:27 160315 ----a-w- c:\windows\War3Unin.dat
2010-01-23 23:26 . 2008-12-08 17:38 -------- d-----w- c:\program files\AGEIA Technologies
2010-01-23 14:52 . 2009-05-19 19:04 -------- d-----w- c:\program files\WeGame
2010-01-21 09:30 . 2008-12-17 14:07 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-19 20:20 . 2008-12-28 16:00 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-01-18 22:19 . 2008-12-11 17:31 -------- d-----w- c:\program files\Fichiers communs\Blizzard Entertainment
2010-01-12 04:03 . 2005-01-02 04:26 10276768 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-12 04:03 . 2005-01-02 04:26 6359168 ----a-w- c:\windows\system32\nv4_disp.dll
2009-12-29 17:29 . 2009-12-29 17:29 -------- d-----w- c:\program files\GigaTribe
2009-12-24 07:06 . 2005-01-02 05:03 -------- d-----w- c:\program files\Google
2009-12-23 22:09 . 2009-11-25 10:03 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-22 22:04 . 2009-12-22 22:04 -------- d-----w- c:\program files\Avira
2009-12-22 22:04 . 2009-11-25 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-21 19:07 . 2004-08-05 18:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 18:06 . 2009-07-01 11:22 -------- d-----w- c:\program files\Diablo II
2009-12-16 17:07 . 2009-12-16 17:07 -------- d-----w- c:\program files\Total Immersion
2009-12-14 12:21 . 2004-11-23 21:26 85744 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-14 12:21 . 2004-11-23 21:26 512206 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-13 17:26 . 2009-12-13 17:26 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-13 17:26 . 2009-12-13 17:26 -------- d-----w- c:\program files\VSO
2009-12-13 16:17 . 2009-05-11 09:53 -------- d-----w- c:\program files\EA GAMES
2009-11-30 19:33 . 2009-11-30 19:33 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-11-27 22:55 . 2009-11-27 22:55 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-11-27 22:55 . 2009-11-27 22:55 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-11-23 19:13 . 2009-11-23 19:13 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-11-21 15:58 . 2004-08-05 18:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 21:42 . 2009-11-16 21:43 40672 ----a-w- c:\windows\system32\drivers\CESG502.SYS
2005-12-17 02:32 . 2008-12-09 00:49 22 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"RamBoostXp"="z:\program files\RamBoost XP\rambxpfr.exe" [2004-03-09 1542144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]
"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"phc710"="c:\windows\vphc700.exe" [2005-07-20 339968]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-03-11 86016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-11 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
c:\documents and settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\HP_Propri‚taire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-17 143360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^TrayMin710.exe.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\TrayMin710.exe.lnk
backup=c:\windows\pss\TrayMin710.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^GigaTribe.lnk]
path=c:\documents and settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\GigaTribe.lnk
backup=c:\windows\pss\GigaTribe.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^LimeWire On Startup.lnk]
path=c:\documents and settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^Xfire.lnk]
path=c:\documents and settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
2007-06-29 13:03 36864 ----a-w- c:\program files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-06-08 21:42 14565376 ----a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-12-28 13:35 1217808 ----a-w- c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-28 21:12 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"z:\\Program Files\\uTorrent\\uTorrent.exe"=
"z:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"z:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3sp.exe"=
"c:\\Program Files\\Services en ligne\\AOL\\InstallAol.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2ServerLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2BenchmarkTool.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"z:\\WOW 3.2.2\\World of Warcraft 3.2.2\\Launcher.exe"=
"z:\\WOW 3.2.2\\World of Warcraft 3.2.2\\WoW-3.1.3.9947-to-3.2.0.10192-frFR-downloader.exe"=
"z:\\WOW 3.2.2\\World of Warcraft 3.2.2\\Repair.exe"=
"c:\\Program Files\\GigaTribe\\gigatribe.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Eidos\\Batman Arkham Asylum\\Binaries\\ShippingPC-BmGame.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3074:UDP"= 3074:UDP:CoD5 UDP1
"28960:UDP"= 28960:UDP:CoD5 UDP2
"28960:TCP"= 28960:TCP:CoD5 TCP
"7777:TCP"= 7777:TCP:Borderlands
"7777:UDP"= 7777:UDP:Borderlands UDP
"28900:TCP"= 28900:TCP:Borderlands TCP
"27900:UDP"= 27900:UDP:Borderlands UDP
"28910:TCP"= 28910:TCP:Borederlands TCP
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [22/12/2009 23:04 108289]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [22/02/2009 13:14 54752]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [02/01/2005 05:26 2786176]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/11/2009 13:32 691696]
S2 gupdate1c9dfd914fb67cc;Service Google Update (gupdate1c9dfd914fb67cc);c:\program files\Google\Update\GoogleUpdate.exe [28/05/2009 22:13 133104]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [17/11/2008 08:05 195752]
S3 phc700;USB PC Camera (phc710);c:\windows\system32\drivers\phc700.sys [19/12/2008 22:14 541568]
S3 phc710;USB PC Camera (SPC710NC);c:\windows\system32\DRIVERS\phc710.sys --> c:\windows\system32\DRIVERS\phc710.sys [?]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\drivers\whfltr2k.sys [25/01/2007 16:45 6784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenu du dossier 'Tâches planifiées'
2010-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-28 21:12]
2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-28 21:12]
2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-28 21:12]
2010-01-28 c:\windows\Tasks\HPCeeSchedule.job
- c:\progra~1\EASYIN~1\Ceement\HPCEE.exe [2005-06-13 16:41]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.ask.com?o=15161&l=dis
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\7j7ys1ao.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5422FC88-1C6C-E69F-EC02-547510324457}&q=
FF - component: c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\7j7ys1ao.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: c:\program files\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-RAMBooster.Net - c:\program files\RAMBooster.Net\RAMBooster.exe
HKLM-Run-nwiz - nwiz.exe
MSConfigStartUp-Alcmtr - ALCMTR.EXE
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe
AddRemove-Fx-Interface_is1 - z:\program files\CASIO\Fx-Interface\unins000.exe
AddRemove-Homeworld2 - c:\program files\Sierra\Homeworld2\uninstall.exe
AddRemove-Wow Cartographe - c:\program files\WowCartographe\uninst.exe
AddRemove-{14B380D6-8205-4F9D-81D8-515235929F2A}_is1 - z:\documents and settings\HP_Propriétaire\Local Settings\Application Data\Dictionnaire Freelang\unins001.exe
AddRemove-{B53353EA-7724-4654-8DFF-674F3E08623C}_is1 - z:\program files\World of Warcraft\Program Files\unins000.exe
AddRemove-{F53C4192-71DE-4B21-BE03-D6F8CBB5A238}_is1 - z:\documents and settings\HP_Propriétaire\Local Settings\Application Data\Dictionnaire Freelang\unins000.exe
AddRemove-BattleDirector - c:\program files\The Sir. Community\BattleDirector\uninstall.exe
AddRemove-Live Search - c:\documents and settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Suppression-Live-Search.exe
AddRemove-Naggarythe Online Launcher - c:\program files\World of warcraft\Uninstal.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-07 20:47
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1465579271-3616371518-2648195347-1008\Software\SecuROM\License information*]
"datasecu"=hex:82,e3,38,27,08,40,0f,2e,9e,3c,8d,b4,a6,2b,a9,8a,b7,26,29,ef,6d,
e0,a7,1c,28,fe,09,ea,cc,7f,b2,4c,a6,6e,cb,6d,a1,9f,27,15,75,e8,30,1f,cb,71,\
"rkeysecu"=hex:e7,30,32,08,a4,63,a1,ea,b1,67,56,c5,77,4e,31,c4
.
Heure de fin: 2010-02-07 20:49:25
ComboFix-quarantined-files.txt 2010-02-07 19:49
Avant-CF: 66 392 367 104 octets libres
Après-CF: 66 380 079 104 octets libres
- - End Of File - - 2502DB5F1BD64F1EDD4B5BFCD510CAF3
ComboFix 10-02-07.02 - HP_Propriétaire 07/02/2010 20:41:30.1.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1534.1135 [GMT 1:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Fast Browser Search
c:\windows\system32\ps2.bat
D:\Autorun.inf
Z:\install.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-07 au 2010-02-07 ))))))))))))))))))))))))))))))))))))
.
2010-02-07 13:57 . 2010-02-07 13:57 -------- d-----w- C:\ERDNT
2010-01-30 12:46 . 2010-01-30 12:46 -------- d-----w- c:\windows\system32\xlive
2010-01-30 12:46 . 2010-01-30 12:47 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-30 12:45 . 2010-01-30 12:45 -------- d-----w- c:\windows\6833245EDD86479A882A8360D62C8194.TMP
2010-01-30 12:31 . 2010-01-30 12:31 -------- d-----w- c:\program files\Eidos
2010-01-30 12:23 . 2010-01-30 12:23 -------- d-----w- c:\program files\DAEMON Tools Lite
2010-01-30 12:21 . 2010-01-30 12:22 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-01-30 08:09 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 08:09 . 2010-01-30 08:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-30 08:09 . 2010-01-30 08:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-30 08:09 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-30 07:56 . 2010-01-30 07:56 -------- d-----w- C:\_OTM
2010-01-30 07:45 . 2010-01-30 07:49 -------- d-----w- C:\rsit
2010-01-23 23:25 . 2010-01-23 23:27 -------- d-----w- c:\program files\NVIDIA Corporation
2010-01-23 23:25 . 2010-01-12 04:03 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-23 23:25 . 2010-01-12 04:03 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-23 23:25 . 2010-01-12 04:03 14458880 ----a-w- c:\windows\system32\nvoglnt.dll
2010-01-23 23:25 . 2010-01-12 04:03 4104192 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-23 23:25 . 2010-01-12 04:03 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-23 23:25 . 2010-01-12 04:03 182888 ----a-w- c:\windows\system32\nvcodins.dll
2010-01-23 23:25 . 2010-01-12 04:03 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-23 23:25 . 2010-01-12 04:03 11632640 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-23 23:25 . 2010-01-12 04:03 1081344 ----a-w- c:\windows\system32\nvapi.dll
2010-01-23 23:25 . 2010-01-12 04:03 2283526 ----a-w- c:\windows\system32\nvdata.bin
2010-01-18 22:08 . 2010-01-18 22:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard Entertainment
2010-01-16 10:44 . 2010-01-16 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2010-01-13 11:23 . 2009-11-21 15:58 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 14:09 . 2009-12-28 13:34 -------- d-----w- c:\program files\Steam
2010-01-31 09:12 . 2009-04-07 12:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-30 12:45 . 2008-12-08 17:38 -------- d-----w- c:\program files\Fichiers communs\Wise Installation Wizard
2010-01-30 12:31 . 2005-01-02 04:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-30 12:23 . 2009-11-28 12:32 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-01-30 07:49 . 2009-04-07 10:45 -------- d-----w- c:\program files\trend micro
2010-01-29 19:36 . 2009-04-08 15:19 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-01-29 19:36 . 2009-04-08 09:45 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-01-24 01:17 . 2009-04-25 10:24 -------- d-----w- c:\program files\Warcraft III
2010-01-24 00:50 . 2009-04-25 10:27 160315 ----a-w- c:\windows\War3Unin.dat
2010-01-23 23:26 . 2008-12-08 17:38 -------- d-----w- c:\program files\AGEIA Technologies
2010-01-23 14:52 . 2009-05-19 19:04 -------- d-----w- c:\program files\WeGame
2010-01-21 09:30 . 2008-12-17 14:07 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-19 20:20 . 2008-12-28 16:00 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-01-18 22:19 . 2008-12-11 17:31 -------- d-----w- c:\program files\Fichiers communs\Blizzard Entertainment
2010-01-12 04:03 . 2005-01-02 04:26 10276768 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-12 04:03 . 2005-01-02 04:26 6359168 ----a-w- c:\windows\system32\nv4_disp.dll
2009-12-29 17:29 . 2009-12-29 17:29 -------- d-----w- c:\program files\GigaTribe
2009-12-24 07:06 . 2005-01-02 05:03 -------- d-----w- c:\program files\Google
2009-12-23 22:09 . 2009-11-25 10:03 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-22 22:04 . 2009-12-22 22:04 -------- d-----w- c:\program files\Avira
2009-12-22 22:04 . 2009-11-25 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-21 19:07 . 2004-08-05 18:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-17 18:06 . 2009-07-01 11:22 -------- d-----w- c:\program files\Diablo II
2009-12-16 17:07 . 2009-12-16 17:07 -------- d-----w- c:\program files\Total Immersion
2009-12-14 12:21 . 2004-11-23 21:26 85744 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-14 12:21 . 2004-11-23 21:26 512206 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-13 17:26 . 2009-12-13 17:26 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-13 17:26 . 2009-12-13 17:26 -------- d-----w- c:\program files\VSO
2009-12-13 16:17 . 2009-05-11 09:53 -------- d-----w- c:\program files\EA GAMES
2009-11-30 19:33 . 2009-11-30 19:33 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-11-27 22:55 . 2009-11-27 22:55 4608 ----a-w- c:\windows\system32\w95inf32.dll
2009-11-27 22:55 . 2009-11-27 22:55 2272 ----a-w- c:\windows\system32\w95inf16.dll
2009-11-23 19:13 . 2009-11-23 19:13 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-11-21 15:58 . 2004-08-05 18:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-16 21:42 . 2009-11-16 21:43 40672 ----a-w- c:\windows\system32\drivers\CESG502.SYS
2005-12-17 02:32 . 2008-12-09 00:49 22 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"RamBoostXp"="z:\program files\RamBoost XP\rambxpfr.exe" [2004-03-09 1542144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"Home Theater SchSvr"="c:\program files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2005-07-18 106496]
"WINREMOTE"="c:\program files\InterVideo\Common\Bin\WinRemote.exe" [2005-07-18 262144]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"phc710"="c:\windows\vphc700.exe" [2005-07-20 339968]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-03-11 86016]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-11 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 13666408]
c:\documents and settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Outil de notification Live Search.lnk - c:\documents and settings\HP_Propri‚taire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe [2008-12-17 143360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^TrayMin710.exe.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\TrayMin710.exe.lnk
backup=c:\windows\pss\TrayMin710.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^GigaTribe.lnk]
path=c:\documents and settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\GigaTribe.lnk
backup=c:\windows\pss\GigaTribe.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^LimeWire On Startup.lnk]
path=c:\documents and settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^Xfire.lnk]
path=c:\documents and settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\Xfire.lnk
backup=c:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
2007-06-29 13:03 36864 ----a-w- c:\program files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-10-28 19:21 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 02:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-06-08 21:42 14565376 ----a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-12-28 13:35 1217808 ----a-w- c:\program files\Steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-05-28 21:12 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"z:\\Program Files\\uTorrent\\uTorrent.exe"=
"z:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"z:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3sp.exe"=
"c:\\Program Files\\Services en ligne\\AOL\\InstallAol.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2ServerLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2BenchmarkTool.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\2K Games\\Gearbox Software\\Borderlands\\Binaries\\Borderlands.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"z:\\WOW 3.2.2\\World of Warcraft 3.2.2\\Launcher.exe"=
"z:\\WOW 3.2.2\\World of Warcraft 3.2.2\\WoW-3.1.3.9947-to-3.2.0.10192-frFR-downloader.exe"=
"z:\\WOW 3.2.2\\World of Warcraft 3.2.2\\Repair.exe"=
"c:\\Program Files\\GigaTribe\\gigatribe.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Eidos\\Batman Arkham Asylum\\Binaries\\ShippingPC-BmGame.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3074:UDP"= 3074:UDP:CoD5 UDP1
"28960:UDP"= 28960:UDP:CoD5 UDP2
"28960:TCP"= 28960:TCP:CoD5 TCP
"7777:TCP"= 7777:TCP:Borderlands
"7777:UDP"= 7777:UDP:Borderlands UDP
"28900:TCP"= 28900:TCP:Borderlands TCP
"27900:UDP"= 27900:UDP:Borderlands UDP
"28910:TCP"= 28910:TCP:Borederlands TCP
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [22/12/2009 23:04 108289]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [22/02/2009 13:14 54752]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [02/01/2005 05:26 2786176]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [28/11/2009 13:32 691696]
S2 gupdate1c9dfd914fb67cc;Service Google Update (gupdate1c9dfd914fb67cc);c:\program files\Google\Update\GoogleUpdate.exe [28/05/2009 22:13 133104]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [17/11/2008 08:05 195752]
S3 phc700;USB PC Camera (phc710);c:\windows\system32\drivers\phc700.sys [19/12/2008 22:14 541568]
S3 phc710;USB PC Camera (SPC710NC);c:\windows\system32\DRIVERS\phc710.sys --> c:\windows\system32\DRIVERS\phc710.sys [?]
S3 whfltr2k;WheelMouse USB Lower Filter Driver;c:\windows\system32\drivers\whfltr2k.sys [25/01/2007 16:45 6784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contenu du dossier 'Tâches planifiées'
2010-01-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-02-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-28 21:12]
2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-28 21:12]
2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-28 21:12]
2010-01-28 c:\windows\Tasks\HPCeeSchedule.job
- c:\progra~1\EASYIN~1\Ceement\HPCEE.exe [2005-06-13 16:41]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://fr.ask.com?o=15161&l=dis
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Pages liées - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Pages similaires - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Version de la page actuelle disponible dans le cache Google - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
FF - ProfilePath - c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\7j7ys1ao.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
FF - prefs.js: browser.search.selectedEngine - Fast Browser Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5422FC88-1C6C-E69F-EC02-547510324457}&q=
FF - component: c:\documents and settings\HP_Propriétaire\Application Data\Mozilla\Firefox\Profiles\7j7ys1ao.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1591.6512\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPDFusionWebFirefox.dll
FF - plugin: c:\program files\Total Immersion\DFusionHomeWebPlugIn\NPDFusionWebFirefox.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-RAMBooster.Net - c:\program files\RAMBooster.Net\RAMBooster.exe
HKLM-Run-nwiz - nwiz.exe
MSConfigStartUp-Alcmtr - ALCMTR.EXE
MSConfigStartUp-AlcoholAutomount - c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe
MSConfigStartUp-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe
MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe
AddRemove-Fx-Interface_is1 - z:\program files\CASIO\Fx-Interface\unins000.exe
AddRemove-Homeworld2 - c:\program files\Sierra\Homeworld2\uninstall.exe
AddRemove-Wow Cartographe - c:\program files\WowCartographe\uninst.exe
AddRemove-{14B380D6-8205-4F9D-81D8-515235929F2A}_is1 - z:\documents and settings\HP_Propriétaire\Local Settings\Application Data\Dictionnaire Freelang\unins001.exe
AddRemove-{B53353EA-7724-4654-8DFF-674F3E08623C}_is1 - z:\program files\World of Warcraft\Program Files\unins000.exe
AddRemove-{F53C4192-71DE-4B21-BE03-D6F8CBB5A238}_is1 - z:\documents and settings\HP_Propriétaire\Local Settings\Application Data\Dictionnaire Freelang\unins000.exe
AddRemove-BattleDirector - c:\program files\The Sir. Community\BattleDirector\uninstall.exe
AddRemove-Live Search - c:\documents and settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Suppression-Live-Search.exe
AddRemove-Naggarythe Online Launcher - c:\program files\World of warcraft\Uninstal.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-07 20:47
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1465579271-3616371518-2648195347-1008\Software\SecuROM\License information*]
"datasecu"=hex:82,e3,38,27,08,40,0f,2e,9e,3c,8d,b4,a6,2b,a9,8a,b7,26,29,ef,6d,
e0,a7,1c,28,fe,09,ea,cc,7f,b2,4c,a6,6e,cb,6d,a1,9f,27,15,75,e8,30,1f,cb,71,\
"rkeysecu"=hex:e7,30,32,08,a4,63,a1,ea,b1,67,56,c5,77,4e,31,c4
.
Heure de fin: 2010-02-07 20:49:25
ComboFix-quarantined-files.txt 2010-02-07 19:49
Avant-CF: 66 392 367 104 octets libres
Après-CF: 66 380 079 104 octets libres
- - End Of File - - 2502DB5F1BD64F1EDD4B5BFCD510CAF3
● Télécharge Ad-Remover (de Cyrildu17 / C_XX) sur ton Bureau.
/!\ Déconnecte-toi d'Internet et ferme toutes applications en cours. /!\
● Double-clique sur le programme AD-R situé sur ton Bureau.
(Sous Vista, il faut cliquer droit sur AD-R et choisir Exécuter en tant qu'administrateur)
● Au menu principal, choisis l'option L.
● Poste le rapport généré (C:\Ad-Report-CLEAN.log).
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Kaspersky, etc.) comme étant un RiskTool.
/!\ Déconnecte-toi d'Internet et ferme toutes applications en cours. /!\
● Double-clique sur le programme AD-R situé sur ton Bureau.
(Sous Vista, il faut cliquer droit sur AD-R et choisir Exécuter en tant qu'administrateur)
● Au menu principal, choisis l'option L.
● Poste le rapport généré (C:\Ad-Report-CLEAN.log).
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Kaspersky, etc.) comme étant un RiskTool.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
.
======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 05.02.2010 à 17:34
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 21:03:10, 07/02/2010 | Mode Normal | Option: CLEAN
Exécuté de: C:\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: FRED | Utilisateur actuel: HP_Propri‚taire
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla\FireFox\Profiles\7j7ys1ao.default\searchplugins\askcom.xml
C:\Program Files\GamesBar
(!) -- Fichiers temporaires supprimés.
.
HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
HKCU\software\microsoft\internet explorer\searchscopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
HKLM\software\GamesBarSetup
HKLM\software\Trymedia Systems
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.5.7 [fr] *
.
Nom du profil: 7j7ys1ao.default (HP_Propri‚taire)
.
(HP_PRO~1, prefs.js) Browser.download.dir, C:\Documents and Settings\HP_Propriétaire\Bureau
(HP_PRO~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\HP_Propriétaire\Bureau
(HP_PRO~1, prefs.js) Browser.search.defaultenginename, Fast Browser Search
(HP_PRO~1, prefs.js) Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(HP_PRO~1, prefs.js) Browser.search.selectedEngine, Fast Browser Search
(HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
(HP_PRO~1, prefs.js) Extensions.enabledItems, battlefieldheroespatcher@ea.com:4.0.36.0,{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}:2.4.2,{3112ca9c-de6d-4884-a869-9855de68056c}:6.1.20091119W,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,OberonGameHost@OberonGames.com:1.0.5.1344,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
(HP_PRO~1, prefs.js) Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5422FC88-1C6C-E69F-EC02-547510324457}&q=
.
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultengine, Ask.com
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultenginename, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultthis.engineName, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(HP_PRO~1, prefs.js) EFFACE - Browser.search.order.1, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Browser.search.selectedEngine, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5422FC88-1C6C-E69F-EC02-547510324457}&q=
.
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Enable Browser Extensions: yes
Use Search Asst: no
Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials, ...) ==============
.
C:\Documents and Settings\HP_Propri‚taire\Application Data\Mozilla\Firefox\Profiles\7j7ys1ao.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe
C:\Documents and Settings\HP_Propri‚taire\Application Data\uTorrent\[PC GAME] Assassins Creed (Full) + CRACK.torrent
C:\Documents and Settings\HP_Propri‚taire\Mes documents\Battlerecorder\Patch FR Battlelauncher.rar
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.1-0.7.0.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.2-0.7.0.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.3-0.7.0.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.4-0.7.0.5.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.5-0.7.0.6.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.6-0.7.0.7.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.7-0.7.0.8.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.8-0.7.0.9.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.9-0.7.1.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.0-0.7.1.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.1-0.7.1.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.2-0.7.1.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.3-0.7.1.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.4-0.7.1.5.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.5-0.7.1.6.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.6-0.7.1.7.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.7-0.7.1.8.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.8-0.7.1.9.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.9-0.7.2.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.0-0.7.2.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.1-0.7.2.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.2-0.7.2.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.3-0.7.2.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.4-0.8.0.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.8.0.1-1.0.0.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.0-1.0.0.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.1-1.0.0.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.2-1.0.0.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.3-1.0.0.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.4-1.0.0.5.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.5-1.0.0.6.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.6-1.0.0.7.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.7-1.0.0.8.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.8-1.0.1.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.0-1.0.1.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.1-1.0.1.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.2-1.0.1.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.3-1.0.1.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.4-1.0.1.5.exe
.
===================================
.
9738 Octet(s) - C:\Ad-Report-CLEAN[1].log
.
0 Fichier(s) - C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
1 Fichier(s) - C:\WINDOWS\Temp
0 Fichier(s) - C:\WINDOWS\Prefetch
.
19 Fichier(s) - C:\Ad-Remover\BACKUP
2 Fichier(s) - C:\Ad-Remover\QUARANTINE
.
Fin à: 21:07:23 | 07/02/2010 - CLEAN[1]
.
============== E.O.F ==============
.
======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 05.02.2010 à 17:34
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 21:03:10, 07/02/2010 | Mode Normal | Option: CLEAN
Exécuté de: C:\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: FRED | Utilisateur actuel: HP_Propri‚taire
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
C:\DOCUME~1\HP_PRO~1\APPLIC~1\Mozilla\FireFox\Profiles\7j7ys1ao.default\searchplugins\askcom.xml
C:\Program Files\GamesBar
(!) -- Fichiers temporaires supprimés.
.
HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}
HKCU\software\microsoft\internet explorer\searchscopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}
HKLM\Software\Classes\TypeLib\{937936AF-28CA-4973-B8AE-F250406149A2}
HKLM\software\GamesBarSetup
HKLM\software\Trymedia Systems
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.5.7 [fr] *
.
Nom du profil: 7j7ys1ao.default (HP_Propri‚taire)
.
(HP_PRO~1, prefs.js) Browser.download.dir, C:\Documents and Settings\HP_Propriétaire\Bureau
(HP_PRO~1, prefs.js) Browser.download.lastDir, C:\Documents and Settings\HP_Propriétaire\Bureau
(HP_PRO~1, prefs.js) Browser.search.defaultenginename, Fast Browser Search
(HP_PRO~1, prefs.js) Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(HP_PRO~1, prefs.js) Browser.search.selectedEngine, Fast Browser Search
(HP_PRO~1, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
(HP_PRO~1, prefs.js) Extensions.enabledItems, battlefieldheroespatcher@ea.com:4.0.36.0,{C2DCA7EB-22D2-4FD2-86A9-F99FCC8122BB}:2.4.2,{3112ca9c-de6d-4884-a869-9855de68056c}:6.1.20091119W,{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15,{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17,jqs@sun.com:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,OberonGameHost@OberonGames.com:1.0.5.1344,{635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.5.4.20081105,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
(HP_PRO~1, prefs.js) Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5422FC88-1C6C-E69F-EC02-547510324457}&q=
.
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultengine, Ask.com
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultenginename, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaultthis.engineName, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(HP_PRO~1, prefs.js) EFFACE - Browser.search.order.1, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Browser.search.selectedEngine, Fast Browser Search
(HP_PRO~1, prefs.js) EFFACE - Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={5422FC88-1C6C-E69F-EC02-547510324457}&q=
.
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Enable Browser Extensions: yes
Use Search Asst: no
Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
============== Suspect (Cracks, Serials, ...) ==============
.
C:\Documents and Settings\HP_Propri‚taire\Application Data\Mozilla\Firefox\Profiles\7j7ys1ao.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\BFHUpdater.exe
C:\Documents and Settings\HP_Propri‚taire\Application Data\uTorrent\[PC GAME] Assassins Creed (Full) + CRACK.torrent
C:\Documents and Settings\HP_Propri‚taire\Mes documents\Battlerecorder\Patch FR Battlelauncher.rar
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.1-0.7.0.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.2-0.7.0.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.3-0.7.0.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.4-0.7.0.5.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.5-0.7.0.6.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.6-0.7.0.7.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.7-0.7.0.8.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.8-0.7.0.9.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.0.9-0.7.1.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.0-0.7.1.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.1-0.7.1.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.2-0.7.1.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.3-0.7.1.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.4-0.7.1.5.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.5-0.7.1.6.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.6-0.7.1.7.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.7-0.7.1.8.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.8-0.7.1.9.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.1.9-0.7.2.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.0-0.7.2.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.1-0.7.2.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.2-0.7.2.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.3-0.7.2.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.7.2.4-0.8.0.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-0.8.0.1-1.0.0.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.0-1.0.0.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.1-1.0.0.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.2-1.0.0.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.3-1.0.0.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.4-1.0.0.5.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.5-1.0.0.6.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.6-1.0.0.7.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.7-1.0.0.8.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.0.8-1.0.1.0.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.0-1.0.1.1.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.1-1.0.1.2.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.2-1.0.1.3.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.3-1.0.1.4.exe
C:\Documents and Settings\HP_Propri‚taire\Mes documents\DungeonParty\UpdaterDownloads\patch-dungeonparty-1.0.1.4-1.0.1.5.exe
.
===================================
.
9738 Octet(s) - C:\Ad-Report-CLEAN[1].log
.
0 Fichier(s) - C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp
1 Fichier(s) - C:\WINDOWS\Temp
0 Fichier(s) - C:\WINDOWS\Prefetch
.
19 Fichier(s) - C:\Ad-Remover\BACKUP
2 Fichier(s) - C:\Ad-Remover\QUARANTINE
.
Fin à: 21:07:23 | 07/02/2010 - CLEAN[1]
.
============== E.O.F ==============
.
1/
---> Désinstalle HijackThis et Ad-Remover.
---> Menu Démarrer > Exécuter > Tape ComboFix /uninstall et valide.
---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
2/
---> Télécharge et installe CCleaner Slim.
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
3/
---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.
==Prévention==
Pour supprimer les popups d'AntiVir : Lien
Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.
Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, Propriétés, onglet Mises à jour automatiques).
Par rapport au P2P : Lien
Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien
Sois plus vigilant(e) sur Internet ;)
---> Désinstalle HijackThis et Ad-Remover.
---> Menu Démarrer > Exécuter > Tape ComboFix /uninstall et valide.
---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
2/
---> Télécharge et installe CCleaner Slim.
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
3/
---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.
==Prévention==
Pour supprimer les popups d'AntiVir : Lien
Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.
Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, Propriétés, onglet Mises à jour automatiques).
Par rapport au P2P : Lien
Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien
Sois plus vigilant(e) sur Internet ;)
[ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]
--> Recherche:
C:\Combofix.txt: trouvé !
C:\_OTM: trouvé !
C:\Rsit: trouvé !
C:\Ad-remover: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !
---------------------------------
--> Suppression:
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\_OTM: supprimé !
C:\Rsit: supprimé !
C:\Ad-remover: supprimé !
--> Recherche:
C:\Combofix.txt: trouvé !
C:\_OTM: trouvé !
C:\Rsit: trouvé !
C:\Ad-remover: trouvé !
C:\Program Files\trend micro\HijackThis.exe: trouvé !
C:\Program Files\trend micro\hijackthis.log: trouvé !
---------------------------------
--> Suppression:
C:\Program Files\trend micro\HijackThis.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Program Files\trend micro\hijackthis.log: supprimé !
C:\_OTM: supprimé !
C:\Rsit: supprimé !
C:\Ad-remover: supprimé !