Un petit problème.

choucco Messages postés 10 Statut Membre -  
 bobo -
Bonsoir,

Voilà, je sais bien que je dois être le je ne sais combientième à dire ça, mais je dois avoir un jolie petit virus qui va me pourrir mes vacances si je ne fais rien! :D
Je suis désolé d'avoir recours à vous, généralement j'arrive à me débrouiller seul, mais la j'ai tenter tout ce qui me venait à l'esprit.

Voilà, il y a quelques temps, ma version d'avast a expiré. J'ai eu quelques jours sans antivirus sur mon ordinateur, et je suppose que c'est à ce moment là que j'ai du attraper une jolie petite bestiole.
J'ai réinstaller avast, mais depuis quelques temps mon ordi n'en fait qu'à sa tête, il se fige tout d'un coup, et il ne veut rien savoir. Il me fait ça toute les dix minutes environ. Il rame peut-être un petit peu aussi, enfin ça c'est peut-être le fruit de mon immagination.
J'ai passé plusieurs fois tout les logiciels que j'avais en réserve, avast, CCleaner, ... Sans m'apporter grand chose.
Le pire c'est qu'il ne laisse aucun message d'erreur, rien du tout.

Enfin voilà, si quelqu'un pouvait m'aider, ça me ferait plaisir!

Sur ce, bonne soirée à vous! :)

19 réponses

  1. J_D_95 Messages postés 229 Statut Membre 37
     
    slt, dsl de te dire ca si tu es honnete, mais le mieux est que tu crack norton 2010, il te donneront une version d'évaluation de 30 jours (je fais comme ca). Ensuite, quand norton sera instalé, tu pourra faaire une analyse complete de ton systeme et il te supprimera ta "jolie petite bestiole" lol. Apres, tu pourra continuer l'abonnement pour 29 e pour 1 an, ou alors des que la version a excpiré, tu la retelecharge etc ...
    0
  2. choucco Messages postés 10 Statut Membre
     
    Mmh, il est vrai que je m'attendais à une autre réponse, mais merci de ton aide, je vais essayer. :)
    0
  3. archet9
     
    Bonsoir,

    Pour voir cela:

    Télécharge RSIT (de random/random) sur le bureau :

    - Double clique sur RSIT.exe qui est sur le bureau
    - Clique sur "Continue" dans la fenêtre
    - RSIT téléchargera HijackThis si il n’est pas présent où détecté, alors il faudra accepter la licence
    - Poste le contenu de log.txt plus info.txt (réduit ds la barre de taches) à la fin de l’analyse .

    Les rapports sont dans le dossier ici C:\rsit

    a+
    0
  4. choucco
     
    Bonsoir,

    J'ai passé et repassé avast, et le même virus revient toujours, "JS:Agent-FM [trj]". Si ça peut faire avancer le schmilblick. :)

    Voilà le contenu de log.txt:

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by chouc at 2010-02-22 20:46:38
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 104 GB (68%) free of 153 GB
    Total RAM: 2047 MB (73% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:46:55, on 22/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\chouc\Bureau\RSIT.exe
    C:\Program Files\trend micro\chouc.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Nero Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. archet9
     
    Re,

    Télécharges AD-REMOVER
    ou
    AD-REMOVER

    (de Cyrildu17 / C_XX) sur ton Bureau.

    Déconnectes-toi et ferme toutes applications en cours

    Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program files).
    Double-clique sur l'icône [AD-Remover située sur ton Bureau.

    Au menu principal, choisis l'option L.

    Postes le rapport qui apparaît à la fin.
    (Le rapport est sauvegardé aussi sous C:\Ad-report(date).log)

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

    a+

    ........
    0
  7. choucco Messages postés 10 Statut Membre
     
    Le voici:

    .
    ======= RAPPORT D'AD-REMOVER 1.1.4.6_J | UNIQUEMENT XP/VISTA/7 =======
    .
    Mis à jour par C_XX le 05.02.2010 à 17:34
    Contact: AdRemover.contact@gmail.com
    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
    .
    Lancé à: 21:25:27, 22/02/2010 | Mode Normal | Option: CLEAN
    Exécuté de: C:\Ad-Remover\
    Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
    Nom du PC: CHOUCPC | Utilisateur actuel: chouc
    .
    ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
    .

    C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
    C:\Program Files\Ask.com
    C:\DOCUME~1\chouc\APPLIC~1\AskToolbar
    C:\Documents and Settings\chouc\Local Settings\Application Data\AskToolbar
    C:\Documents and Settings\HelpAssistant\Application Data\AskToolbar
    C:\Documents and Settings\HelpAssistant\Local Settings\Application Data\AskToolbar
    C:\Documents and Settings\HelpAssistant\Application Data\Macromedia\Flash Player\#SharedObjects\FJ2ET8BH\casino.com
    C:\Documents and Settings\HelpAssistant\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#casino.com

    (!) -- Fichiers temporaires supprimés.

    .
    HKCU\software\appdatalow\AskToolbarInfo
    HKCU\software\Ask.com
    HKCU\software\AskToolbar
    HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383}
    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440}
    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00000000-6E41-4FD3-8538-502F5495E5FC}
    HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
    HKLM\software\classes\appid\GenericAskToolbar.DLL
    HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
    HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
    HKLM\software\classes\GenericAskToolbar.ToolbarWnd
    HKLM\software\classes\GenericAskToolbar.ToolbarWnd.1
    HKLM\software\classes\installer\Products\A28B4D68DEBAA244EB686953B7074FEF
    HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
    HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
    HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
    HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
    HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
    HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
    HKLM\software\microsoft\windows\currentversion\uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
    .
    ============== Scan additionnel ==============
    .
    .
    * Mozilla FireFox Version 3.6 [fr] *
    .
    Nom du profil: 661636re.default (chouc)
    .
    (chouc, prefs.js) Browser.startup.homepage, hxxp://www.google.fr/
    (chouc, prefs.js) Extensions.enabledItems, {20a82645-c095-46ed-80e3-08825760534b}:1.1,jqs@sun.com:1.0,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6
    .
    .
    * Internet Explorer Version 8.0.6001.18702 *
    .
    [HKEY_CURRENT_USER\..\Internet Explorer\Main]
    .
    Do404Search: 01000000
    Local Page: C:\WINDOWS\system32\blank.htm
    Show_ToolBar: yes
    Start Page: hxxp://fr.msn.com/
    Enable Browser Extensions: yes
    Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    .
    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
    .
    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Delete_Temp_Files_On_Exit: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Start Page: hxxp://fr.msn.com/
    Search bar: hxxp://search.msn.com/spbasic.htm
    .
    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
    .
    Tabs: res://ieframe.dll/tabswelcome.htm
    .
    ===================================
    .
    5125 Octet(s) - C:\Ad-Report-CLEAN[1].log
    .
    34 Fichier(s) - C:\DOCUME~1\chouc\LOCALS~1\Temp
    52 Fichier(s) - C:\WINDOWS\Temp
    6 Fichier(s) - C:\WINDOWS\Prefetch
    .
    18 Fichier(s) - C:\Ad-Remover\BACKUP
    24 Fichier(s) - C:\Ad-Remover\QUARANTINE
    .
    Fin à: 21:28:54 | 22/02/2010 - CLEAN[1]
    .
    ============== E.O.F ==============
    .
    0
  8. archet9
     
    Très bien...

    Ceci maintenant :

    Fais un scan avec cet antispyware :
    Malwarebytes + tutoriel

    Tu l´installes; mets le a jour...(onglet mise a jour)
    Click maintenant sur l´onglet recherche et coche la case :
    "Executer un examen rapide".
    Puis click sur "rechercher".
    Laisses le scanner le pc...
    A la fin du scan, clique sur Afficher les résultats
    Si des elements on ete trouvés :
    > click sur supprimer la selection
    .
    si il t´es demandé de redemarrer > click sur "oui".
    A la fin un rapport va s´ouvrir;
    sauvegarde le de maniere a le retrouver en vue de le poster sur le forum.
    Copies et colles le rapport stp.

    a+

    0
  9. choucco Messages postés 10 Statut Membre
     
    Voici le rapport:

    Malwarebytes' Anti-Malware 1.44
    Version de la base de données: 3777
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    22/02/2010 23:40:01
    mbam-log-2010-02-22 (23-40-01).txt

    Type de recherche: Examen rapide
    Eléments examinés: 133611
    Temps écoulé: 13 minute(s), 51 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 3

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Documents and Settings\chouc\Local Settings\Temp\Xwuc.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\HelpAssistant\Local Settings\Temp\Xwuc.dll (Trojan.Dropper) -> Quarantined and deleted successfully.
    C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\JRDZZGNH\eH91fe2096V0100f070006R699bbfe7102Tda7e5334201l000cK0109cbaa318J100006010[1] (Trojan.Dropper) -> Quarantined and deleted successfully.

    Trois trojan, je ne sais pas où j'ai é chopper tout ça!
    0
  10. choucco Messages postés 10 Statut Membre
     
    Mmh? Plus de logiciel en tête?
    Je commence à désespérer là, je n'ai pas envi de tout reformatter, je l'ai fais il y a peu de temps...
    C'est peut-être un problème matériel? Qu'est-ce qui peut causer des freeze comme ça?

    Merci de ton aide.
    0
  11. archet9
     
    ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

    ---> Double-clique sur Combofix.exe
    Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
    Accepte en cliquant sur "Oui"

    ---> Mets-le en langue française F
    Tape sur la touche 1 (Yes) pour démarrer le scan.

    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

    Note : Le rapport se trouve également là : C:\ComboFix.txt
    0
  12. choucco Messages postés 10 Statut Membre
     
    Voici le rapport:

    ComboFix 10-02-23.04 - chouc 24/02/2010 19:42:39.1.2 - x86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1571 [GMT 1:00]
    Lancé depuis: c:\documents and settings\All Users\Documents\ComboFix.exe
    AV: avast! antivirus 4.8.1368 [VPS 100224-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: NVIDIA Firewall *disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2010-01-24 au 2010-02-24 ))))))))))))))))))))))))))))))))))))
    .

    2010-02-23 18:53 . 2010-02-23 18:53 -------- d-----w- c:\documents and settings\chouc\Local Settings\Application Data\Help
    2010-02-23 18:53 . 2004-02-19 03:03 65536 ----a-w- c:\windows\system32\E_S00RP1.EXE
    2010-02-22 22:32 . 2010-02-22 22:32 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\Malwarebytes
    2010-02-22 22:23 . 2010-02-22 22:23 -------- d-----w- c:\documents and settings\chouc\Application Data\Malwarebytes
    2010-02-22 22:23 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-02-22 22:23 . 2010-02-22 22:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-02-22 22:23 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-02-22 22:23 . 2010-02-22 22:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-02-22 20:22 . 2010-02-22 20:28 -------- d-----w- C:\Ad-Remover
    2010-02-22 19:46 . 2010-02-22 19:46 -------- d-----w- c:\program files\trend micro
    2010-02-22 19:46 . 2010-02-22 19:46 -------- d-----w- C:\rsit
    2010-02-22 18:42 . 2010-02-22 18:42 0 ----a-w- c:\windows\nsreg.dat
    2010-02-22 18:42 . 2010-02-22 18:42 -------- d-----w- c:\documents and settings\chouc\Local Settings\Application Data\Mozilla
    2010-02-22 18:26 . 2010-02-22 18:26 -------- d-----w- c:\program files\Lavalys
    2010-02-21 22:39 . 2010-02-21 23:13 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\XBMC
    2010-02-21 22:38 . 2010-02-04 09:01 74072 ----a-w- c:\windows\system32\XAPOFX1_4.dll
    2010-02-21 22:38 . 2010-02-04 09:01 528216 ----a-w- c:\windows\system32\XAudio2_6.dll
    2010-02-21 22:38 . 2010-02-04 09:01 238936 ----a-w- c:\windows\system32\xactengine3_6.dll
    2010-02-21 22:37 . 2010-02-04 09:01 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
    2010-02-21 22:37 . 2010-02-21 22:37 -------- d--h--w- c:\windows\msdownld.tmp
    2010-02-21 22:37 . 2010-02-21 22:45 -------- d-----w- c:\documents and settings\chouc\Application Data\XBMC
    2010-02-21 22:36 . 2010-02-21 22:38 -------- d-----w- c:\program files\XBMC
    2010-02-21 00:26 . 2010-02-21 00:26 -------- d-----w- c:\documents and settings\HelpAssistant\UserData
    2010-02-21 00:26 . 2010-02-21 00:26 -------- d-----w- c:\documents and settings\HelpAssistant\Tracing
    2010-02-21 00:26 . 2010-02-21 00:26 -------- d-----w- c:\documents and settings\HelpAssistant\PrivacIE
    2010-02-21 00:02 . 2010-02-21 12:49 -------- d-----w- c:\documents and settings\HelpAssistant\IETldCache
    2010-02-21 00:02 . 2010-02-21 12:49 -------- d-----w- c:\documents and settings\HelpAssistant\IECompatCache
    2010-02-21 00:02 . 2010-02-21 00:02 -------- d-----w- c:\documents and settings\HelpAssistant\Bluetooth Software
    2010-02-21 00:02 . 2010-02-21 00:02 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\vlc
    2010-02-21 00:02 . 2010-02-18 17:22 1 ----a-w- c:\documents and settings\HelpAssistant\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-02-21 00:02 . 2010-02-21 00:02 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\OpenOffice.org
    2010-02-21 00:02 . 2010-02-21 00:02 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\Nero
    2010-02-21 00:02 . 2010-02-21 00:02 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\Media Player Classic
    2010-02-20 11:43 . 2009-11-25 10:19 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2010-02-14 17:04 . 2010-02-14 17:05 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
    2010-02-10 13:24 . 2010-02-10 13:24 -------- d-----w- c:\program files\MSECache
    2010-02-07 16:05 . 2010-02-07 16:05 -------- d-----w- c:\documents and settings\chouc\Application Data\DivX
    2010-02-07 16:05 . 2010-02-07 16:05 -------- d-----w- c:\documents and settings\chouc\Application Data\Media Player Classic
    2010-02-06 15:56 . 2010-02-06 15:56 -------- d-----w- c:\windows\Sun
    2010-02-06 09:50 . 2010-02-06 09:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
    2010-02-06 09:50 . 2010-02-06 09:50 -------- d-----w- c:\windows\system32\drivers\NSS
    2010-02-06 09:50 . 2010-02-06 09:50 -------- d-----w- c:\program files\Norton Security Scan
    2010-02-06 09:50 . 2010-02-06 09:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
    2010-02-06 09:50 . 2010-02-06 09:50 -------- d-----w- c:\program files\NortonInstaller
    2010-02-06 09:50 . 2010-02-06 09:50 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
    2010-02-05 23:54 . 2009-12-12 14:15 178176 ----a-w- c:\windows\system32\unrar.dll
    2010-02-05 23:54 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
    2010-02-05 23:54 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
    2010-02-05 23:54 . 2010-02-02 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
    2010-02-05 23:54 . 2010-02-05 23:54 -------- d-----w- c:\program files\K-Lite Codec Pack
    2010-01-28 16:18 . 2010-01-28 16:18 -------- d-sh--w- c:\windows\ftpcache

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-24 16:16 . 2010-01-16 13:46 -------- d-----w- c:\program files\Warcraft III
    2010-02-22 16:57 . 2009-12-25 01:46 -------- d-----w- c:\documents and settings\chouc\Application Data\vlc
    2010-02-22 16:37 . 2009-12-20 21:24 -------- d-----w- c:\program files\AIDA32 - Personal System Information
    2010-02-21 11:10 . 2010-01-08 21:03 -------- d-----w- c:\program files\Free Music Zilla
    2010-02-21 00:01 . 2010-02-21 00:01 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\InterVideo
    2010-02-21 00:01 . 2010-02-21 00:01 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\gtk-2.0
    2010-02-21 00:01 . 2010-02-21 00:01 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\FMZilla
    2010-02-21 00:01 . 2010-02-21 00:01 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\dvdcss
    2010-02-21 00:01 . 2010-02-21 00:01 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\DivX
    2010-02-21 00:01 . 2010-02-21 00:01 -------- d-----w- c:\documents and settings\HelpAssistant\Application Data\AdobeUM
    2010-02-19 20:01 . 2009-12-25 01:46 -------- d-----w- c:\documents and settings\chouc\Application Data\dvdcss
    2010-02-18 20:04 . 2010-01-11 20:52 -------- d-----w- c:\program files\adslTV
    2010-02-18 17:22 . 2009-12-23 17:01 1 ----a-w- c:\documents and settings\chouc\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-02-05 22:56 . 2010-01-22 23:48 -------- d-----w- c:\program files\DivX
    2010-02-05 22:55 . 2010-01-22 23:48 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
    2010-01-30 17:25 . 2009-12-20 17:50 -------- d-----w- c:\program files\Steam
    2010-01-18 18:31 . 2010-01-18 18:31 -------- d-----w- c:\program files\Windows Media Connect 2
    2010-01-16 13:48 . 2010-01-16 12:35 -------- d-----w- c:\program files\Fichiers communs\Blizzard Entertainment
    2010-01-08 21:03 . 2010-01-08 21:03 -------- d-----w- c:\documents and settings\chouc\Application Data\FMZilla
    2009-12-31 16:50 . 2004-08-05 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
    2009-12-26 23:13 . 2009-12-26 23:12 -------- d-----w- c:\program files\Maxima-5.13.0
    2009-12-25 01:40 . 2009-12-19 16:33 20720 ----a-w- c:\documents and settings\chouc\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-12-23 16:57 . 2009-12-23 16:58 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-12-21 19:07 . 2004-08-05 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
    2009-12-20 15:30 . 2004-08-05 12:00 80508 ----a-w- c:\windows\system32\perfc00C.dat
    2009-12-20 15:30 . 2004-08-05 12:00 500454 ----a-w- c:\windows\system32\perfh00C.dat
    2009-12-19 19:24 . 2009-12-19 19:24 445016 ----a-w- c:\windows\system32\wrap_oal.dll
    2009-12-19 19:24 . 2009-12-19 19:24 109144 ----a-w- c:\windows\system32\OpenAL32.dll
    2009-12-19 17:55 . 2009-12-19 17:55 60416 ----a-w- c:\windows\ALCFDRTM.EXE
    2009-12-19 17:54 . 2009-12-19 16:27 76507 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
    2009-12-19 17:20 . 2009-09-28 06:12 2194024 ----a-w- c:\windows\system32\nvcuvid.dll
    2009-12-19 17:20 . 2009-09-28 06:12 2007040 ----a-w- c:\windows\system32\nvcuda.dll
    2009-12-19 17:20 . 2009-09-28 06:12 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
    2009-12-19 17:20 . 2009-09-28 06:12 1604482 ----a-w- c:\windows\system32\nvdata.bin
    2009-12-19 17:20 . 2009-09-28 06:12 10756096 ----a-w- c:\windows\system32\nvoglnt.dll
    2009-12-19 17:20 . 2009-09-28 06:12 888832 ----a-w- c:\windows\system32\nvapi.dll
    2009-12-19 17:20 . 2009-09-28 06:12 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
    2009-12-19 17:20 . 2009-09-28 06:12 5900416 ----a-w- c:\windows\system32\nv4_disp.dll
    2009-12-19 17:20 . 2009-09-28 06:12 170600 ----a-w- c:\windows\system32\nvcodins.dll
    2009-12-19 17:20 . 2009-09-28 06:12 170600 ----a-w- c:\windows\system32\nvcod.dll
    2009-12-19 16:26 . 2009-12-19 16:26 21892 ----a-w- c:\windows\system32\emptyregdb.dat
    2009-12-19 16:24 . 2009-12-19 16:24 297984 ----a-w- c:\windows\system32\termsrv32.dll
    2009-12-17 07:41 . 2009-12-19 16:24 347648 ----a-w- c:\windows\system32\mspaint.exe
    2009-12-14 07:09 . 2004-08-05 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
    2009-12-08 15:06 . 2009-12-08 15:06 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
    2009-12-04 18:22 . 2004-08-05 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2009-11-27 17:13 . 2004-08-05 12:00 1297920 ----a-w- c:\windows\system32\quartz.dll
    2009-11-27 17:13 . 2004-08-04 00:54 17920 ----a-w- c:\windows\system32\msyuv.dll
    2009-11-27 16:08 . 2004-08-05 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
    2009-11-27 16:08 . 2004-08-05 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
    2009-11-27 16:08 . 2004-08-05 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll
    2009-11-27 16:08 . 2004-08-04 00:54 48128 ----a-w- c:\windows\system32\iyuv_32.dll
    2009-11-27 16:08 . 2001-08-23 17:47 8704 ----a-w- c:\windows\system32\tsbyuv.dll
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 266240]
    "SoundMan"="SOUNDMAN.EXE" [2005-10-24 90112]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
    "ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 213936]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-23 149280]
    "\\ODEJAVEL\EPSON Stylus D68 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE" [2005-01-25 98304]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
    backup=c:\windows\pss\BTTray.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^chouc^Menu Démarrer^Programmes^Démarrage^Free Music Zilla.lnk]
    path=c:\documents and settings\chouc\Menu Démarrer\Programmes\Démarrage\Free Music Zilla.lnk
    backup=c:\windows\pss\Free Music Zilla.lnkStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^chouc^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.1.lnk]
    path=c:\documents and settings\chouc\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.1.lnk
    backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus D68 Series]
    2005-01-25 05:00 98304 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIAAE.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 02:34 1695232 ------w- c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2006-09-01 14:57 282624 ----a-w- c:\program files\QuickTime\qttask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    2009-12-20 17:51 1217808 ----a-w- c:\program files\Steam\Steam.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Steam\\Steam.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
    "c:\\Program Files\\Steam\\steamapps\\choucco\\counter-strike source\\hl2.exe"=
    "c:\\Program Files\\Maxima-5.13.0\\wxMaxima\\wxMaxima.exe"=
    "c:\\Program Files\\Maxima-5.13.0\\bin\\xmaxima.exe"=
    "c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
    "c:\\Program Files\\adslTV\\adsltv.exe"=
    "c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
    "c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
    "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6112:TCP"= 6112:TCP:WarCraft III Battle.net
    "65533:TCP"= 65533:TCP:Services
    "52344:TCP"= 52344:TCP:Services
    "2479:TCP"= 2479:TCP:Services
    "7521:TCP"= 7521:TCP:Services
    "3389:TCP"= 3389:TCP:Remote Desktop

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [19/12/2009 18:19 114768]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [19/12/2009 18:19 20560]
    .
    Contenu du dossier 'Tâches planifiées'

    2010-02-24 c:\windows\Tasks\Norton Security Scan for chouc.job
    - c:\program files\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2010-02-06 12:09]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/
    IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    LSP: %SYSTEMROOT%\system32\nvappfilter.dll
    FF - ProfilePath - c:\documents and settings\chouc\Application Data\Mozilla\Firefox\Profiles\661636re.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- PARAMETRES FIREFOX ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-24 19:47
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x89A59AE8]<<
    kernel: MBR read successfully
    detected MBR rootkit hooks:
    \Driver\Disk -> CLASSPNP.SYS @ 0xb80ecf28
    \Driver\ACPI -> 0x89a59ae8
    \Driver\atapi -> atapi.sys @ 0xb7f36852
    IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
    ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
    \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
    ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
    NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> 0x88ee3330
    PacketIndicateHandler -> NDIS.sys @ 0xb7e1aa0d
    SendHandler -> NDIS.sys @ 0xb7e2eb40
    Warning: possible MBR rootkit infection !
    copy of MBR has been found in sector 0x012A14C00
    malicious code @ sector 0x012A14C03 !
    PE file found in sector at 0x012A14C19 !
    MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'lsass.exe'(704)
    c:\windows\system32\nvappfilter.dll

    - - - - - - - > 'explorer.exe'(1640)
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Heure de fin: 2010-02-24 19:48:47
    ComboFix-quarantined-files.txt 2010-02-24 18:48

    Avant-CF: 103 580 753 920 octets libres
    Après-CF: 105 118 236 672 octets libres

    WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

    - - End Of File - - 1EF58CB8ACD5EB5B83224F53D0AD9E23
    0
  13. archet9
     
    As-tu toujours des alertes "Avast" ?

    /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

    Télécharge : Gmer (by Przemyslaw Gmerek)

    http://www.gmer.net/

    Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

    Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)

    Ensuite

    sur les lignes rouge:

    Services:cliques droit delete service
    Process:cliques droit kill process
    Adl ,file:cliques droit delete files

    ==> Dis moi si tu as vu des lines rouges.....

    a+
    0
  14. choucco Messages postés 10 Statut Membre
     
    Non, aucune alerte Avast en vu.

    Aucune ligne rouge non plus pour Gmer. Voici le rapport:

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-02-24 22:34:03
    Windows 5.1.2600 Service Pack 3
    Running: juuhh87v.exe; Driver: C:\DOCUME~1\chouc\LOCALS~1\Temp\pxtdqpob.sys

    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA8F0F6B8]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA8F0F574]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA8F0FA52]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA8F0F14C]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA8F0F64E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA8F0F08C]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA8F0F0F0]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA8F0F76E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA8F0F72E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA8F0F8AE]

    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xA8F1882E]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xA8F18678]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xA8F187AC]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection

    ---- Kernel code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB5FB5360, 0x3E57A5, 0xE8000020]

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe[308] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 016028E5
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe[308] WS2_32.dll!send 719F4C27 5 Bytes JMP 01602771
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe[308] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 01602863
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe[308] WS2_32.dll!recv 719F676F 5 Bytes JMP 016027A9
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe[308] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 016027E1
    .text C:\WINDOWS\system32\nvsvc32.exe[880] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 013D28E5
    .text C:\WINDOWS\system32\nvsvc32.exe[880] WS2_32.dll!send 719F4C27 5 Bytes JMP 013D2771
    .text C:\WINDOWS\system32\nvsvc32.exe[880] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 013D2863
    .text C:\WINDOWS\system32\nvsvc32.exe[880] WS2_32.dll!recv 719F676F 5 Bytes JMP 013D27A9
    .text C:\WINDOWS\system32\nvsvc32.exe[880] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 013D27E1
    .text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1348] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 026D28E5
    .text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1348] WS2_32.dll!send 719F4C27 5 Bytes JMP 026D2771
    .text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1348] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 026D2863
    .text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1348] WS2_32.dll!recv 719F676F 5 Bytes JMP 026D27A9
    .text C:\Program Files\Alwil Software\Avast4\ashServ.exe[1348] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 026D27E1
    .text C:\WINDOWS\Explorer.EXE[1616] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00D528E5
    .text C:\WINDOWS\Explorer.EXE[1616] WS2_32.dll!send 719F4C27 5 Bytes JMP 00D52771
    .text C:\WINDOWS\Explorer.EXE[1616] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00D52863
    .text C:\WINDOWS\Explorer.EXE[1616] WS2_32.dll!recv 719F676F 5 Bytes JMP 00D527A9
    .text C:\WINDOWS\Explorer.EXE[1616] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00D527E1
    .text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1748] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 019C28E5
    .text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1748] WS2_32.dll!send 719F4C27 5 Bytes JMP 019C2771
    .text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1748] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 019C2863
    .text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1748] WS2_32.dll!recv 719F676F 5 Bytes JMP 019C27A9
    .text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[1748] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 019C27E1
    .text C:\WINDOWS\system32\RUNDLL32.EXE[1768] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00E528E5
    .text C:\WINDOWS\system32\RUNDLL32.EXE[1768] WS2_32.dll!send 719F4C27 5 Bytes JMP 00E52771
    .text C:\WINDOWS\system32\RUNDLL32.EXE[1768] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00E52863
    .text C:\WINDOWS\system32\RUNDLL32.EXE[1768] WS2_32.dll!recv 719F676F 5 Bytes JMP 00E527A9
    .text C:\WINDOWS\system32\RUNDLL32.EXE[1768] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00E527E1
    .text C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe[1792] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00D628E5
    .text C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe[1792] WS2_32.dll!send 719F4C27 5 Bytes JMP 00D62771
    .text C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe[1792] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00D62863
    .text C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe[1792] WS2_32.dll!recv 719F676F 5 Bytes JMP 00D627A9
    .text C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe[1792] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00D627E1
    .text C:\Program Files\Java\jre6\bin\jusched.exe[1800] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00CB28E5
    .text C:\Program Files\Java\jre6\bin\jusched.exe[1800] WS2_32.dll!send 719F4C27 5 Bytes JMP 00CB2771
    .text C:\Program Files\Java\jre6\bin\jusched.exe[1800] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00CB2863
    .text C:\Program Files\Java\jre6\bin\jusched.exe[1800] WS2_32.dll!recv 719F676F 5 Bytes JMP 00CB27A9
    .text C:\Program Files\Java\jre6\bin\jusched.exe[1800] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00CB27E1
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2540] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00A028E5
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2540] WS2_32.dll!send 719F4C27 5 Bytes JMP 00A02771
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2540] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00A02863
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2540] WS2_32.dll!recv 719F676F 5 Bytes JMP 00A027A9
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2540] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00A027E1
    .text C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe[2584] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00B528E5
    .text C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe[2584] WS2_32.dll!send 719F4C27 5 Bytes JMP 00B52771
    .text C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe[2584] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00B52863
    .text C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe[2584] WS2_32.dll!recv 719F676F 5 Bytes JMP 00B527A9
    .text C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe[2584] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00B527E1
    .text C:\Program Files\Java\jre6\bin\jqs.exe[2624] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00D028E5
    .text C:\Program Files\Java\jre6\bin\jqs.exe[2624] WS2_32.dll!send 719F4C27 5 Bytes JMP 00D02771
    .text C:\Program Files\Java\jre6\bin\jqs.exe[2624] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00D02863
    .text C:\Program Files\Java\jre6\bin\jqs.exe[2624] WS2_32.dll!recv 719F676F 5 Bytes JMP 00D027A9
    .text C:\Program Files\Java\jre6\bin\jqs.exe[2624] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00D027E1
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe[2688] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 01D828E5
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe[2688] WS2_32.dll!send 719F4C27 5 Bytes JMP 01D82771
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe[2688] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 01D82863
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe[2688] WS2_32.dll!recv 719F676F 5 Bytes JMP 01D827A9
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe[2688] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 01D827E1
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2832] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 009328E5
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2832] WS2_32.dll!send 719F4C27 5 Bytes JMP 00932771
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2832] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00932863
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2832] WS2_32.dll!recv 719F676F 5 Bytes JMP 009327A9
    .text C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe[2832] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 009327E1
    .text C:\WINDOWS\System32\alg.exe[4148] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00C328E5
    .text C:\WINDOWS\System32\alg.exe[4148] WS2_32.dll!send 719F4C27 5 Bytes JMP 00C32771
    .text C:\WINDOWS\System32\alg.exe[4148] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 00C32863
    .text C:\WINDOWS\System32\alg.exe[4148] WS2_32.dll!recv 719F676F 5 Bytes JMP 00C327A9
    .text C:\WINDOWS\System32\alg.exe[4148] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 00C327E1

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\WINDOWS\system32\services.exe[692] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
    IAT C:\WINDOWS\system32\services.exe[692] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\ACPI \Device\00000041 89ADCFC8
    Device \Driver\ACPI \Device\00000042 89ADCFC8
    Device \Driver\ACPI \Device\00000043 89ADCFC8
    Device \Driver\ACPI \Device\00000050 89ADCFC8
    Device \Driver\ACPI \Device\00000045 89ADCFC8
    Device \Driver\ACPI \Device\00000052 89ADCFC8
    Device \Driver\ACPI \Device\00000060 89ADCFC8
    Device \Driver\ACPI \Device\00000055 89ADCFC8

    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\ACPI \Device\00000056 89ADCFC8
    Device \Driver\ACPI \Device\00000063 89ADCFC8
    Device \Driver\ACPI \Device\00000064 89ADCFC8
    Device \Driver\ACPI \Device\00000066 89ADCFC8
    Device \Driver\ACPI \Device\00000068 89ADCFC8
    Device \Driver\ACPI \Device\0000003e 89ADCFC8
    Device \Driver\ACPI \Device\0000004a 89ADCFC8
    Device \Driver\ACPI \Device\0000004d 89ADCFC8
    Device \Driver\ACPI \Device\0000004e 89ADCFC8
    Device \Driver\ACPI \Device\0000004f 89ADCFC8

    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\ACPI \Device\0000005d 89ADCFC8

    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\ACPI \Device\0000005e 89ADCFC8
    Device \Driver\ACPI \Device\0000005f 89ADCFC8

    ---- EOF - GMER 1.0.15 ----

    Mais voilà, juste après avoir passé Gmer, mon ordinateur a commencé à rammer énormément, et la, écran bleu avec marqué:

    "IRLQ_NOT_LESS_OR_EQUAL
    Si vous voyez ce message d'erreur pour la première fois, redémarrer votre ordinateur. Si cet erreur apparaît encore:
    Assurez vous que tout nouveau matériel ou logiciel est installé correctemen. Si il s'agit d'une nouvelle instalation, consultez votre fabriquant de matériel ou de logiciel, afin d'obtenir les mises à jour windows dont vous avec besoin. Si les problèmes persistent, désactivez ou supprimez tout matériel ou tout logiciel nouvellement installé/ Désactivez les options de mémoire du BIOS telle que la mise en cache ou l'ombrage.

    Information Technique:
    *** STOP: 0x0000000A (0x00000000, 0x0000001C, 0x00000000, 0x80538102)
    Début du vidag de la mémoire physique
    (...)"

    Mais le truc c'est que je n'ai pas installé de nouveau matériel récemment...
    0
  15. archet9
     
    Refais un nouveau scan avec RSIT...

    Un seul rapport sera généré cette fois , c'est normal.

    a+
    0
  16. choucco Messages postés 10 Statut Membre
     
    Le voici:

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by chouc at 2010-02-25 19:41:28
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 100 GB (66%) free of 153 GB
    Total RAM: 2047 MB (77% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 19:41:37, on 25/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\E_S00RP1.EXE
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Documents and Settings\chouc\Bureau\RSIT.exe
    C:\Program Files\trend micro\chouc.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [\\ODEJAVEL\EPSON Stylus D68 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P34 "\\ODEJAVEL\EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    0
  17. archet9
     
    A part les quelques infectionns virées par les 2 premiers scans ...
    Ton pc ne montre plus d'infection visible !!!!!

    Pour verif ceci:

    Desactives ton antivirus le temps de la manip ainsi que ton parefeu si présent

    Télécharges List&Kill'em et enregistre le sur ton bureau

    http://sd-1.archive-host.com/membres/up/829108531491024/List_Killem_Install.exe

    dezippes-le , (clic droit/ extraire.....)

    Il ne necessite pas d'installation

    double clic (clic droit "executer en tant qu'administrateur" pour Vista) pour lancer le scan

    choisis la langue puis choisis l'option 1 = Mode Recherche

    laisses travailler l'outil

    colles le contenu dans ta prochaine réponse , un fois la fenetre refermée :

    C:\List'em.txt

    a+

    0
  18. choucco
     
    Excuse moi, je n'étais pas là cette semaine.

    Voici le rapport:

    List'em by g3n-h@ckm@n 1.2.8.0

    User : chouc (Administrateurs)
    Update on 25/02/2010 by g3n-h@ckm@n ::::: 13.00
    Start at: 23:35:54 | 25/02/2010
    Contact : https://forums.commentcamarche.net/forum/virus-securite-7

    AMD Athlon(tm) 64 X2 Dual Core Processor 4200+
    Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702
    Windows Firewall Status : Disabled
    AV : avast! antivirus 4.8.1368 [VPS 100225-0] 4.8.1368 [ (!) Disabled | Updated ]
    FW : NVIDIA Firewall[ (!) Disabled ]1.0

    C:\ -> Disque fixe local | 149,04 Go (98,07 Go free) | NTFS
    D:\ -> Disque CD-ROM

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\WINDOWS\system32\E_S00RP1.EXE
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\List_Kill'em\List_Kill'em.scr
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Documents and Settings\chouc\Local Settings\temp\A.tmp\pv.exe

    ======================
    Keys "Run"
    ======================
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    nTrayFw REG_SZ C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
    SoundMan REG_SZ SOUNDMAN.EXE
    avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    NvMediaCenter REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    ISUSPM REG_SZ "C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
    \\ODEJAVEL\EPSON Stylus D68 Series REG_SZ C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAE.EXE /P34 "\\ODEJAVEL\EPSON Stylus D68 Series" /O6 "USB001" /M "Stylus D68"
    KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]

    =====================
    Other Keys
    =====================
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    dontdisplaylastusername REG_DWORD 0 (0x0)
    legalnoticecaption REG_SZ
    legalnoticetext REG_SZ
    shutdownwithoutlogon REG_DWORD 1 (0x1)
    undockwithoutlogon REG_DWORD 1 (0x1)
    DisableRegistryTools REG_DWORD 0 (0x0)

    ===============
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    NoDriveTypeAutoRun REG_DWORD 323 (0x143)
    NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
    NoDrives REG_DWORD 0 (0x0)

    ===============
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    HonorAutoRunSetting REG_DWORD 1 (0x1)
    NoDriveAutoRun REG_DWORD 67108863 (0x3ffffff)
    NoDriveTypeAutoRun REG_DWORD 323 (0x143)
    NoDrives REG_DWORD 0 (0x0)

    ===============
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

    ===============
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    AutoRestartShell REG_DWORD 1 (0x1)
    DefaultDomainName REG_SZ CHOUCPC
    DefaultUserName REG_SZ chouc
    LegalNoticeCaption REG_SZ
    LegalNoticeText REG_SZ
    PowerdownAfterShutdown REG_SZ 0
    ReportBootOk REG_SZ 1
    Shell REG_SZ Explorer.exe
    ShutdownWithoutLogon REG_SZ 0
    System REG_SZ
    Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
    SfcQuota REG_DWORD -1 (0xffffffff)
    allocatecdroms REG_SZ 0
    allocatedasd REG_SZ 0
    allocatefloppies REG_SZ 0
    cachedlogonscount REG_SZ 10
    forceunlocklogon REG_DWORD 0 (0x0)
    passwordexpirywarning REG_DWORD 14 (0xe)
    scremoveoption REG_SZ 0
    AllowMultipleTSSessions REG_DWORD 1 (0x1)
    UIHost REG_EXPAND_SZ logonui.exe
    LogonType REG_DWORD 1 (0x1)
    Background REG_SZ 0 0 0
    DebugServerCommand REG_SZ no
    SFCDisable REG_DWORD 0 (0x0)
    WinStationsDisabled REG_SZ 0
    HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
    ShowLogonOptions REG_DWORD 0 (0x0)
    AltDefaultUserName REG_SZ chouc
    AltDefaultDomainName REG_SZ CHOUCPC
    ChangePasswordUseKerberos REG_DWORD 1 (0x1)
    EnableConcurrentSessions REG_DWORD 1 (0x1)

    ===============
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]

    ===============
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    {AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ

    ===============
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe REG_SZ C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server
    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
    C:\Program Files\Steam\Steam.exe REG_SZ C:\Program Files\Steam\Steam.exe:*:Enabled:Steam
    C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
    C:\Program Files\InterVideo\DVD8\WinDVD.exe REG_SZ C:\Program Files\InterVideo\DVD8\WinDVD.exe:*:Enabled:WinDVD
    C:\Program Files\Steam\steamapps\choucco\counter-strike source\hl2.exe REG_SZ C:\Program Files\Steam\steamapps\choucco\counter-strike source\hl2.exe:*:Enabled:hl2
    C:\Program Files\Maxima-5.13.0\wxMaxima\wxMaxima.exe REG_SZ C:\Program Files\Maxima-5.13.0\wxMaxima\wxMaxima.exe:*:Enabled:wxMaxima
    C:\Program Files\Maxima-5.13.0\bin\xmaxima.exe REG_SZ C:\Program Files\Maxima-5.13.0\bin\xmaxima.exe:*:Enabled:TclKit = Tcl + IncrTcl + Tk + MetaKit
    C:\Program Files\Free Music Zilla\FMZilla.exe REG_SZ C:\Program Files\Free Music Zilla\FMZilla.exe:*:Enabled:FMZilla
    C:\Program Files\adslTV\adsltv.exe REG_SZ C:\Program Files\adslTV\adsltv.exe:*:Enabled:adsltv
    C:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe REG_SZ C:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe:*:Enabled:Call of Duty: Modern Warfare 2
    C:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe REG_SZ C:\Program Files\Steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe:*:Enabled:Call of Duty: Modern Warfare 2 - Multiplayer
    C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE REG_SZ C:\WINDOWS\system32\spool\drivers\w32x86\3\SAGENT4.EXE:*:Enabled:SAgent4

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    %windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
    %windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

    ===============
    ActivX controls
    ===============
    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-11D1-B3E9-00805F499D93}
    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
    HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}

    ===============
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{283807B5-2C60-11D0-A31D-00AA00B92C03}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4278c270-a269-11d1-b5bf-0000f8051515}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f216970-c90c-11d1-b5c7-0000f8051515}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5945c046-1e7d-11d1-bc44-00c04fd912be}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5A8D6EE0-3E18-11D0-821E-444553540000}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CC2A9BA0-3BDD-11D0-821E-444553540000}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11cf-96B8-444553540000}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}
    HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}

    ==============
    BHO :
    ======
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]

    ===
    DNS
    ===

    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=212.27.40.241 212.27.40.240

    ================
    Internet Explorer :
    ================
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    Start Page REG_SZ https://www.msn.com/fr-fr

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    Start Page REG_SZ https://www.google.com/?gws_rd=ssl

    ========
    Services
    ========
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

    Ndisuio : 0x3 ( OK = 3 )
    EapHost : 0x3 ( OK = 2 )
    SharedAccess : 0x2 ( OK = 2 )
    wuauserv : 0x2 ( OK = 2 )

    =========
    Atapi.sys
    =========

    %%%% HASHDEEP-1.0
    %%%% size,md5,sha256,filename
    ## Invoked from: C:\Documents and Settings\chouc\Local Settings\temp\A.tmp
    ## C:\> hashdeep.exe C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
    ##
    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
    %%%% HASHDEEP-1.0
    %%%% size,md5,sha256,filename
    ## Invoked from: C:\Documents and Settings\chouc\Local Settings\temp\A.tmp
    ## C:\> hashdeep.exe C:\WINDOWS\ERDNT\cache\atapi.sys
    ##
    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ERDNT\cache\atapi.sys
    %%%% HASHDEEP-1.0
    %%%% size,md5,sha256,filename
    ## Invoked from: C:\Documents and Settings\chouc\Local Settings\temp\A.tmp
    ## C:\> hashdeep.exe C:\WINDOWS\ServicePackFiles\i386\atapi.sys
    ##
    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\ServicePackFiles\i386\atapi.sys
    %%%% HASHDEEP-1.0
    %%%% size,md5,sha256,filename
    ## Invoked from: C:\Documents and Settings\chouc\Local Settings\temp\A.tmp
    ## C:\> hashdeep.exe C:\WINDOWS\system32\drivers\atapi.sys
    ##
    96512,9f3a2f5aa6875c72bf062c712cfa2674,b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9,C:\WINDOWS\system32\drivers\atapi.sys
    %%%% HASHDEEP-1.0
    %%%% size,md5,sha256,filename
    ## Invoked from: C:\Documents and Settings\chouc\Local Settings\temp\A.tmp
    ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys
    ##
    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys
    %%%% HASHDEEP-1.0
    %%%% size,md5,sha256,filename
    ## Invoked from: C:\Documents and Settings\chouc\Local Settings\temp\A.tmp
    ## C:\> hashdeep.exe C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys
    ##
    95360,cdfe4411a69c224bd1d11b2da92dac51,0e6b23a80f171550575bebc56f7500cd87a5cf03b2b9fdc49bc3de96282cd69d,C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys

    Référence :
    ==========

    Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
    Win XP_32b : a64013e98426e1877cb653685c5c0009
    Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
    Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
    Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
    Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
    Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
    Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
    Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
    Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C

    =======
    Drive :
    =======

    D‚fragmenteur de disque Windows
    Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.

    Rapport d'analyse
    149 Go total, 98,07 Go libre (65%), 0% fragment‚ (fragmentation du fichier 1%)

    Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.

    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

    Present !! : C:\Documents and Settings\All Users\Application Data\.zreglib
    Present !! : C:\WINDOWS\002569_.tmp
    Present !! : C:\WINDOWS\SET3.tmp
    Present !! : C:\WINDOWS\SET4.tmp
    Present !! : C:\WINDOWS\SET8.tmp
    Present !! : C:\WINDOWS\System32\SET*.tmp
    Present !! : C:\Documents and Settings\chouc\Local Settings\Temp\adn.ppt

    ¤¤¤¤¤¤¤¤¤¤ Keys :

    Present !! : HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
    Present !! : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
    Present !! : HKEY_USERS\S-1-5-21-1644491937-1770027372-839522115-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDrives
    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
    Present !! : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
    Present !! : HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
    Present !! : HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
    Present !! : HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
    Present !! : HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
    Present !! : HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}

    ============

    catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-25 23:41:24
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...
    0
  19. bobo
     
    va sur www.hackme.com et prend le fichier :mypcdontwansurvive
    tout les problemes vont disparaitre don ton diske dur et bien plus !
    cest génial
    0