Virus de pop ups.
mia928
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour, j'ai été asser stupide pour télécharger un fichier pas très safe.. et maintenant je recois des pop ups sans arrêt.. je ne suis pas super bonne avec les ordinateurs.. et en ce moment je suis en train de scanner mon ordi avec Avast... mais de ce que j'ai lu.. ca sert à rien avec ce virus... quelqu'un s'aurait-il comment s'en débarasser?
J'utilise Mozilla Firefox...Windows XP...
J'utilise Mozilla Firefox...Windows XP...
A voir également:
- Virus de pop ups.
- Mcafee virus pop-up - Accueil - Piratage
- Pop corn time - Télécharger - TV & Vidéo
- Demande de retenue pour retrait ups - Forum Consommation & Internet
- Serveur pop - Guide
- Allumer tv avec télécommande freebox pop ✓ - Forum Freebox
69 réponses
Salut mia928
Comme mentionner dans la procédure pour Combofix :
Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure
Au vu du rapport de Gmer, on a un fichier système patché (modifié) :
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
Combofix devrais réparer cela
@++ :)
Comme mentionner dans la procédure pour Combofix :
Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure
Au vu du rapport de Gmer, on a un fichier système patché (modifié) :
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
Combofix devrais réparer cela
@++ :)
Bonjour dédétraqué
Voici le rapport ComboFix:
ComboFix 10-05-15.01 - Zamboni 2010-05-15 14:31:45.3.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.3071.2532 [GMT -3:00]
Lancé depuis: c:\documents and settings\Zamboni\Mes documents\Téléchargements\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-04-15 au 2010-05-15 ))))))))))))))))))))))))))))))))))))
.
2010-05-14 23:10 . 2010-05-14 23:10 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-14 23:10 . 2010-05-14 23:08 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-05-14 23:10 . 2010-05-14 23:08 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-05-14 23:09 . 2010-05-14 23:09 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 56978 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2010-05-14 23:08 . 2010-05-14 23:08 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-14 23:08 . 2010-05-14 23:09 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-05-11 22:08 . 2010-05-11 22:08 503808 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-12fd9ff7-n\msvcp71.dll
2010-05-11 22:08 . 2010-05-11 22:08 499712 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-12fd9ff7-n\jmc.dll
2010-05-11 22:08 . 2010-05-11 22:08 348160 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-12fd9ff7-n\msvcr71.dll
2010-05-11 22:08 . 2010-05-11 22:08 61440 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1f7fe9fa-n\decora-sse.dll
2010-05-11 22:08 . 2010-05-11 22:08 12800 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1f7fe9fa-n\decora-d3d.dll
2010-05-09 21:07 . 2010-05-15 04:11 0 ----a-w- c:\documents and settings\Zamboni\Local Settings\Application Data\prvlcl.dat
2010-05-09 20:53 . 2010-05-09 20:53 -------- d-----w- c:\documents and settings\Zamboni\Application Data\AVG9
2010-05-07 21:11 . 2010-05-07 21:11 -------- d-----w- c:\documents and settings\Zamboni\Local Settings\Application Data\AVG Security Toolbar
2010-05-07 12:58 . 2010-05-07 12:58 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-07 12:58 . 2010-05-07 12:58 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-07 12:58 . 2010-05-07 12:58 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-07 12:58 . 2010-05-07 12:58 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-07 12:57 . 2010-05-07 12:57 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-07 12:57 . 2010-05-07 12:57 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-07 12:57 . 2010-05-15 11:21 -------- d-----w- c:\windows\system32\drivers\Avg
2010-05-07 12:57 . 2010-05-07 12:57 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-05-07 12:47 . 2010-05-07 12:56 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-05-07 12:47 . 2010-05-07 12:47 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-05-07 12:46 . 2010-05-07 12:46 -------- d-----w- c:\program files\AVG
2010-05-07 12:46 . 2010-05-10 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-05-01 19:52 . 2010-05-01 19:52 -------- d-----w- c:\program files\EA GAMES
2010-05-01 19:52 . 2005-02-26 05:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2010-04-29 02:28 . 2010-04-29 02:28 -------- d-----w- c:\documents and settings\Zamboni\Local Settings\Application Data\Yahoo!
2010-04-20 23:45 . 2010-04-20 23:45 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-20 23:44 . 2010-04-20 23:44 79488 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-04-20 23:44 . 2010-04-20 23:44 152576 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-04-20 02:12 . 2010-04-20 02:12 -------- d-----w- c:\program files\ESET
2010-04-18 23:56 . 2010-04-20 23:27 -------- d-----w- c:\program files\trend micro
2010-04-16 21:16 . 2010-04-16 21:16 -------- d-----w- c:\program files\Ares
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-14 23:10 . 2009-02-24 21:15 -------- d-----w- c:\program files\Google
2010-05-14 23:09 . 2009-11-04 03:26 -------- d-----w- c:\program files\DivX
2010-05-08 15:16 . 2009-05-15 23:08 -------- d-----w- c:\program files\Messenger Plus! Live
2010-04-20 23:47 . 2008-07-03 19:45 -------- d-----w- c:\program files\CCleaner
2010-04-20 23:37 . 2008-07-03 19:46 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-04-18 23:14 . 2009-02-14 00:15 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-17 00:31 . 2008-08-14 20:43 -------- d-----w- c:\program files\Fichiers communs\DVDVIDEOSOFT
2010-04-16 21:26 . 2010-03-08 00:58 -------- d-----w- c:\documents and settings\Zamboni\Application Data\LimeWire
2010-04-13 10:27 . 2010-04-13 10:26 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-13 10:27 . 2008-12-28 12:06 -------- d-----w- c:\program files\iTunes
2010-04-13 10:26 . 2010-04-13 10:26 -------- d-----w- c:\program files\iPod
2010-04-13 10:26 . 2008-12-28 12:05 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-04-13 10:24 . 2010-04-13 10:24 -------- d-----w- c:\program files\QuickTime
2010-04-13 10:22 . 2010-04-13 10:22 -------- d-----w- c:\program files\Bonjour
2010-04-13 10:20 . 2010-04-13 10:20 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-10 22:30 . 2010-04-10 22:30 532 ----a-w- c:\windows\eReg.dat
2010-04-10 22:29 . 2010-04-10 22:29 -------- d-----w- c:\program files\Maxis
2010-03-23 02:46 . 2010-02-05 21:26 50354 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\uninstall.exe
2010-03-23 02:46 . 2010-02-05 21:26 -------- d-----w- c:\documents and settings\Zamboni\Application Data\Facebook
2010-03-15 03:49 . 2010-03-15 03:49 503808 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\msvcp71.dll
2010-03-15 03:49 . 2010-03-15 03:49 499712 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\jmc.dll
2010-03-15 03:49 . 2010-03-15 03:49 348160 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\msvcr71.dll
2010-03-15 03:49 . 2010-03-15 03:49 61440 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28a3a294-n\decora-sse.dll
2010-03-15 03:49 . 2010-03-15 03:49 12800 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28a3a294-n\decora-d3d.dll
2010-03-15 03:48 . 2006-03-02 12:00 85608 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-15 03:48 . 2006-03-02 12:00 513410 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-14 16:48 . 2009-11-11 17:56 79488 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-11 12:34 . 2006-03-02 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:34 . 2009-10-27 15:14 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:34 . 2006-03-02 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2006-03-02 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-02-24 13:11 . 2006-03-02 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 01:32 . 2010-02-17 01:32 0 -c--a-w- c:\documents and settings\Zamboni\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-02-16 19:06 . 2006-03-02 12:00 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2004-08-19 16:04 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2008-11-02 21:06 . 2008-11-02 21:06 89408 -c--a-w- c:\program files\setup spiral frog.exe
2008-09-30 01:36 . 2008-09-30 01:36 5408074 -c--a-w- c:\program files\Last.fm-1.5.2.38918.exe
2008-08-14 19:17 . 2008-08-14 19:17 611424 -c--a-w- c:\program files\setuppad.exe
2008-08-02 05:35 . 2008-08-02 05:35 1283912 -c--a-w- c:\program files\WoW-2.3.0.7561-enUS-downloader.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-04-21_20.09.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 23:54 . 2009-07-11 23:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-12 04:07 . 2009-07-12 04:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 04:19 . 2009-07-12 04:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-11 22:41 . 2009-07-11 22:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-05-15 17:23 . 2010-05-15 17:23 16384 c:\windows\Temp\Perflib_Perfdata_284.dat
+ 2008-07-03 19:35 . 2010-05-12 06:01 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-07-03 05:47 . 2010-01-29 15:00 691712 c:\windows\system32\inetcomm.dll
- 2008-07-03 05:47 . 2008-04-11 19:05 691712 c:\windows\system32\inetcomm.dll
- 2008-08-15 00:51 . 2008-04-11 19:05 691712 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-08-15 00:51 . 2010-01-29 15:00 691712 c:\windows\system32\dllcache\inetcomm.dll
+ 2010-05-07 12:41 . 2010-05-07 12:41 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2010-05-14 23:09 . 2010-05-14 23:09 169472 c:\windows\Installer\dfe362.msi
+ 2010-05-07 12:46 . 2010-05-07 12:46 424448 c:\windows\Installer\143aba.msi
- 2008-07-03 19:35 . 2010-04-15 06:00 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-07-11 23:46 . 2009-07-11 23:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 23:46 . 2009-07-11 23:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
- 2008-07-03 05:47 . 2009-07-10 13:27 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2008-07-03 05:47 . 2010-01-29 15:00 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2010-04-21 20:46 . 2010-04-21 20:46 5522432 c:\windows\Installer\24b7f6d.msp
+ 2008-07-04 13:29 . 2010-04-30 18:51 32058312 c:\windows\system32\MRT.exe
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\92e86.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\8bf289.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\83263.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\727d2c7.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\45cfe80.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3a20340.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3a0e4d0.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\385d04.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\377081.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\35ba7e6.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3570c45.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\32b118b.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3286632.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2f56995.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\29a3001.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2693f.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\257f6c2.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\23e459c.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\230d6d4.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2244a1f.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\22440a9.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\22236b0.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\1f43884.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\18fba71.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\18d60c2.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\138714a.msp
.
Voici le rapport ComboFix:
ComboFix 10-05-15.01 - Zamboni 2010-05-15 14:31:45.3.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.3071.2532 [GMT -3:00]
Lancé depuis: c:\documents and settings\Zamboni\Mes documents\Téléchargements\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-04-15 au 2010-05-15 ))))))))))))))))))))))))))))))))))))
.
2010-05-14 23:10 . 2010-05-14 23:10 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-05-14 23:10 . 2010-05-14 23:08 754984 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-05-14 23:10 . 2010-05-14 23:08 1180952 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-05-14 23:09 . 2010-05-14 23:09 56766 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 56978 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-05-14 23:09 . 2010-05-14 23:09 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2010-05-14 23:08 . 2010-05-14 23:08 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-05-14 23:08 . 2010-05-14 23:09 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-05-11 22:08 . 2010-05-11 22:08 503808 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-12fd9ff7-n\msvcp71.dll
2010-05-11 22:08 . 2010-05-11 22:08 499712 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-12fd9ff7-n\jmc.dll
2010-05-11 22:08 . 2010-05-11 22:08 348160 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-12fd9ff7-n\msvcr71.dll
2010-05-11 22:08 . 2010-05-11 22:08 61440 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1f7fe9fa-n\decora-sse.dll
2010-05-11 22:08 . 2010-05-11 22:08 12800 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-1f7fe9fa-n\decora-d3d.dll
2010-05-09 21:07 . 2010-05-15 04:11 0 ----a-w- c:\documents and settings\Zamboni\Local Settings\Application Data\prvlcl.dat
2010-05-09 20:53 . 2010-05-09 20:53 -------- d-----w- c:\documents and settings\Zamboni\Application Data\AVG9
2010-05-07 21:11 . 2010-05-07 21:11 -------- d-----w- c:\documents and settings\Zamboni\Local Settings\Application Data\AVG Security Toolbar
2010-05-07 12:58 . 2010-05-07 12:58 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-07 12:58 . 2010-05-07 12:58 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-07 12:58 . 2010-05-07 12:58 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-07 12:58 . 2010-05-07 12:58 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-07 12:57 . 2010-05-07 12:57 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-07 12:57 . 2010-05-07 12:57 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-07 12:57 . 2010-05-15 11:21 -------- d-----w- c:\windows\system32\drivers\Avg
2010-05-07 12:57 . 2010-05-07 12:57 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-05-07 12:47 . 2010-05-07 12:56 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-05-07 12:47 . 2010-05-07 12:47 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-05-07 12:46 . 2010-05-07 12:46 -------- d-----w- c:\program files\AVG
2010-05-07 12:46 . 2010-05-10 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-05-01 19:52 . 2010-05-01 19:52 -------- d-----w- c:\program files\EA GAMES
2010-05-01 19:52 . 2005-02-26 05:34 442368 ----a-r- c:\windows\system32\vp6vfw.dll
2010-04-29 02:28 . 2010-04-29 02:28 -------- d-----w- c:\documents and settings\Zamboni\Local Settings\Application Data\Yahoo!
2010-04-20 23:45 . 2010-04-20 23:45 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-20 23:44 . 2010-04-20 23:44 79488 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-04-20 23:44 . 2010-04-20 23:44 152576 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-04-20 02:12 . 2010-04-20 02:12 -------- d-----w- c:\program files\ESET
2010-04-18 23:56 . 2010-04-20 23:27 -------- d-----w- c:\program files\trend micro
2010-04-16 21:16 . 2010-04-16 21:16 -------- d-----w- c:\program files\Ares
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-14 23:10 . 2009-02-24 21:15 -------- d-----w- c:\program files\Google
2010-05-14 23:09 . 2009-11-04 03:26 -------- d-----w- c:\program files\DivX
2010-05-08 15:16 . 2009-05-15 23:08 -------- d-----w- c:\program files\Messenger Plus! Live
2010-04-20 23:47 . 2008-07-03 19:45 -------- d-----w- c:\program files\CCleaner
2010-04-20 23:37 . 2008-07-03 19:46 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-04-18 23:14 . 2009-02-14 00:15 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-17 00:31 . 2008-08-14 20:43 -------- d-----w- c:\program files\Fichiers communs\DVDVIDEOSOFT
2010-04-16 21:26 . 2010-03-08 00:58 -------- d-----w- c:\documents and settings\Zamboni\Application Data\LimeWire
2010-04-13 10:27 . 2010-04-13 10:26 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-13 10:27 . 2008-12-28 12:06 -------- d-----w- c:\program files\iTunes
2010-04-13 10:26 . 2010-04-13 10:26 -------- d-----w- c:\program files\iPod
2010-04-13 10:26 . 2008-12-28 12:05 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-04-13 10:24 . 2010-04-13 10:24 -------- d-----w- c:\program files\QuickTime
2010-04-13 10:22 . 2010-04-13 10:22 -------- d-----w- c:\program files\Bonjour
2010-04-13 10:20 . 2010-04-13 10:20 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-10 22:30 . 2010-04-10 22:30 532 ----a-w- c:\windows\eReg.dat
2010-04-10 22:29 . 2010-04-10 22:29 -------- d-----w- c:\program files\Maxis
2010-03-23 02:46 . 2010-02-05 21:26 50354 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\uninstall.exe
2010-03-23 02:46 . 2010-02-05 21:26 -------- d-----w- c:\documents and settings\Zamboni\Application Data\Facebook
2010-03-15 03:49 . 2010-03-15 03:49 503808 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\msvcp71.dll
2010-03-15 03:49 . 2010-03-15 03:49 499712 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\jmc.dll
2010-03-15 03:49 . 2010-03-15 03:49 348160 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\msvcr71.dll
2010-03-15 03:49 . 2010-03-15 03:49 61440 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28a3a294-n\decora-sse.dll
2010-03-15 03:49 . 2010-03-15 03:49 12800 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28a3a294-n\decora-d3d.dll
2010-03-15 03:48 . 2006-03-02 12:00 85608 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-15 03:48 . 2006-03-02 12:00 513410 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-14 16:48 . 2009-11-11 17:56 79488 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-11 12:34 . 2006-03-02 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:34 . 2009-10-27 15:14 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:34 . 2006-03-02 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2006-03-02 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-06 05:30 . 2010-03-06 05:30 5582848 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-02-24 13:11 . 2006-03-02 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 01:32 . 2010-02-17 01:32 0 -c--a-w- c:\documents and settings\Zamboni\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-02-16 19:06 . 2006-03-02 12:00 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2004-08-19 16:04 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2008-11-02 21:06 . 2008-11-02 21:06 89408 -c--a-w- c:\program files\setup spiral frog.exe
2008-09-30 01:36 . 2008-09-30 01:36 5408074 -c--a-w- c:\program files\Last.fm-1.5.2.38918.exe
2008-08-14 19:17 . 2008-08-14 19:17 611424 -c--a-w- c:\program files\setuppad.exe
2008-08-02 05:35 . 2008-08-02 05:35 1283912 -c--a-w- c:\program files\WoW-2.3.0.7561-enUS-downloader.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-04-21_20.09.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 23:54 . 2009-07-11 23:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-11 23:32 . 2009-07-11 23:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-12 04:07 . 2009-07-12 04:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 04:19 . 2009-07-12 04:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-11 22:41 . 2009-07-11 22:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-05-15 17:23 . 2010-05-15 17:23 16384 c:\windows\Temp\Perflib_Perfdata_284.dat
+ 2008-07-03 19:35 . 2010-05-12 06:01 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 23040 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 61440 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 27136 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 11264 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 86016 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 12288 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 4096 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-07-03 05:47 . 2010-01-29 15:00 691712 c:\windows\system32\inetcomm.dll
- 2008-07-03 05:47 . 2008-04-11 19:05 691712 c:\windows\system32\inetcomm.dll
- 2008-08-15 00:51 . 2008-04-11 19:05 691712 c:\windows\system32\dllcache\inetcomm.dll
+ 2008-08-15 00:51 . 2010-01-29 15:00 691712 c:\windows\system32\dllcache\inetcomm.dll
+ 2010-05-07 12:41 . 2010-05-07 12:41 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2010-05-14 23:09 . 2010-05-14 23:09 169472 c:\windows\Installer\dfe362.msi
+ 2010-05-07 12:46 . 2010-05-07 12:46 424448 c:\windows\Installer\143aba.msi
- 2008-07-03 19:35 . 2010-04-15 06:00 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 409600 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 286720 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 249856 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 794624 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 135168 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-07-03 19:35 . 2010-05-12 06:01 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-07-03 19:35 . 2010-04-15 06:00 593920 c:\windows\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-07-11 23:46 . 2009-07-11 23:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-11 23:46 . 2009-07-11 23:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
- 2008-07-03 05:47 . 2009-07-10 13:27 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2008-07-03 05:47 . 2010-01-29 15:00 1315328 c:\windows\system32\dllcache\msoe.dll
+ 2010-04-21 20:46 . 2010-04-21 20:46 5522432 c:\windows\Installer\24b7f6d.msp
+ 2008-07-04 13:29 . 2010-04-30 18:51 32058312 c:\windows\system32\MRT.exe
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\92e86.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\8bf289.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\83263.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\727d2c7.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\45cfe80.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3a20340.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3a0e4d0.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\385d04.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\377081.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\35ba7e6.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3570c45.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\32b118b.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\3286632.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2f56995.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\29a3001.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2693f.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\257f6c2.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\23e459c.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\230d6d4.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2244a1f.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\22440a9.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\22236b0.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\1f43884.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\18fba71.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\18d60c2.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\138714a.msp
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 13:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
"WeatherEye"="c:\documents and settings\Zamboni\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-10-27 718232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VM30xSnap"="VM30xSnap.exe Vimicro USB PC Camera (ZC030x)" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-08-14 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-08-14 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-08-14 94208]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"Window UDP Control Servic"="winlogon.exe" [2008-04-14 512000]
"SlipStream"="c:\program files\Netscape Accélérateur\slipcore.exe" [2006-04-06 237568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Belkin Wireless G Desktop Card Client Utility.lnk - c:\program files\Belkin\F5D7000v7032\Belkinwcui.exe [2010-1-28 1560576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 15:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-07 12:58 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 18:43 69632 -c----r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 20:36 455968 ----a-w- c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-04-10 15:28 16126464 -c----r- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-04-04 17:22 1822720 -c----r- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-01-21 15:17 61440 -c--a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Warcraft III\\War3.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-05-07 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-05-07 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-05-07 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-05-07 242896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-05-07 308064]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-05-07 2325816]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-05-07 5888008]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [2010-02-07 17984]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2008-07-03 35840]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-05-07 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [2010-05-07 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [2010-05-07 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [2010-05-07 26120]
R3 Belkin700F;Belkin Wireless G Desktop Card Service v7;c:\windows\system32\drivers\BLKWGDv7.sys [2010-01-24 303616]
R3 VM30xx86;Vimicro USB PC Camera (ZC030x);c:\windows\system32\drivers\vm30xx86.sys [2009-02-24 1294336]
S2 gupdate1c996c4f9b01916;Google Update Service (gupdate1c996c4f9b01916);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-05-07 430152]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-05-07 30104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys --> c:\windows\System32\Drivers\SjyPkt.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 20:34 451872 ----a-w- c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'
2010-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 21:15]
2010-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 21:15]
2010-05-15 c:\windows\Tasks\User_Feed_Synchronization-{1976200C-4A2E-4FAC-9D4C-74B0D23C66DA}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 21:36]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://facebook.com/
uInternet Settings,ProxyOverride = *.local
IE: Save YouTube Video - c:\program files\Fichiers communs\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
IE: Save YouTube Video as MP3 - c:\program files\Fichiers communs\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
LSP: c:\progra~1\NETSCA~2\sliplsp.dll
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://download.playfirst.com/play/game/chocolatier2/Chocolatier2Web.1.0.0.10.cab
FF - ProfilePath - c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - component: c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\Zamboni\Local Settings\Application Data\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
.
------- Associations de fichier -------
.
.scr=AutoCADLTScriptFile
.
**************************************************************************
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32]
@DACL=(02 0000)
@="c:\\Program Files\\MyWebSearch\\bar\\2.bin\\F3REPROX.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€-€|ÿÿÿÿÀ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1268)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1324)
c:\progra~1\NETSCA~2\sliplsp.dll
c:\windows\system32\sliprt.dll
.
Heure de fin: 2010-05-15 14:39:33
ComboFix-quarantined-files.txt 2010-05-15 17:39
ComboFix2.txt 2010-04-27 03:35
ComboFix3.txt 2010-04-21 20:10
Avant-CF: 63 012 765 696 octets libres
Après-CF: 63 065 378 816 octets libres
- - End Of File - - 9997CCF054FAC20D0D015081B3D3A9C7
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 13:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
"WeatherEye"="c:\documents and settings\Zamboni\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-10-27 718232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VM30xSnap"="VM30xSnap.exe Vimicro USB PC Camera (ZC030x)" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-08-14 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-08-14 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-08-14 94208]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"Window UDP Control Servic"="winlogon.exe" [2008-04-14 512000]
"SlipStream"="c:\program files\Netscape Accélérateur\slipcore.exe" [2006-04-06 237568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Belkin Wireless G Desktop Card Client Utility.lnk - c:\program files\Belkin\F5D7000v7032\Belkinwcui.exe [2010-1-28 1560576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 15:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-07 12:58 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 18:43 69632 -c----r- c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 20:36 455968 ----a-w- c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-04-10 15:28 16126464 -c----r- c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-04-04 17:22 1822720 -c----r- c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-01-21 15:17 61440 -c--a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Warcraft III\\War3.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-05-07 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-05-07 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-05-07 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-05-07 242896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-05-07 308064]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [2010-05-07 2325816]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-05-07 5888008]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [2010-02-07 17984]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2008-07-03 35840]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-05-07 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [2010-05-07 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [2010-05-07 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [2010-05-07 26120]
R3 Belkin700F;Belkin Wireless G Desktop Card Service v7;c:\windows\system32\drivers\BLKWGDv7.sys [2010-01-24 303616]
R3 VM30xx86;Vimicro USB PC Camera (ZC030x);c:\windows\system32\drivers\vm30xx86.sys [2009-02-24 1294336]
S2 gupdate1c996c4f9b01916;Google Update Service (gupdate1c996c4f9b01916);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\AVG\AVG9\Toolbar\ToolbarBroker.exe [2010-05-07 430152]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-05-07 30104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys --> c:\windows\System32\Drivers\SjyPkt.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 20:34 451872 ----a-w- c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'
2010-05-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 21:15]
2010-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 21:15]
2010-05-15 c:\windows\Tasks\User_Feed_Synchronization-{1976200C-4A2E-4FAC-9D4C-74B0D23C66DA}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 21:36]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://facebook.com/
uInternet Settings,ProxyOverride = *.local
IE: Save YouTube Video - c:\program files\Fichiers communs\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
IE: Save YouTube Video as MP3 - c:\program files\Fichiers communs\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
LSP: c:\progra~1\NETSCA~2\sliplsp.dll
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://download.playfirst.com/play/game/chocolatier2/Chocolatier2Web.1.0.0.10.cab
FF - ProfilePath - c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - component: c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\Zamboni\Local Settings\Application Data\Yahoo!\BrowserPlus\2.7.1\Plugins\npybrowserplus_2.7.1.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
.
------- Associations de fichier -------
.
.scr=AutoCADLTScriptFile
.
**************************************************************************
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés:
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32]
@DACL=(02 0000)
@="c:\\Program Files\\MyWebSearch\\bar\\2.bin\\F3REPROX.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€-€|ÿÿÿÿÀ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1268)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1324)
c:\progra~1\NETSCA~2\sliplsp.dll
c:\windows\system32\sliprt.dll
.
Heure de fin: 2010-05-15 14:39:33
ComboFix-quarantined-files.txt 2010-05-15 17:39
ComboFix2.txt 2010-04-27 03:35
ComboFix3.txt 2010-04-21 20:10
Avant-CF: 63 012 765 696 octets libres
Après-CF: 63 065 378 816 octets libres
- - End Of File - - 9997CCF054FAC20D0D015081B3D3A9C7
Salut dédétraqué..
Est-ce possible que l'un ou plusieurs des programmes que vous m'avez faite installer sur mon ordinateur aurais pu le ralentir?
Je trouve que depuis un certain temps (a peu près lorque j'ai commencé à installer des programmes), mon ordi se montre plus lent que d'habitude.
Merci!
Est-ce possible que l'un ou plusieurs des programmes que vous m'avez faite installer sur mon ordinateur aurais pu le ralentir?
Je trouve que depuis un certain temps (a peu près lorque j'ai commencé à installer des programmes), mon ordi se montre plus lent que d'habitude.
Merci!
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Salut mia928
Désolé j'ai été fort occupé cette fin de semaine...
Est-ce possible que l'un ou plusieurs des programmes que vous m'avez faite installer sur mon ordinateur aurais pu le ralentir?
Comme je l'ai dit plus haut ton PC étais encore infecté et fichier système modifié.
Télécharge Gmer et enregistre-le sur ton bureau.
http://www2.gmer.net/download.php
- Déconnecte toi d'internet si possible et ferme tous les programmes, puis lance l'outil.
- Clique sur le bouton "Scan" sur la droite.
- Lorsque le scan est terminé, clic sur "Copy".
- Ouvre le bloc-note et clic sur le Menu Edition / Coller
- Le rapport doit alors apparaître.
- Enregistre le fichier sur ton bureau et copie/colle le contenu ici.
@++ :)
Désolé j'ai été fort occupé cette fin de semaine...
Est-ce possible que l'un ou plusieurs des programmes que vous m'avez faite installer sur mon ordinateur aurais pu le ralentir?
Comme je l'ai dit plus haut ton PC étais encore infecté et fichier système modifié.
Télécharge Gmer et enregistre-le sur ton bureau.
http://www2.gmer.net/download.php
- Déconnecte toi d'internet si possible et ferme tous les programmes, puis lance l'outil.
- Clique sur le bouton "Scan" sur la droite.
- Lorsque le scan est terminé, clic sur "Copy".
- Ouvre le bloc-note et clic sur le Menu Edition / Coller
- Le rapport doit alors apparaître.
- Enregistre le fichier sur ton bureau et copie/colle le contenu ici.
@++ :)
Salut dédétraqué
Ahh, alors l'infection ralentit mon ordi?
Voici le rapport:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-18 07:09:23
Windows 5.1.2600 Service Pack 3
Running: z0vjw5ke.exe; Driver: C:\DOCUME~1\Zamboni\LOCALS~1\Temp\fxrorkoc.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xAB942670]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xADCC8F20]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xAB9427C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xAB942860]
---- Kernel code sections - GMER 1.0.15 ----
.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF7325780]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6669000, 0x19DA46, 0xE8000020]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\atapi \Device\Ide\IdePort0 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort1 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort2 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort3 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort4 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort5 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-16 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-b [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\ProgID@ Office.awsdc.1
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\TypeLib@ {012F24C1-35B0-11D0-BF2D-0000E8D0D146}
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\VersionIndependentProgID@ Office.awsdc
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ C:\WINDOWS\system32\PortableDeviceTypes.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MSPUB.EXE /Automation
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@LocalServer32 *]gAVn-}f(ZXfeAR6.jiPubPrimary>dic+V~SM09P_'_@$%)xK /Automation?
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\NotInsertable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\ProgID@ Publisher.Application.11
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\Programmable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\TypeLib@ {0002123C-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\VersionIndependentProgID@ Publisher.Application
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\ITIRCL52.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@InprocServer32 *]gAVn-}f(ZXfeAR6.jiTranslationHidden>BbxH8x=!g(3?!!!_GX=b?
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\ProgID@ ITIR.DefaultStemmer.5.2
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Ahh, alors l'infection ralentit mon ordi?
Voici le rapport:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-18 07:09:23
Windows 5.1.2600 Service Pack 3
Running: z0vjw5ke.exe; Driver: C:\DOCUME~1\Zamboni\LOCALS~1\Temp\fxrorkoc.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xAB942670]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xADCC8F20]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xAB9427C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xAB942860]
---- Kernel code sections - GMER 1.0.15 ----
.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF7325780]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6669000, 0x19DA46, 0xE8000020]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\atapi \Device\Ide\IdePort0 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort1 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort2 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort3 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort4 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort5 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-16 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-b [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\ProgID@ Office.awsdc.1
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\TypeLib@ {012F24C1-35B0-11D0-BF2D-0000E8D0D146}
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\VersionIndependentProgID@ Office.awsdc
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ C:\WINDOWS\system32\PortableDeviceTypes.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MSPUB.EXE /Automation
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@LocalServer32 *]gAVn-}f(ZXfeAR6.jiPubPrimary>dic+V~SM09P_'_@$%)xK /Automation?
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\NotInsertable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\ProgID@ Publisher.Application.11
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\Programmable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\TypeLib@ {0002123C-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\VersionIndependentProgID@ Publisher.Application
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\ITIRCL52.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@InprocServer32 *]gAVn-}f(ZXfeAR6.jiTranslationHidden>BbxH8x=!g(3?!!!_GX=b?
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\ProgID@ ITIR.DefaultStemmer.5.2
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\DefaultIcon@ C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE,7
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command@ "C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE"
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}@
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ThreadingModel apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ProgID@ KmlLayerRootCoClass.KmlLayerRootCoC.1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ToolboxBitmap32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll, 1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\TypeLib@ {F9152AEC-3462-4632-8087-EEE3C3CDDA35}
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\VersionIndependentProgID@ KmlLayerRootCoClass.KmlLayerRootCoC
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ %SystemRoot%\system32\dsuiext.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu@ 1
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32@ C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\sys_drv.dat 6024 bytes
File C:\WINDOWS\system32\sys_drv_2.dat 5020 bytes
File C:\WINDOWS\system32\WinFLdrv.sys 17984 bytes executable <-- ROOTKIT !!!
File C:\Documents and Settings\Zamboni\Application Data\systemfl.$dk 990 bytes
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\WinFLdrv.sys [AUTO] WinFLdrv <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
Merci!
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\DefaultIcon@ C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE,7
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command@ "C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE"
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}@
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ThreadingModel apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ProgID@ KmlLayerRootCoClass.KmlLayerRootCoC.1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ToolboxBitmap32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll, 1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\TypeLib@ {F9152AEC-3462-4632-8087-EEE3C3CDDA35}
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\VersionIndependentProgID@ KmlLayerRootCoClass.KmlLayerRootCoC
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ %SystemRoot%\system32\dsuiext.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu@ 1
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32@ C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\sys_drv.dat 6024 bytes
File C:\WINDOWS\system32\sys_drv_2.dat 5020 bytes
File C:\WINDOWS\system32\WinFLdrv.sys 17984 bytes executable <-- ROOTKIT !!!
File C:\Documents and Settings\Zamboni\Application Data\systemfl.$dk 990 bytes
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\WinFLdrv.sys [AUTO] WinFLdrv <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
Merci!
Salut mia928
Combofix n'a pas réparer, on va voir avec un fichier de remplacement pour le fichier système atapi.sys :
Télécharge SystemLook sur ton Bureau :
http://jpshortstuff.247fixes.com/SystemLook.exe
- Double-clique sur SystemLook.exe pour le lancer.
- Copie le contenu en gras ci-dessous et colle-le dans la zone texte de SystemLook :
:filefind
atapi.sys
- Clique sur le bouton Look pour démarrer l'examen.
- A la fin, le Bloc-notes s'ouvre avec le résultat de l'analyse. Copie-colle le rapport dans ta prochaine réponse.
@++ :)
Combofix n'a pas réparer, on va voir avec un fichier de remplacement pour le fichier système atapi.sys :
Télécharge SystemLook sur ton Bureau :
http://jpshortstuff.247fixes.com/SystemLook.exe
- Double-clique sur SystemLook.exe pour le lancer.
- Copie le contenu en gras ci-dessous et colle-le dans la zone texte de SystemLook :
:filefind
atapi.sys
- Clique sur le bouton Look pour démarrer l'examen.
- A la fin, le Bloc-notes s'ouvre avec le résultat de l'analyse. Copie-colle le rapport dans ta prochaine réponse.
@++ :)
Bonjour dédétraqué
Voici le rapport:
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 23:08 on 19/05/2010 by Zamboni (Administrator - Elevation successful)
========== filefind ==========
Searching for "atapi.sys "
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys -----c 95360 bytes [18:02 17/10/2008] [01:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\ERDNT\cache\atapi.sys --a--- 96512 bytes [20:09 21/04/2010] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\ServicePackFiles\i386\atapi.sys -----c 96512 bytes [18:40 13/04/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys --a--- 96512 bytes [12:00 02/03/2006] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [12:00 02/03/2006] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [12:00 02/03/2006] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [01:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
-=End Of File=-
Merci!
Voici le rapport:
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 23:08 on 19/05/2010 by Zamboni (Administrator - Elevation successful)
========== filefind ==========
Searching for "atapi.sys "
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys -----c 95360 bytes [18:02 17/10/2008] [01:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\ERDNT\cache\atapi.sys --a--- 96512 bytes [20:09 21/04/2010] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\ServicePackFiles\i386\atapi.sys -----c 96512 bytes [18:40 13/04/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys --a--- 96512 bytes [12:00 02/03/2006] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [12:00 02/03/2006] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [12:00 02/03/2006] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [01:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
-=End Of File=-
Merci!