Pub Meta-search et tringaloo
Résolu/Fermé
Ticki84
Messages postés
844
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
-
24 juin 2011 à 18:03
Ticki84 Messages postés 844 Date d'inscription mardi 17 août 2010 Statut Membre Dernière intervention 26 décembre 2017 - 28 juin 2011 à 22:12
Ticki84 Messages postés 844 Date d'inscription mardi 17 août 2010 Statut Membre Dernière intervention 26 décembre 2017 - 28 juin 2011 à 22:12
A voir également:
- Pub Meta-search et tringaloo
- Fr alert pub - Guide
- Stop pub - Télécharger - Divers Utilitaires
- Meta quest pro - Guide
- Mega search - Télécharger - Divers Web & Internet
- Méta - Guide
22 réponses
Ticki84
Messages postés
844
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
159
28 juin 2011 à 15:51
28 juin 2011 à 15:51
Je n'ai plus les pubs même si je n'ai pas suivis la dernière étape, dois-je comme même la suivre ? Sinon merci de ton aide.
Ticki84
Messages postés
844
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
159
28 juin 2011 à 21:38
28 juin 2011 à 21:38
ComboFix 11-06-27.04 - Administrateur 28/06/2011 19:11:39.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.3071.2423 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\npf.sys
.
.
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ADXAPIE
-------\Legacy_NPF
-------\Service_adxapie
-------\Service_npf
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-05-28 au 2011-06-28 ))))))))))))))))))))))))))))))))))))
.
.
2011-06-28 17:17 . 2011-06-28 17:17 -------- d-----w-Ä? c:\windows\system32\!2AC2~1
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- C:\videooutput
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- c:\program files\Freez FLV to AVI MPEG WMV Converter
2011-06-28 15:49 . 2009-06-04 11:17 8676883 ----a-w- c:\windows\system32\NCMedia2.dll
2011-06-28 15:49 . 2008-10-08 08:16 139264 ----a-w- c:\windows\system32\xvid.ax
2011-06-28 15:26 . 2011-06-28 17:08 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\windows\LastGood.Tmp
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\program files\Hamachi
2011-06-28 15:18 . 2011-06-28 15:18 -------- d-----w- C:\My Videos
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\documents and settings\Administrateur\Application Data\aHisoft
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\program files\Video Sharer
2011-06-28 15:06 . 2011-06-28 15:06 -------- d-----w-Ä? c:\windows\system32\!2ACE~1
2011-06-28 14:09 . 2011-06-28 17:06 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2011-06-28 14:09 . 2011-06-28 14:09 -------- d-----r- c:\program files\Skype
2011-06-28 14:08 . 2011-06-28 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2011-06-28 12:34 . 2011-06-28 12:34 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Foxit Software
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\xircom
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\wbem\snmp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\oobe
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\npp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\msagent
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\program files\microsoft frontpage
2011-06-27 06:50 . 2011-06-27 06:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\Foxit Software
2011-06-27 05:42 . 2010-05-07 10:37 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2011-06-27 05:42 . 2010-05-07 10:37 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2011-06-27 00:21 . 2011-06-27 00:21 623 ----a-w- C:\gb.exe
2011-06-26 20:40 . 2011-06-26 23:58 -------- d-----w- c:\documents and settings\Administrateur\Application Data\.minecraft
2011-06-26 16:04 . 2011-06-26 16:33 97859 ----a-w- c:\windows\system32\drivers\klick.dat
2011-06-26 16:04 . 2011-06-26 16:33 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-06-26 16:03 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2011-06-26 16:03 . 2011-06-26 16:03 -------- d-----w- c:\program files\Kaspersky Lab
2011-06-26 16:01 . 2011-06-26 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2011-06-26 13:54 . 2011-06-26 21:45 -------- d-----w- c:\program files\eMule
2011-06-24 18:47 . 2011-06-24 18:47 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\program files\Fichiers communs\Steam
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\documents and settings\All Users\Menu Dmarrer
2011-06-24 17:31 . 2011-06-26 10:00 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-06-23 18:49 . 2011-06-23 18:49 -------- d-----w- c:\windows\system32\Ä?
2011-06-23 18:44 . 2011-06-23 18:44 -------- d-----w- C:\Updater
2011-06-23 16:48 . 2010-10-05 19:26 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll
2011-06-23 16:48 . 2010-10-05 19:27 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll
2011-06-23 11:01 . 2011-06-23 11:01 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Pinnacle
2011-06-23 05:06 . 2005-09-23 20:18 171520 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2011-06-23 05:06 . 2011-06-23 05:06 -------- d-----w- c:\program files\Fichiers communs\Pinnacle
2011-06-23 05:05 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate Collection
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Pegasus Imaging
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Yahoo!
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Studio 14
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Plus
2011-06-22 17:26 . 2011-06-22 17:26 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Safe mirror
2011-06-22 17:26 . 2011-06-28 12:27 -------- d-----w- c:\program files\Cobian Backup 10
2011-06-22 14:33 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2011-06-22 14:33 . 2011-06-23 05:02 -------- d-----w- c:\program files\Pinnacle
2011-06-22 14:30 . 2011-06-22 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\CrystalIdea Software
2011-06-22 07:14 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-06-21 22:27 . 2011-06-21 22:27 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\PackageAware
2011-06-21 22:09 . 2011-02-09 13:54 270848 ------w- c:\windows\system32\dllcache\sbe.dll
2011-06-21 22:09 . 2011-02-09 13:54 186880 ------w- c:\windows\system32\dllcache\encdec.dll
2011-06-21 22:08 . 2010-08-27 05:58 99840 ------w- c:\windows\system32\dllcache\srvsvc.dll
2011-06-21 22:08 . 2011-01-27 11:57 677888 ------w- c:\windows\system32\dllcache\lhmstsc.exe
2011-06-21 22:08 . 2011-02-02 07:59 2067456 ------w- c:\windows\system32\dllcache\lhmstscx.dll
2011-06-21 22:08 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-21 22:07 . 2011-01-21 14:44 441344 ------w- c:\windows\system32\dllcache\shimgvw.dll
2011-06-21 22:06 . 2010-07-16 12:06 1287680 ------w- c:\windows\system32\dllcache\ole32.dll
2011-06-21 22:06 . 2010-07-16 12:04 221696 ------w- c:\windows\system32\dllcache\wordpad.exe
2011-06-21 22:06 . 2010-11-09 14:52 536576 ------w- c:\windows\system32\dllcache\msado15.dll
2011-06-21 22:06 . 2010-11-09 14:52 249856 ------w- c:\windows\system32\dllcache\odbc32.dll
2011-06-21 22:06 . 2010-11-09 14:52 200704 ------w- c:\windows\system32\dllcache\msadox.dll
2011-06-21 22:06 . 2010-11-09 14:52 180224 ------w- c:\windows\system32\dllcache\msadomd.dll
2011-06-21 22:06 . 2010-11-09 14:52 143360 ------w- c:\windows\system32\dllcache\msadco.dll
2011-06-21 22:06 . 2010-11-09 14:52 102400 ------w- c:\windows\system32\dllcache\msjro.dll
2011-06-21 22:05 . 2009-07-27 23:17 135680 ------w- c:\windows\system32\dllcache\shsvcs.dll
2011-06-21 22:05 . 2011-02-08 13:34 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-06-21 22:04 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2011-06-21 22:04 . 2009-04-20 17:07 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2011-06-21 22:04 . 2008-06-20 17:44 247808 ------w- c:\windows\system32\dllcache\mswsock.dll
2011-06-21 22:04 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2011-06-21 22:03 . 2011-06-21 22:03 -------- d-----w- c:\program files\Uninstall Tool
2011-06-21 22:03 . 2010-09-18 06:53 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-06-21 22:03 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-06-21 21:57 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-06-21 21:54 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-06-21 21:50 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-04 02:52 . 2010-05-05 09:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-04 00:25 . 2010-05-05 09:53 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:30 . 2009-12-05 16:14 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-08-23 23:53 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:06 . 2008-08-23 23:53 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:06 . 2008-08-23 23:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:06 . 2008-08-23 23:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2008-08-23 23:53 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-08-23 23:53 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
.
[-] 2008-08-23 23:53 . F2614128EF03320BBFCF17F19A1633E9 . 1648640 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll
.
[-] 2008-08-23 . 22F702A6DCBDB4F7282C4B73B95EE4E4 . 2011136 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\i386\REGEDIT.EXE
.
[-] 2008-08-23 . A9658459BB4F4EE00FA117C9382C0D3A . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
.
c:\windows\System32\drivers\beep.sys ... manque !!
c:\windows\System32\regsvc.dll ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"WinSys2"="c:\windows\system32\winsys2.exe" [2008-01-18 208896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"SAOB Monitor"="c:\program files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe" [2010-08-20 2570080]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-08-21 5492760]
"Service Scheduler2 Acronis"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2010-08-21 391128]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-05-07 344736]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-04-08 254696]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogMeIn Hamachi Ui"="c:\program files\Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^SATARAID5.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\SATARAID5.lnk
backup=c:\windows\pss\SATARAID5.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\nvsvc32.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4719:TCP"= 4719:TCP:4719
"1033:TCP"= 1033:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [03/06/2003 16:52 123957]
R0 Si3124;Si3124;c:\windows\system32\drivers\si3124.sys [24/08/2008 01:53 76208]
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [24/08/2008 01:53 210224]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/08/2010 22:57 691696]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [18/09/2010 20:29 752128]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [03/06/2003 16:52 46900]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Fichiers communs\Acronis\CDP\afcdpsrv.exe [18/09/2010 20:29 3975088]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [24/08/2008 01:53 14336]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\Hamachi\hamachi-2.exe [25/05/2011 17:29 1336712]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [18/09/2010 20:29 163232]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]
S1 kl2;Kl2;c:\windows\system32\drivers\kl2.sys [07/05/2010 00:19 132184]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/05/2010 22:23 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c311036ea1a.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 20:23]
.
2010-05-05 c:\windows\Tasks\User_Feed_Synchronization-{341BD00F-A50B-4DF9-9E01-7C938F6F8E3E}.job
- c:\windows\system32\msfeedssync.exe [2008-08-23 03:31]
.
2009-12-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-12-26 21:18]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{8A315E1D-07D5-4545-8A46-80058229EB96}: NameServer = 212.27.54.252,212.27.53.253
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\zkalyan5.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Anti-Banner: KavAntiBanner@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: IE Tab: {77b819fa-95ad-4f2c-ac7c-486b356188a9} - %profile%\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
FF - Ext: OpenBook: {aba3f5c2-35d5-4960-bdfc-de9c162e39ce} - %profile%\extensions\{aba3f5c2-35d5-4960-bdfc-de9c162e39ce}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: GooglePreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-ITBar7Layout - (no file)
Toolbar-ITBar7Position - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-28 19:18
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e3,c8,11,b3,5f,e7,3d,4d,b8,bd,6b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,a3,3a,08,62,1f,89,49,91,83,99,\
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:76,55,15,fd,35,44,4a,2e,a6,d5,8d,2c,5a,79,77,34,8b,a0,61,8e,8f,
ce,67,3b,7c,68,78,df,07,20,a2,a5,29,fb,8e,77,e0,c4,ba,96,5d,60,c0,70,e8,5c,\
"rkeysecu"=hex:4f,61,9e,40,3c,cf,f6,8f,83,9a,ef,d3,6e,f7,bb,01
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1880)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
.
- - - - - - - > 'lsass.exe'(2032)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(2672)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-06-28 19:20:41 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-06-28 17:20
ComboFix2.txt 2011-06-27 19:12
.
Avant-CF: 286 781 816 832 octets libres
Après-CF: 286 828 806 144 octets libres
.
- - End Of File - - ACF56E335B80B0DCF8A36F0B4B2843AD
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.3071.2423 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\npf.sys
.
.
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ADXAPIE
-------\Legacy_NPF
-------\Service_adxapie
-------\Service_npf
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-05-28 au 2011-06-28 ))))))))))))))))))))))))))))))))))))
.
.
2011-06-28 17:17 . 2011-06-28 17:17 -------- d-----w-Ä? c:\windows\system32\!2AC2~1
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- C:\videooutput
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- c:\program files\Freez FLV to AVI MPEG WMV Converter
2011-06-28 15:49 . 2009-06-04 11:17 8676883 ----a-w- c:\windows\system32\NCMedia2.dll
2011-06-28 15:49 . 2008-10-08 08:16 139264 ----a-w- c:\windows\system32\xvid.ax
2011-06-28 15:26 . 2011-06-28 17:08 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\windows\LastGood.Tmp
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\program files\Hamachi
2011-06-28 15:18 . 2011-06-28 15:18 -------- d-----w- C:\My Videos
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\documents and settings\Administrateur\Application Data\aHisoft
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\program files\Video Sharer
2011-06-28 15:06 . 2011-06-28 15:06 -------- d-----w-Ä? c:\windows\system32\!2ACE~1
2011-06-28 14:09 . 2011-06-28 17:06 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2011-06-28 14:09 . 2011-06-28 14:09 -------- d-----r- c:\program files\Skype
2011-06-28 14:08 . 2011-06-28 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2011-06-28 12:34 . 2011-06-28 12:34 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Foxit Software
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\xircom
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\wbem\snmp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\oobe
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\npp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\msagent
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\program files\microsoft frontpage
2011-06-27 06:50 . 2011-06-27 06:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\Foxit Software
2011-06-27 05:42 . 2010-05-07 10:37 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2011-06-27 05:42 . 2010-05-07 10:37 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2011-06-27 00:21 . 2011-06-27 00:21 623 ----a-w- C:\gb.exe
2011-06-26 20:40 . 2011-06-26 23:58 -------- d-----w- c:\documents and settings\Administrateur\Application Data\.minecraft
2011-06-26 16:04 . 2011-06-26 16:33 97859 ----a-w- c:\windows\system32\drivers\klick.dat
2011-06-26 16:04 . 2011-06-26 16:33 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-06-26 16:03 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2011-06-26 16:03 . 2011-06-26 16:03 -------- d-----w- c:\program files\Kaspersky Lab
2011-06-26 16:01 . 2011-06-26 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2011-06-26 13:54 . 2011-06-26 21:45 -------- d-----w- c:\program files\eMule
2011-06-24 18:47 . 2011-06-24 18:47 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\program files\Fichiers communs\Steam
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\documents and settings\All Users\Menu Dmarrer
2011-06-24 17:31 . 2011-06-26 10:00 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-06-23 18:49 . 2011-06-23 18:49 -------- d-----w- c:\windows\system32\Ä?
2011-06-23 18:44 . 2011-06-23 18:44 -------- d-----w- C:\Updater
2011-06-23 16:48 . 2010-10-05 19:26 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll
2011-06-23 16:48 . 2010-10-05 19:27 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll
2011-06-23 11:01 . 2011-06-23 11:01 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Pinnacle
2011-06-23 05:06 . 2005-09-23 20:18 171520 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2011-06-23 05:06 . 2011-06-23 05:06 -------- d-----w- c:\program files\Fichiers communs\Pinnacle
2011-06-23 05:05 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate Collection
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Pegasus Imaging
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Yahoo!
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Studio 14
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Plus
2011-06-22 17:26 . 2011-06-22 17:26 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Safe mirror
2011-06-22 17:26 . 2011-06-28 12:27 -------- d-----w- c:\program files\Cobian Backup 10
2011-06-22 14:33 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2011-06-22 14:33 . 2011-06-23 05:02 -------- d-----w- c:\program files\Pinnacle
2011-06-22 14:30 . 2011-06-22 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\CrystalIdea Software
2011-06-22 07:14 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-06-21 22:27 . 2011-06-21 22:27 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\PackageAware
2011-06-21 22:09 . 2011-02-09 13:54 270848 ------w- c:\windows\system32\dllcache\sbe.dll
2011-06-21 22:09 . 2011-02-09 13:54 186880 ------w- c:\windows\system32\dllcache\encdec.dll
2011-06-21 22:08 . 2010-08-27 05:58 99840 ------w- c:\windows\system32\dllcache\srvsvc.dll
2011-06-21 22:08 . 2011-01-27 11:57 677888 ------w- c:\windows\system32\dllcache\lhmstsc.exe
2011-06-21 22:08 . 2011-02-02 07:59 2067456 ------w- c:\windows\system32\dllcache\lhmstscx.dll
2011-06-21 22:08 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-21 22:07 . 2011-01-21 14:44 441344 ------w- c:\windows\system32\dllcache\shimgvw.dll
2011-06-21 22:06 . 2010-07-16 12:06 1287680 ------w- c:\windows\system32\dllcache\ole32.dll
2011-06-21 22:06 . 2010-07-16 12:04 221696 ------w- c:\windows\system32\dllcache\wordpad.exe
2011-06-21 22:06 . 2010-11-09 14:52 536576 ------w- c:\windows\system32\dllcache\msado15.dll
2011-06-21 22:06 . 2010-11-09 14:52 249856 ------w- c:\windows\system32\dllcache\odbc32.dll
2011-06-21 22:06 . 2010-11-09 14:52 200704 ------w- c:\windows\system32\dllcache\msadox.dll
2011-06-21 22:06 . 2010-11-09 14:52 180224 ------w- c:\windows\system32\dllcache\msadomd.dll
2011-06-21 22:06 . 2010-11-09 14:52 143360 ------w- c:\windows\system32\dllcache\msadco.dll
2011-06-21 22:06 . 2010-11-09 14:52 102400 ------w- c:\windows\system32\dllcache\msjro.dll
2011-06-21 22:05 . 2009-07-27 23:17 135680 ------w- c:\windows\system32\dllcache\shsvcs.dll
2011-06-21 22:05 . 2011-02-08 13:34 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-06-21 22:04 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2011-06-21 22:04 . 2009-04-20 17:07 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2011-06-21 22:04 . 2008-06-20 17:44 247808 ------w- c:\windows\system32\dllcache\mswsock.dll
2011-06-21 22:04 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2011-06-21 22:03 . 2011-06-21 22:03 -------- d-----w- c:\program files\Uninstall Tool
2011-06-21 22:03 . 2010-09-18 06:53 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-06-21 22:03 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-06-21 21:57 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-06-21 21:54 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-06-21 21:50 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-04 02:52 . 2010-05-05 09:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-04 00:25 . 2010-05-05 09:53 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:30 . 2009-12-05 16:14 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-08-23 23:53 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:06 . 2008-08-23 23:53 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:06 . 2008-08-23 23:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:06 . 2008-08-23 23:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2008-08-23 23:53 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-08-23 23:53 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
.
[-] 2008-08-23 23:53 . F2614128EF03320BBFCF17F19A1633E9 . 1648640 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll
.
[-] 2008-08-23 . 22F702A6DCBDB4F7282C4B73B95EE4E4 . 2011136 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\i386\REGEDIT.EXE
.
[-] 2008-08-23 . A9658459BB4F4EE00FA117C9382C0D3A . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
.
c:\windows\System32\drivers\beep.sys ... manque !!
c:\windows\System32\regsvc.dll ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"WinSys2"="c:\windows\system32\winsys2.exe" [2008-01-18 208896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"SAOB Monitor"="c:\program files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe" [2010-08-20 2570080]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-08-21 5492760]
"Service Scheduler2 Acronis"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2010-08-21 391128]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-05-07 344736]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-04-08 254696]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogMeIn Hamachi Ui"="c:\program files\Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^SATARAID5.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\SATARAID5.lnk
backup=c:\windows\pss\SATARAID5.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\nvsvc32.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4719:TCP"= 4719:TCP:4719
"1033:TCP"= 1033:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [03/06/2003 16:52 123957]
R0 Si3124;Si3124;c:\windows\system32\drivers\si3124.sys [24/08/2008 01:53 76208]
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [24/08/2008 01:53 210224]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/08/2010 22:57 691696]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [18/09/2010 20:29 752128]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [03/06/2003 16:52 46900]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Fichiers communs\Acronis\CDP\afcdpsrv.exe [18/09/2010 20:29 3975088]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [24/08/2008 01:53 14336]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\Hamachi\hamachi-2.exe [25/05/2011 17:29 1336712]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [18/09/2010 20:29 163232]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]
S1 kl2;Kl2;c:\windows\system32\drivers\kl2.sys [07/05/2010 00:19 132184]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/05/2010 22:23 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c311036ea1a.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 20:23]
.
2010-05-05 c:\windows\Tasks\User_Feed_Synchronization-{341BD00F-A50B-4DF9-9E01-7C938F6F8E3E}.job
- c:\windows\system32\msfeedssync.exe [2008-08-23 03:31]
.
2009-12-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-12-26 21:18]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{8A315E1D-07D5-4545-8A46-80058229EB96}: NameServer = 212.27.54.252,212.27.53.253
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\zkalyan5.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Anti-Banner: KavAntiBanner@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: IE Tab: {77b819fa-95ad-4f2c-ac7c-486b356188a9} - %profile%\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
FF - Ext: OpenBook: {aba3f5c2-35d5-4960-bdfc-de9c162e39ce} - %profile%\extensions\{aba3f5c2-35d5-4960-bdfc-de9c162e39ce}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: GooglePreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-ITBar7Layout - (no file)
Toolbar-ITBar7Position - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-28 19:18
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e3,c8,11,b3,5f,e7,3d,4d,b8,bd,6b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,a3,3a,08,62,1f,89,49,91,83,99,\
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:76,55,15,fd,35,44,4a,2e,a6,d5,8d,2c,5a,79,77,34,8b,a0,61,8e,8f,
ce,67,3b,7c,68,78,df,07,20,a2,a5,29,fb,8e,77,e0,c4,ba,96,5d,60,c0,70,e8,5c,\
"rkeysecu"=hex:4f,61,9e,40,3c,cf,f6,8f,83,9a,ef,d3,6e,f7,bb,01
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1880)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
.
- - - - - - - > 'lsass.exe'(2032)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(2672)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-06-28 19:20:41 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-06-28 17:20
ComboFix2.txt 2011-06-27 19:12
.
Avant-CF: 286 781 816 832 octets libres
Après-CF: 286 828 806 144 octets libres
.
- - End Of File - - ACF56E335B80B0DCF8A36F0B4B2843AD
nanard4700
Messages postés
11228
Date d'inscription
mardi 17 juillet 2007
Statut
Contributeur sécurité
Dernière intervention
27 décembre 2015
835
28 juin 2011 à 21:53
28 juin 2011 à 21:53
Tu collectionnes les M=====.
En installant un programme P2P tu viens de te réinfecter avec une barre toolbar.
Vires la toolbar babylon de tes programmes et ce sera bon.
En installant un programme P2P tu viens de te réinfecter avec une barre toolbar.
Vires la toolbar babylon de tes programmes et ce sera bon.
Ticki84
Messages postés
844
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
159
28 juin 2011 à 22:12
28 juin 2011 à 22:12
C'était en téléchargeant un fichier soft-tonic. Sinon je l'ai désinstaller. Merci de ton aide !
28 juin 2011 à 16:50