Pub Meta-search et tringaloo
Résolu/Fermé
Ticki84
Messages postés
850
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
-
24 juin 2011 à 18:03
Ticki84 Messages postés 850 Date d'inscription mardi 17 août 2010 Statut Membre Dernière intervention 26 décembre 2017 - 28 juin 2011 à 22:12
Ticki84 Messages postés 850 Date d'inscription mardi 17 août 2010 Statut Membre Dernière intervention 26 décembre 2017 - 28 juin 2011 à 22:12
A voir également:
- Pub Meta-search et tringaloo
- Youtube sans pub - Accueil - Streaming
- Netflix avec pub avis - Accueil - Streaming
- Www.google.com search video - Télécharger - TV & Vidéo
- Bloqueur de pub youtube - Accueil - Streaming
- Stop pub gratuit - Télécharger - Divers Utilitaires
22 réponses
Ticki84
Messages postés
850
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
158
28 juin 2011 à 15:51
28 juin 2011 à 15:51
Je n'ai plus les pubs même si je n'ai pas suivis la dernière étape, dois-je comme même la suivre ? Sinon merci de ton aide.
Ticki84
Messages postés
850
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
158
28 juin 2011 à 21:38
28 juin 2011 à 21:38
ComboFix 11-06-27.04 - Administrateur 28/06/2011 19:11:39.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.3071.2423 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\npf.sys
.
.
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ADXAPIE
-------\Legacy_NPF
-------\Service_adxapie
-------\Service_npf
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-05-28 au 2011-06-28 ))))))))))))))))))))))))))))))))))))
.
.
2011-06-28 17:17 . 2011-06-28 17:17 -------- d-----w-Ä? c:\windows\system32\!2AC2~1
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- C:\videooutput
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- c:\program files\Freez FLV to AVI MPEG WMV Converter
2011-06-28 15:49 . 2009-06-04 11:17 8676883 ----a-w- c:\windows\system32\NCMedia2.dll
2011-06-28 15:49 . 2008-10-08 08:16 139264 ----a-w- c:\windows\system32\xvid.ax
2011-06-28 15:26 . 2011-06-28 17:08 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\windows\LastGood.Tmp
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\program files\Hamachi
2011-06-28 15:18 . 2011-06-28 15:18 -------- d-----w- C:\My Videos
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\documents and settings\Administrateur\Application Data\aHisoft
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\program files\Video Sharer
2011-06-28 15:06 . 2011-06-28 15:06 -------- d-----w-Ä? c:\windows\system32\!2ACE~1
2011-06-28 14:09 . 2011-06-28 17:06 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2011-06-28 14:09 . 2011-06-28 14:09 -------- d-----r- c:\program files\Skype
2011-06-28 14:08 . 2011-06-28 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2011-06-28 12:34 . 2011-06-28 12:34 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Foxit Software
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\xircom
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\wbem\snmp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\oobe
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\npp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\msagent
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\program files\microsoft frontpage
2011-06-27 06:50 . 2011-06-27 06:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\Foxit Software
2011-06-27 05:42 . 2010-05-07 10:37 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2011-06-27 05:42 . 2010-05-07 10:37 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2011-06-27 00:21 . 2011-06-27 00:21 623 ----a-w- C:\gb.exe
2011-06-26 20:40 . 2011-06-26 23:58 -------- d-----w- c:\documents and settings\Administrateur\Application Data\.minecraft
2011-06-26 16:04 . 2011-06-26 16:33 97859 ----a-w- c:\windows\system32\drivers\klick.dat
2011-06-26 16:04 . 2011-06-26 16:33 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-06-26 16:03 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2011-06-26 16:03 . 2011-06-26 16:03 -------- d-----w- c:\program files\Kaspersky Lab
2011-06-26 16:01 . 2011-06-26 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2011-06-26 13:54 . 2011-06-26 21:45 -------- d-----w- c:\program files\eMule
2011-06-24 18:47 . 2011-06-24 18:47 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\program files\Fichiers communs\Steam
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\documents and settings\All Users\Menu Dmarrer
2011-06-24 17:31 . 2011-06-26 10:00 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-06-23 18:49 . 2011-06-23 18:49 -------- d-----w- c:\windows\system32\Ä?
2011-06-23 18:44 . 2011-06-23 18:44 -------- d-----w- C:\Updater
2011-06-23 16:48 . 2010-10-05 19:26 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll
2011-06-23 16:48 . 2010-10-05 19:27 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll
2011-06-23 11:01 . 2011-06-23 11:01 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Pinnacle
2011-06-23 05:06 . 2005-09-23 20:18 171520 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2011-06-23 05:06 . 2011-06-23 05:06 -------- d-----w- c:\program files\Fichiers communs\Pinnacle
2011-06-23 05:05 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate Collection
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Pegasus Imaging
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Yahoo!
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Studio 14
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Plus
2011-06-22 17:26 . 2011-06-22 17:26 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Safe mirror
2011-06-22 17:26 . 2011-06-28 12:27 -------- d-----w- c:\program files\Cobian Backup 10
2011-06-22 14:33 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2011-06-22 14:33 . 2011-06-23 05:02 -------- d-----w- c:\program files\Pinnacle
2011-06-22 14:30 . 2011-06-22 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\CrystalIdea Software
2011-06-22 07:14 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-06-21 22:27 . 2011-06-21 22:27 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\PackageAware
2011-06-21 22:09 . 2011-02-09 13:54 270848 ------w- c:\windows\system32\dllcache\sbe.dll
2011-06-21 22:09 . 2011-02-09 13:54 186880 ------w- c:\windows\system32\dllcache\encdec.dll
2011-06-21 22:08 . 2010-08-27 05:58 99840 ------w- c:\windows\system32\dllcache\srvsvc.dll
2011-06-21 22:08 . 2011-01-27 11:57 677888 ------w- c:\windows\system32\dllcache\lhmstsc.exe
2011-06-21 22:08 . 2011-02-02 07:59 2067456 ------w- c:\windows\system32\dllcache\lhmstscx.dll
2011-06-21 22:08 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-21 22:07 . 2011-01-21 14:44 441344 ------w- c:\windows\system32\dllcache\shimgvw.dll
2011-06-21 22:06 . 2010-07-16 12:06 1287680 ------w- c:\windows\system32\dllcache\ole32.dll
2011-06-21 22:06 . 2010-07-16 12:04 221696 ------w- c:\windows\system32\dllcache\wordpad.exe
2011-06-21 22:06 . 2010-11-09 14:52 536576 ------w- c:\windows\system32\dllcache\msado15.dll
2011-06-21 22:06 . 2010-11-09 14:52 249856 ------w- c:\windows\system32\dllcache\odbc32.dll
2011-06-21 22:06 . 2010-11-09 14:52 200704 ------w- c:\windows\system32\dllcache\msadox.dll
2011-06-21 22:06 . 2010-11-09 14:52 180224 ------w- c:\windows\system32\dllcache\msadomd.dll
2011-06-21 22:06 . 2010-11-09 14:52 143360 ------w- c:\windows\system32\dllcache\msadco.dll
2011-06-21 22:06 . 2010-11-09 14:52 102400 ------w- c:\windows\system32\dllcache\msjro.dll
2011-06-21 22:05 . 2009-07-27 23:17 135680 ------w- c:\windows\system32\dllcache\shsvcs.dll
2011-06-21 22:05 . 2011-02-08 13:34 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-06-21 22:04 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2011-06-21 22:04 . 2009-04-20 17:07 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2011-06-21 22:04 . 2008-06-20 17:44 247808 ------w- c:\windows\system32\dllcache\mswsock.dll
2011-06-21 22:04 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2011-06-21 22:03 . 2011-06-21 22:03 -------- d-----w- c:\program files\Uninstall Tool
2011-06-21 22:03 . 2010-09-18 06:53 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-06-21 22:03 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-06-21 21:57 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-06-21 21:54 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-06-21 21:50 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-04 02:52 . 2010-05-05 09:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-04 00:25 . 2010-05-05 09:53 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:30 . 2009-12-05 16:14 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-08-23 23:53 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:06 . 2008-08-23 23:53 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:06 . 2008-08-23 23:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:06 . 2008-08-23 23:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2008-08-23 23:53 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-08-23 23:53 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
.
[-] 2008-08-23 23:53 . F2614128EF03320BBFCF17F19A1633E9 . 1648640 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll
.
[-] 2008-08-23 . 22F702A6DCBDB4F7282C4B73B95EE4E4 . 2011136 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\i386\REGEDIT.EXE
.
[-] 2008-08-23 . A9658459BB4F4EE00FA117C9382C0D3A . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
.
c:\windows\System32\drivers\beep.sys ... manque !!
c:\windows\System32\regsvc.dll ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"WinSys2"="c:\windows\system32\winsys2.exe" [2008-01-18 208896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"SAOB Monitor"="c:\program files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe" [2010-08-20 2570080]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-08-21 5492760]
"Service Scheduler2 Acronis"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2010-08-21 391128]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-05-07 344736]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-04-08 254696]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogMeIn Hamachi Ui"="c:\program files\Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^SATARAID5.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\SATARAID5.lnk
backup=c:\windows\pss\SATARAID5.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\nvsvc32.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4719:TCP"= 4719:TCP:4719
"1033:TCP"= 1033:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [03/06/2003 16:52 123957]
R0 Si3124;Si3124;c:\windows\system32\drivers\si3124.sys [24/08/2008 01:53 76208]
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [24/08/2008 01:53 210224]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/08/2010 22:57 691696]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [18/09/2010 20:29 752128]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [03/06/2003 16:52 46900]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Fichiers communs\Acronis\CDP\afcdpsrv.exe [18/09/2010 20:29 3975088]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [24/08/2008 01:53 14336]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\Hamachi\hamachi-2.exe [25/05/2011 17:29 1336712]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [18/09/2010 20:29 163232]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]
S1 kl2;Kl2;c:\windows\system32\drivers\kl2.sys [07/05/2010 00:19 132184]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/05/2010 22:23 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c311036ea1a.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 20:23]
.
2010-05-05 c:\windows\Tasks\User_Feed_Synchronization-{341BD00F-A50B-4DF9-9E01-7C938F6F8E3E}.job
- c:\windows\system32\msfeedssync.exe [2008-08-23 03:31]
.
2009-12-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-12-26 21:18]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{8A315E1D-07D5-4545-8A46-80058229EB96}: NameServer = 212.27.54.252,212.27.53.253
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\zkalyan5.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Anti-Banner: KavAntiBanner@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: IE Tab: {77b819fa-95ad-4f2c-ac7c-486b356188a9} - %profile%\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
FF - Ext: OpenBook: {aba3f5c2-35d5-4960-bdfc-de9c162e39ce} - %profile%\extensions\{aba3f5c2-35d5-4960-bdfc-de9c162e39ce}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: GooglePreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-ITBar7Layout - (no file)
Toolbar-ITBar7Position - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-28 19:18
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e3,c8,11,b3,5f,e7,3d,4d,b8,bd,6b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,a3,3a,08,62,1f,89,49,91,83,99,\
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:76,55,15,fd,35,44,4a,2e,a6,d5,8d,2c,5a,79,77,34,8b,a0,61,8e,8f,
ce,67,3b,7c,68,78,df,07,20,a2,a5,29,fb,8e,77,e0,c4,ba,96,5d,60,c0,70,e8,5c,\
"rkeysecu"=hex:4f,61,9e,40,3c,cf,f6,8f,83,9a,ef,d3,6e,f7,bb,01
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1880)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
.
- - - - - - - > 'lsass.exe'(2032)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(2672)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-06-28 19:20:41 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-06-28 17:20
ComboFix2.txt 2011-06-27 19:12
.
Avant-CF: 286 781 816 832 octets libres
Après-CF: 286 828 806 144 octets libres
.
- - End Of File - - ACF56E335B80B0DCF8A36F0B4B2843AD
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.3071.2423 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur\Bureau\CFScript.txt
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\npf.sys
.
.
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ADXAPIE
-------\Legacy_NPF
-------\Service_adxapie
-------\Service_npf
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-05-28 au 2011-06-28 ))))))))))))))))))))))))))))))))))))
.
.
2011-06-28 17:17 . 2011-06-28 17:17 -------- d-----w-Ä? c:\windows\system32\!2AC2~1
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- C:\videooutput
2011-06-28 15:49 . 2011-06-28 15:49 -------- d-----w- c:\program files\Freez FLV to AVI MPEG WMV Converter
2011-06-28 15:49 . 2009-06-04 11:17 8676883 ----a-w- c:\windows\system32\NCMedia2.dll
2011-06-28 15:49 . 2008-10-08 08:16 139264 ----a-w- c:\windows\system32\xvid.ax
2011-06-28 15:26 . 2011-06-28 17:08 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\windows\LastGood.Tmp
2011-06-28 15:26 . 2011-06-28 15:26 -------- d-----w- c:\program files\Hamachi
2011-06-28 15:18 . 2011-06-28 15:18 -------- d-----w- C:\My Videos
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\documents and settings\Administrateur\Application Data\aHisoft
2011-06-28 15:17 . 2011-06-28 15:17 -------- d-----w- c:\program files\Video Sharer
2011-06-28 15:06 . 2011-06-28 15:06 -------- d-----w-Ä? c:\windows\system32\!2ACE~1
2011-06-28 14:09 . 2011-06-28 17:06 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2011-06-28 14:09 . 2011-06-28 14:09 -------- d-----r- c:\program files\Skype
2011-06-28 14:08 . 2011-06-28 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2011-06-28 12:34 . 2011-06-28 12:34 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Foxit Software
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\xircom
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\wbem\snmp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\oobe
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\system32\npp
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\windows\msagent
2011-06-27 19:06 . 2011-06-27 19:06 -------- d-----w- c:\program files\microsoft frontpage
2011-06-27 06:50 . 2011-06-27 06:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\Foxit Software
2011-06-27 05:42 . 2010-05-07 10:37 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
2011-06-27 05:42 . 2010-05-07 10:37 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru\components\abhelperxpcom.dll
2011-06-27 00:21 . 2011-06-27 00:21 623 ----a-w- C:\gb.exe
2011-06-26 20:40 . 2011-06-26 23:58 -------- d-----w- c:\documents and settings\Administrateur\Application Data\.minecraft
2011-06-26 16:04 . 2011-06-26 16:33 97859 ----a-w- c:\windows\system32\drivers\klick.dat
2011-06-26 16:04 . 2011-06-26 16:33 115369 ----a-w- c:\windows\system32\drivers\klin.dat
2011-06-26 16:03 . 2011-06-28 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2011-06-26 16:03 . 2011-06-26 16:03 -------- d-----w- c:\program files\Kaspersky Lab
2011-06-26 16:01 . 2011-06-26 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2011-06-26 13:54 . 2011-06-26 21:45 -------- d-----w- c:\program files\eMule
2011-06-24 18:47 . 2011-06-24 18:47 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\program files\Fichiers communs\Steam
2011-06-24 17:54 . 2011-06-24 17:54 -------- d-----w- c:\documents and settings\All Users\Menu Dmarrer
2011-06-24 17:31 . 2011-06-26 10:00 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-06-23 18:49 . 2011-06-23 18:49 -------- d-----w- c:\windows\system32\Ä?
2011-06-23 18:44 . 2011-06-23 18:44 -------- d-----w- C:\Updater
2011-06-23 16:48 . 2010-10-05 19:26 109240 ----a-w- c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll
2011-06-23 16:48 . 2010-10-05 19:27 150200 ----a-w- c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll
2011-06-23 11:01 . 2011-06-23 11:01 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Pinnacle
2011-06-23 05:06 . 2005-09-23 20:18 171520 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2011-06-23 05:06 . 2011-06-23 05:06 -------- d-----w- c:\program files\Fichiers communs\Pinnacle
2011-06-23 05:05 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Ultimate Collection
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Pegasus Imaging
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\program files\Fichiers communs\Yahoo!
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Studio 14
2011-06-23 05:02 . 2011-06-23 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle Studio Plus
2011-06-22 17:26 . 2011-06-22 17:26 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Safe mirror
2011-06-22 17:26 . 2011-06-28 12:27 -------- d-----w- c:\program files\Cobian Backup 10
2011-06-22 14:33 . 2011-06-23 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Pinnacle
2011-06-22 14:33 . 2011-06-23 05:02 -------- d-----w- c:\program files\Pinnacle
2011-06-22 14:30 . 2011-06-22 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\CrystalIdea Software
2011-06-22 07:14 . 2010-10-11 14:59 45568 ------w- c:\windows\system32\dllcache\wab.exe
2011-06-21 22:27 . 2011-06-21 22:27 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\PackageAware
2011-06-21 22:09 . 2011-02-09 13:54 270848 ------w- c:\windows\system32\dllcache\sbe.dll
2011-06-21 22:09 . 2011-02-09 13:54 186880 ------w- c:\windows\system32\dllcache\encdec.dll
2011-06-21 22:08 . 2010-08-27 05:58 99840 ------w- c:\windows\system32\dllcache\srvsvc.dll
2011-06-21 22:08 . 2011-01-27 11:57 677888 ------w- c:\windows\system32\dllcache\lhmstsc.exe
2011-06-21 22:08 . 2011-02-02 07:59 2067456 ------w- c:\windows\system32\dllcache\lhmstscx.dll
2011-06-21 22:08 . 2010-12-20 17:32 551936 ------w- c:\windows\system32\dllcache\oleaut32.dll
2011-06-21 22:07 . 2011-01-21 14:44 441344 ------w- c:\windows\system32\dllcache\shimgvw.dll
2011-06-21 22:06 . 2010-07-16 12:06 1287680 ------w- c:\windows\system32\dllcache\ole32.dll
2011-06-21 22:06 . 2010-07-16 12:04 221696 ------w- c:\windows\system32\dllcache\wordpad.exe
2011-06-21 22:06 . 2010-11-09 14:52 536576 ------w- c:\windows\system32\dllcache\msado15.dll
2011-06-21 22:06 . 2010-11-09 14:52 249856 ------w- c:\windows\system32\dllcache\odbc32.dll
2011-06-21 22:06 . 2010-11-09 14:52 200704 ------w- c:\windows\system32\dllcache\msadox.dll
2011-06-21 22:06 . 2010-11-09 14:52 180224 ------w- c:\windows\system32\dllcache\msadomd.dll
2011-06-21 22:06 . 2010-11-09 14:52 143360 ------w- c:\windows\system32\dllcache\msadco.dll
2011-06-21 22:06 . 2010-11-09 14:52 102400 ------w- c:\windows\system32\dllcache\msjro.dll
2011-06-21 22:05 . 2009-07-27 23:17 135680 ------w- c:\windows\system32\dllcache\shsvcs.dll
2011-06-21 22:05 . 2011-02-08 13:34 978944 ------w- c:\windows\system32\dllcache\mfc42.dll
2011-06-21 22:04 . 2011-03-03 06:53 149504 ------w- c:\windows\system32\dllcache\dnsapi.dll
2011-06-21 22:04 . 2009-04-20 17:07 45568 ------w- c:\windows\system32\dllcache\dnsrslvr.dll
2011-06-21 22:04 . 2008-06-20 17:44 247808 ------w- c:\windows\system32\dllcache\mswsock.dll
2011-06-21 22:04 . 2008-06-20 11:59 361600 ------w- c:\windows\system32\dllcache\tcpip.sys
2011-06-21 22:03 . 2011-06-21 22:03 -------- d-----w- c:\program files\Uninstall Tool
2011-06-21 22:03 . 2010-09-18 06:53 954368 ------w- c:\windows\system32\dllcache\mfc40.dll
2011-06-21 22:03 . 2010-09-18 06:53 953856 ------w- c:\windows\system32\dllcache\mfc40u.dll
2011-06-21 21:57 . 2010-08-23 16:12 617472 ------w- c:\windows\system32\dllcache\comctl32.dll
2011-06-21 21:54 . 2010-11-02 15:17 40960 ------w- c:\windows\system32\dllcache\ndproxy.sys
2011-06-21 21:50 . 2011-04-21 13:37 105472 ------w- c:\windows\system32\dllcache\mup.sys
2011-06-02 17:53 . 2011-06-02 17:53 94208 ----a-w- c:\windows\system32\dpl100.dll
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-04 02:52 . 2010-05-05 09:53 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-04 00:25 . 2010-05-05 09:53 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-05-02 15:30 . 2009-12-05 16:14 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 16:19 . 2008-08-23 23:53 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:06 . 2008-08-23 23:53 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:06 . 2008-08-23 23:53 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:06 . 2008-08-23 23:53 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2008-08-23 23:53 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2008-08-23 23:53 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
.
[-] 2008-08-23 23:53 . F2614128EF03320BBFCF17F19A1633E9 . 1648640 . . [2001.12.4414.700] . . c:\windows\system32\comres.dll
.
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
[-] 2007-02-04 . B69157CFB81EAA53357D3BD3650731D4 . 579584 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\user32.dll
.
[-] 2008-08-23 . 22F702A6DCBDB4F7282C4B73B95EE4E4 . 2011136 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[-] 2008-08-23 . D2BD6E5AA98850DC118065A83A9C6E85 . 302592 . . [5.1.2600.5512] . . c:\windows\i386\REGEDIT.EXE
.
[-] 2008-08-23 . A9658459BB4F4EE00FA117C9382C0D3A . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
.
c:\windows\System32\drivers\beep.sys ... manque !!
c:\windows\System32\regsvc.dll ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2004-10-08 196608]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 15141768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"WinSys2"="c:\windows\system32\winsys2.exe" [2008-01-18 208896]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"SAOB Monitor"="c:\program files\Acronis\OnlineBackupStandalone\TrueImageMonitor.exe" [2010-08-20 2570080]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-08-21 5492760]
"Service Scheduler2 Acronis"="c:\program files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2010-08-21 391128]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"USBToolTip"="c:\progra~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe" [2007-02-20 199752]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2010-05-07 344736]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2011-04-08 254696]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2004-10-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2004-10-08 458752]
"LogMeIn Hamachi Ui"="c:\program files\Hamachi\hamachi-2-ui.exe" [2011-05-25 1951112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TaskSwitchXP"="c:\program files\TaskSwitchXP\TaskSwitchXP.exe" [2006-08-04 62976]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^SATARAID5.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\SATARAID5.lnk
backup=c:\windows\pss\SATARAID5.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\nvsvc32.exe"=
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 14\\Programs\\umi.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4719:TCP"= 4719:TCP:4719
"1033:TCP"= 1033:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [03/06/2003 16:52 123957]
R0 Si3124;Si3124;c:\windows\system32\drivers\si3124.sys [24/08/2008 01:53 76208]
R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [24/08/2008 01:53 210224]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/08/2010 22:57 691696]
R0 tdrpman273;Acronis Try&Decide and Restore Points filter (build 273);c:\windows\system32\drivers\tdrpm273.sys [18/09/2010 20:29 752128]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [03/06/2003 16:52 46900]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Fichiers communs\Acronis\CDP\afcdpsrv.exe [18/09/2010 20:29 3975088]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [24/08/2008 01:53 14336]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\Hamachi\hamachi-2.exe [25/05/2011 17:29 1336712]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [18/09/2010 20:29 163232]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [14/09/2009 14:42 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]
S1 kl2;Kl2;c:\windows\system32\drivers\kl2.sys [07/05/2010 00:19 132184]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/05/2010 22:23 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cb0c311036ea1a.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 20:23]
.
2010-05-05 c:\windows\Tasks\User_Feed_Synchronization-{341BD00F-A50B-4DF9-9E01-7C938F6F8E3E}.job
- c:\windows\system32\msfeedssync.exe [2008-08-23 03:31]
.
2009-12-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-12-26 21:18]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{8A315E1D-07D5-4545-8A46-80058229EB96}: NameServer = 212.27.54.252,212.27.53.253
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\zkalyan5.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=ff4780eb000000000000002421a3f34c&tlver=1.4.19.19&ss=1&affID=18026
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@Kaspersky.ru
FF - Ext: Anti-Banner: KavAntiBanner@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru_bak - c:\program files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Babylon: ffxtlbr@babylon.com - %profile%\extensions\ffxtlbr@babylon.com
FF - Ext: Vista-aero: {07b2a769-ed19-4483-87ce-c643914c81bb} - %profile%\extensions\{07b2a769-ed19-4483-87ce-c643914c81bb}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: IE Tab: {77b819fa-95ad-4f2c-ac7c-486b356188a9} - %profile%\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
FF - Ext: OpenBook: {aba3f5c2-35d5-4960-bdfc-de9c162e39ce} - %profile%\extensions\{aba3f5c2-35d5-4960-bdfc-de9c162e39ce}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: GooglePreview: {EF522540-89F5-46b9-B6FE-1829E2B572C6} - %profile%\extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Kaspersky Anti-Banner: KavAntiBanner@Kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru
FF - Ext: Kaspersky URL Advisor: linkfilter@kaspersky.ru - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru
.
- - - - ORPHELINS SUPPRIMES - - - -
.
Toolbar-ITBar7Layout - (no file)
Toolbar-ITBar7Position - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-28 19:18
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e3,c8,11,b3,5f,e7,3d,4d,b8,bd,6b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,65,a3,3a,08,62,1f,89,49,91,83,99,\
.
[HKEY_USERS\S-1-5-21-1606980848-113007714-682003330-500\Software\SecuROM\License information*]
"datasecu"=hex:76,55,15,fd,35,44,4a,2e,a6,d5,8d,2c,5a,79,77,34,8b,a0,61,8e,8f,
ce,67,3b,7c,68,78,df,07,20,a2,a5,29,fb,8e,77,e0,c4,ba,96,5d,60,c0,70,e8,5c,\
"rkeysecu"=hex:4f,61,9e,40,3c,cf,f6,8f,83,9a,ef,d3,6e,f7,bb,01
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1880)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\COMRes.dll
.
- - - - - - - > 'lsass.exe'(2032)
c:\windows\system32\setupapi.dll
.
- - - - - - - > 'explorer.exe'(2672)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\COMRes.dll
c:\windows\system32\msi.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-06-28 19:20:41 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-06-28 17:20
ComboFix2.txt 2011-06-27 19:12
.
Avant-CF: 286 781 816 832 octets libres
Après-CF: 286 828 806 144 octets libres
.
- - End Of File - - ACF56E335B80B0DCF8A36F0B4B2843AD
Ticki84
Messages postés
850
Date d'inscription
mardi 17 août 2010
Statut
Membre
Dernière intervention
26 décembre 2017
158
28 juin 2011 à 22:12
28 juin 2011 à 22:12
C'était en téléchargeant un fichier soft-tonic. Sinon je l'ai désinstaller. Merci de ton aide !
28 juin 2011 à 16:50