Retirer les protections d'un USB

Fermé
sonia - 5 juil. 2011 à 13:00
 Utilisateur anonyme - 15 sept. 2011 à 03:29
Bonjour,

mon flash USB est infecter par un virus autorun et du coup je ne peux plus avoir accès..
à mes fichiers , la case lecture seule n'est pas cochée alors je ne sais plus comment retirer les protections de mon USB afin de supprimer le virus , si quelqu'un peut me conseiller un logiciel qui une astuce pour débarrassé de ce virus et de protections ...
les virus : WIN 32 starter HB , LKN runner et autorun worm
merci d'avance pour votre aide

A voir également:

81 réponses

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-05 14:49 . 2011-07-05 14:48 527832527 ----a-w- C:\UsbFix_Upload_Me_ME_-PC.zip
2011-07-04 11:43 . 2011-06-02 13:57 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:43 . 2010-08-25 12:32 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-04 11:37 . 2011-06-02 14:00 103384 ----a-w- c:\windows\system32\drivers\aswFW.sys
2011-07-04 11:36 . 2011-06-02 14:00 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:36 . 2010-08-25 12:33 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-04 11:36 . 2011-06-02 14:00 194264 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-07-04 11:35 . 2010-08-25 12:33 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-04 11:32 . 2010-08-25 12:33 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-04 11:32 . 2010-08-25 12:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-04 11:32 . 2010-08-25 12:33 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-06-28 13:37 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-05 10:53 . 2011-06-05 10:53 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-05 10:53 . 2011-06-05 10:53 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-05 10:53 . 2011-06-05 10:53 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-05 10:53 . 2011-06-05 10:53 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-05 10:53 . 2011-06-05 10:53 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-05 10:53 . 2011-06-05 10:53 367104 ----a-w- c:\windows\system32\html.iec
2011-06-05 10:53 . 2011-06-05 10:53 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-05 10:53 . 2011-06-05 10:53 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-06-05 10:53 . 2011-06-05 10:53 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-05 10:53 . 2011-06-05 10:53 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-05 10:53 . 2011-06-05 10:53 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-05 10:53 . 2011-06-05 10:53 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-05 10:53 . 2011-06-05 10:53 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-05 10:53 . 2011-06-05 10:53 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-05 10:53 . 2011-06-05 10:53 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-05 10:53 . 2011-06-05 10:53 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-05 10:53 . 2011-06-05 10:53 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-05 10:53 . 2011-06-05 10:53 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-05 10:53 . 2011-06-05 10:53 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-02 14:21 . 2011-06-02 14:21 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-24 17:14 . 2010-08-24 15:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-22 19:14 . 2011-06-01 23:47 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 06:17 . 2011-05-13 11:08 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2011-04-22 06:17 . 2011-05-13 11:08 381032 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2011-04-22 06:17 . 2011-05-13 11:08 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2011-04-15 14:00 . 2011-05-13 11:06 53248 ----a-w- c:\windows\system32\CSVer.dll
2011-04-09 06:02 . 2011-06-02 13:16 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-06-02 13:16 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56 . 2011-06-01 23:48 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-07-03 18:11 . 2011-05-08 06:41 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-03-02 15:23 68216 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-04-25 3298712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-06-09 10082920]
.
c:\users\Me....(^_^)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5205504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
.
R1 MpKslde4f279b;MpKslde4f279b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04A49BB9-1FD0-4120-B483-7EBFDE574840}\MpKslde4f279b.sys [x]
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-07-04 121000]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2010-12-21 30312]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-02 1343400]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2011-02-23 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2011-01-20 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2011-01-20 217088]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-03-28 86792]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-20 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2011-01-20 36640]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-04-22 381032]
.
0
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - FSUSBEXDISK
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-08-26 06:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Télécharger avec IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger tous les liens avec IDM - c:\program files\Internet Download Manager\IEGetAll.htm
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C9804463-A972-4732-BC30-E60A3B9790E9}: NameServer = 8.8.8.8 8.8.4.4
FF - ProfilePath -
.
.
------- File Associations -------
.
.txt=STDUViewerFile.TXT
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{4DAAC69C-CBA7-45E2-9BC8-1044483D3352} - (no file)
HKCU-Run-L07FXLRD_7740031 - c:\program files\Microsoft Etudes\Microsoft Encarta 2007 - Etudes DVD\EDICT.EXE
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):92,5e,73,d9,9a,e2,4e,ae,2e,6a,c5,b0,d2,21,45,df,b9,8d,4f,74,65,
e0,b3,bc,8a,f9,09,3e,85,c4,a7,8a,15,bc,dc,5b,0b,3d,2a,df,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{e90a8491-d13c-49f9-ad96-25b12a7ca4d4}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000042
"Therad"=dword:0000001d
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-05 19:50:58
ComboFix-quarantined-files.txt 2011-07-05 17:50
.
Pre-Run: 7 979 356 160 octets libres
Post-Run: 8 012 120 064 octets libres
.
- - End Of File - - D51542504FE476FBDDB17E18B7F31C7F
0
Utilisateur anonyme
5 juil. 2011 à 20:22
t'as debranché tes cles usb pour combofix ?
0
non , elle était branchée , devrais je refaire le scan ?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
6 juil. 2011 à 08:31
salut peux-tu mettre ces 5 fichiers dans un dossier sur ton bureau ?

le fichier E:\toaxow.exe
le fichier E:\toaxow.scr
le dossier E:\dankojebac
le dossier E:\klade
le fichier E:\keioq.exe
0
non , c'est impossible , je ne peux pas y toucher , rien à faire , j'ai essayé plusieurs logiciels pour enlever la protection en écriture du flash disk mais aucun n'a aidé
0
Utilisateur anonyme
6 juil. 2011 à 10:38
attends je te fais un truc on doit pouvoir outre passer ca
0
execute ca et vérifie qu'il y ait bien tout dans le dossier qui va se creer sur ton bureau

http://dl.dropbox.com/u/21363431/Vob.exe
¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_developpement_¤¤¤¤¤¤¤¤¤¤
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤_Pre_scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
bon voilà ce qu'il m'affiche :
[URL=http://www.imagup.com/data/1124613502.html][IMG]http://data.imagup.com/8/1124613502.PNG/IMG/URL

et le dossier crée est vide , comment je fais pour insérer quoi que ce sois dedans ?
0
Utilisateur anonyme
6 juil. 2011 à 12:43
et si tu fais copier/coller dans le dossier ?
0
ça ne marche pas non plus , voilà ce qu'il m'affiche
http://imageshack.us/photo/my-images/837/capturefge.png/
0
Utilisateur anonyme
6 juil. 2011 à 13:15
ok essaie avec cettte version

http://dl.dropbox.com/u/21363431/Vob2.exe
0
ça marche merci , comment je fais pour uploader , je ne sais pourquoi pas mais mes messages sont supprimés automatiquement
0
ça marche avec uploader.to : http://ul.to/35qh89id
0
Utilisateur anonyme
6 juil. 2011 à 22:43
attendons de voir si cedric a reussi à recuperer le fichiers ...........
0
Utilisateur anonyme
7 juil. 2011 à 10:45
Hello ,

Ouep c'est récupéré :)

Faut mettre à jours ou tu gères ?
0
Utilisateur anonyme
7 juil. 2011 à 10:55
c'est ok je vais voir si je peux les virer :)

merci
0
Utilisateur anonyme
7 juil. 2011 à 11:01

__________________________________________________
=>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
=>il est fort déconseillé de le transposer sur un autre ordinateur !<=
----------------------------------------------------------------------------


Toujours avec toutes les protections désactivées, fais ceci :

▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

----------------------------------------------------------
KillAll::

File::
E:\toaxow.exe
E:\toaxow.scr
E:\keioq.exe

Folder::
c:\users\Me....(^_^)\temp
E:\dankojebac
E:\klade

RegLock::
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{e90a8491-d13c-49f9-ad96-25b12a7ca4d4}]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]


------------------------------------------------------------------

▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
▶ Quitte le Bloc Notes

▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt


0
voici le rapport :

ComboFix 11-07-05.02 - Me....(^_^) 05/07/2011 19:39:20.1.2 - x86
Microsoft Windows 7 Edition Intégrale 6.1.7601.1.1256.213.1036.18.1024.515 [GMT 2:00]
Running from: c:\users\Me....(^_^)\Desktop\sonia.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\muzapp.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-06-05 to 2011-07-05 )))))))))))))))))))))))))))))))
.
.
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\Me....(^_^)\AppData\Local\temp
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\ME2046~1~(^_\AppData\Local\temp
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\Invité\AppData\Local\temp
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-05 16:49 . 2011-07-05 16:49 -------- d-----w- C:\sonia
2011-07-05 16:48 . 2011-07-05 17:36 -------- d-----w- C:\32788R22FWJFW
2011-07-05 15:22 . 2011-07-05 16:24 -------- d-----w- C:\Kill'em
2011-07-05 10:06 . 2011-07-05 14:49 -------- d-----w- C:\UsbFix
2011-07-03 18:11 . 2011-07-03 18:11 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-07-03 18:11 . 2011-07-03 18:11 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-28 17:16 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-28 17:16 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-28 17:16 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-28 17:16 . 2011-06-28 17:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-06-28 17:00 . 2011-05-03 04:30 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-28 17:00 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-28 17:00 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-28 17:00 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-28 17:00 . 2011-04-25 04:31 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-28 17:00 . 2011-04-25 02:18 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-28 17:00 . 2011-02-25 05:34 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-28 17:00 . 2011-04-27 02:17 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-28 17:00 . 2011-04-27 02:17 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-28 17:00 . 2011-04-27 02:17 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-28 15:37 . 2011-05-31 07:42 631400 ----a-w- c:\windows\system32\DTSSymmetryDLL.dll
2011-06-28 15:34 . 2011-05-27 15:58 1284712 ----a-w- c:\windows\RtlExUpd.dll
2011-06-28 15:33 . 2011-06-28 15:33 -------- d-----w- c:\program files\Common Files\InstallShield
2011-06-28 13:21 . 2011-06-28 13:21 -------- d-----w- c:\windows\system32\SPReview
2011-06-28 13:20 . 2011-06-28 13:20 -------- d-----w- c:\windows\system32\EventProviders
2011-06-28 10:21 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{81D4F52F-17CA-45CA-B20A-D8BA7DC87746}\mpengine.dll
2011-06-26 17:29 . 2011-06-26 17:30 -------- d-----w- c:\users\Me....(^_^)\AppData\Roaming\TeamViewer
2011-06-26 17:29 . 2011-06-26 17:29 -------- d-----w- c:\users\Me....(^_^)\temp
2011-06-13 16:48 . 2011-06-13 16:48 -------- d-----w- c:\programdata\Tencent
2011-06-11 19:25 . 2011-06-11 19:35 -------- d-----w- c:\program files\Smart PDF Converter
2011-06-06 15:37 . 2011-06-13 16:48 -------- d-----w- c:\users\Me....(^_^)\AppData\Roaming\Tencent
2011-06-06 15:18 . 2011-06-06 15:18 -------- d-----w- c:\program files\Tencent
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-05 14:49 . 2011-07-05 14:48 527832527 ----a-w- C:\UsbFix_Upload_Me_ME_-PC.zip
2011-07-04 11:43 . 2011-06-02 13:57 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:43 . 2010-08-25 12:32 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-04 11:37 . 2011-06-02 14:00 103384 ----a-w- c:\windows\system32\drivers\aswFW.sys
2011-07-04 11:36 . 2011-06-02 14:00 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:36 . 2010-08-25 12:33 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-04 11:36 . 2011-06-02 14:00 194264 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-07-04 11:35 . 2010-08-25 12:33 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-04 11:32 . 2010-08-25 12:33 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-04 11:32 . 2010-08-25 12:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-04 11:32 . 2010-08-25 12:33 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-06-28 13:37 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-05 10:53 . 2011-06-05 10:53 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-05 10:53 . 2011-06-05 10:53 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-05 10:53 . 2011-06-05 10:53 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-05 10:53 . 2011-06-05 10:53 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-05 10:53 . 2011-06-05 10:53 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-05 10:53 . 2011-06-05 10:53 367104 ----a-w- c:\windows\system32\html.iec
2011-06-05 10:53 . 2011-06-05 10:53 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-05 10:53 . 2011-06-05 10:53 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-06-05 10:53 . 2011-06-05 10:53 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-05 10:53 . 2011-06-05 10:53 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-05 10:53 . 2011-06-05 10:53 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-05 10:53 . 2011-06-05 10:53 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-05 10:53 . 2011-06-05 10:53 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-05 10:53 . 2011-06-05 10:53 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-05 10:53 . 2011-06-05 10:53 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-05 10:53 . 2011-06-05 10:53 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-05 10:53 . 2011-06-05 10:53 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-05 10:53 . 2011-06-05 10:53 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-05 10:53 . 2011-06-05 10:53 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-02 14:21 . 2011-06-02 14:21 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-24 17:14 . 2010-08-24 15:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-22 19:14 . 2011-06-01 23:47 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 06:17 . 2011-05-13 11:08 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2011-04-22 06:17 . 2011-05-13 11:08 381032 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2011-04-22 06:17 . 2011-05-13 11:08 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2011-04-15 14:00 . 2011-05-13 11:06 53248 ----a-w- c:\windows\system32\CSVer.dll
2011-04-09 06:02 . 2011-06-02 13:16 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-06-02 13:16 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56 . 2011-06-01 23:48 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-07-03 18:11 . 2011-05-08 06:41 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-03-02 15:23 68216 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-04-25 3298712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-06-09 10082920]
.
c:\users\Me....(^_^)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5205504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
.
R1 MpKslde4f279b;MpKslde4f279b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04A49BB9-1FD0-4120-B483-7EBFDE574840}\MpKslde4f279b.sys [x]
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-07-04 121000]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2010-12-21 30312]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-02 1343400]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2011-02-23 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2011-01-20 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2011-01-20 217088]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-03-28 86792]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-20 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2011-01-20 36640]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-04-22 381032]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - FSUSBEXDISK
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-08-26 06:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Télécharger avec IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger tous les liens avec IDM - c:\program files\Internet Download Manager\IEGetAll.htm
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C9804463-A972-4732-BC30-E60A3B9790E9}: NameServer = 8.8.8.8 8.8.4.4
FF - ProfilePath -
.
.
------- File Associations -------
.
.txt=STDUViewerFile.TXT
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{4DAAC69C-CBA7-45E2-9BC8-1044483D3352} - (no file)
HKCU-Run-L07FXLRD_7740031 - c:\program files\Microsoft Etudes\Microsoft Encarta 2007 - Etudes DVD\EDICT.EXE
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):92,5e,73,d9,9a,e2,4e,ae,2e,6a,c5,b0,d2,21,45,df,b9,8d,4f,74,65,
e0,b3,bc,8a,f9,09,3e,85,c4,a7,8a,15,bc,dc,5b,0b,3d,2a,df,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{e90a8491-d13c-49f9-ad96-25b12a7ca4d4}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000042
"Therad"=dword:0000001d
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-05 19:50:58
ComboFix-quarantined-files.txt 2011-07-05 17:50
.
Pre-Run: 7 979 356 160 octets libres
Post-Run: 8 012 120 064 octets libres
.
- - End Of File - - D51542504FE476FBDDB17E18B7F31C7F
0
Utilisateur anonyme
7 juil. 2011 à 14:19
c'est Combofix2.txt qu'il me faut ^^
0
oui c'est ça

ComboFix 11-07-05.02 - Me....(^_^) 05/07/2011 19:39:20.1.2 - x86
Microsoft Windows 7 Edition Intégrale 6.1.7601.1.1256.213.1036.18.1024.515 [GMT 2:00]
Running from: c:\users\Me....(^_^)\Desktop\sonia.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\muzapp.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-06-05 to 2011-07-05 )))))))))))))))))))))))))))))))
.
.
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\Me....(^_^)\AppData\Local\temp
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\ME2046~1~(^_\AppData\Local\temp
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\Invité\AppData\Local\temp
2011-07-05 17:48 . 2011-07-05 17:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-05 16:49 . 2011-07-05 16:49 -------- d-----w- C:\sonia
2011-07-05 16:48 . 2011-07-05 17:36 -------- d-----w- C:\32788R22FWJFW
2011-07-05 15:22 . 2011-07-05 16:24 -------- d-----w- C:\Kill'em
2011-07-05 10:06 . 2011-07-05 14:49 -------- d-----w- C:\UsbFix
2011-07-03 18:11 . 2011-07-03 18:11 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-07-03 18:11 . 2011-07-03 18:11 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-06-28 17:16 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-28 17:16 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-28 17:16 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-28 17:16 . 2011-06-28 17:16 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2011-06-28 17:00 . 2011-05-03 04:30 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-28 17:00 . 2011-04-29 02:46 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-06-28 17:00 . 2011-04-29 02:46 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-28 17:00 . 2011-04-29 02:46 114688 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-28 17:00 . 2011-04-25 04:31 1290624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-28 17:00 . 2011-04-25 02:18 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-28 17:00 . 2011-02-25 05:34 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-28 17:00 . 2011-04-27 02:17 223744 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-28 17:00 . 2011-04-27 02:17 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-28 17:00 . 2011-04-27 02:17 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-28 15:37 . 2011-05-31 07:42 631400 ----a-w- c:\windows\system32\DTSSymmetryDLL.dll
2011-06-28 15:34 . 2011-05-27 15:58 1284712 ----a-w- c:\windows\RtlExUpd.dll
2011-06-28 15:33 . 2011-06-28 15:33 -------- d-----w- c:\program files\Common Files\InstallShield
2011-06-28 13:21 . 2011-06-28 13:21 -------- d-----w- c:\windows\system32\SPReview
2011-06-28 13:20 . 2011-06-28 13:20 -------- d-----w- c:\windows\system32\EventProviders
2011-06-28 10:21 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{81D4F52F-17CA-45CA-B20A-D8BA7DC87746}\mpengine.dll
2011-06-26 17:29 . 2011-06-26 17:30 -------- d-----w- c:\users\Me....(^_^)\AppData\Roaming\TeamViewer
2011-06-26 17:29 . 2011-06-26 17:29 -------- d-----w- c:\users\Me....(^_^)\temp
2011-06-13 16:48 . 2011-06-13 16:48 -------- d-----w- c:\programdata\Tencent
2011-06-11 19:25 . 2011-06-11 19:35 -------- d-----w- c:\program files\Smart PDF Converter
2011-06-06 15:37 . 2011-06-13 16:48 -------- d-----w- c:\users\Me....(^_^)\AppData\Roaming\Tencent
2011-06-06 15:18 . 2011-06-06 15:18 -------- d-----w- c:\program files\Tencent
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-06-06 10:55 . 2011-06-06 10:55 183696 ----a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-05 14:49 . 2011-07-05 14:48 527832527 ----a-w- C:\UsbFix_Upload_Me_ME_-PC.zip
2011-07-04 11:43 . 2011-06-02 13:57 40112 ----a-w- c:\windows\avastSS.scr
2011-07-04 11:43 . 2010-08-25 12:32 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-04 11:37 . 2011-06-02 14:00 103384 ----a-w- c:\windows\system32\drivers\aswFW.sys
2011-07-04 11:36 . 2011-06-02 14:00 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-04 11:36 . 2010-08-25 12:33 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-04 11:36 . 2011-06-02 14:00 194264 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-07-04 11:35 . 2010-08-25 12:33 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-04 11:32 . 2010-08-25 12:33 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-04 11:32 . 2010-08-25 12:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-04 11:32 . 2010-08-25 12:33 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-06-28 13:37 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-06-05 10:53 . 2011-06-05 10:53 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-05 10:53 . 2011-06-05 10:53 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-05 10:53 . 2011-06-05 10:53 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-05 10:53 . 2011-06-05 10:53 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-05 10:53 . 2011-06-05 10:53 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-05 10:53 . 2011-06-05 10:53 367104 ----a-w- c:\windows\system32\html.iec
2011-06-05 10:53 . 2011-06-05 10:53 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-05 10:53 . 2011-06-05 10:53 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-06-05 10:53 . 2011-06-05 10:53 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-05 10:53 . 2011-06-05 10:53 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-05 10:53 . 2011-06-05 10:53 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-05 10:53 . 2011-06-05 10:53 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-05 10:53 . 2011-06-05 10:53 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-05 10:53 . 2011-06-05 10:53 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-05 10:53 . 2011-06-05 10:53 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-05 10:53 . 2011-06-05 10:53 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-05 10:53 . 2011-06-05 10:53 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-05 10:53 . 2011-06-05 10:53 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-05 10:53 . 2011-06-05 10:53 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-02 14:21 . 2011-06-02 14:21 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-24 17:14 . 2010-08-24 15:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-22 19:14 . 2011-06-01 23:47 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-04-22 06:17 . 2011-05-13 11:08 80416 ----a-w- c:\windows\system32\RtNicProp32.dll
2011-04-22 06:17 . 2011-05-13 11:08 381032 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2011-04-22 06:17 . 2011-05-13 11:08 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2011-04-15 14:00 . 2011-05-13 11:06 53248 ----a-w- c:\windows\system32\CSVer.dll
2011-04-09 06:02 . 2011-06-02 13:16 3967872 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-04-09 06:02 . 2011-06-02 13:16 3912576 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-04-09 05:56 . 2011-06-01 23:48 123904 ----a-w- c:\windows\system32\poqexec.exe
2011-07-03 18:11 . 2011-05-08 06:41 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
@="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2011-03-02 15:23 68216 ----a-w- c:\program files\Internet Download Manager\IDMShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-04-25 3298712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-06-09 10082920]
.
c:\users\Me....(^_^)\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5205504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
.
R1 MpKslde4f279b;MpKslde4f279b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04A49BB9-1FD0-4120-B483-7EBFDE574840}\MpKslde4f279b.sys [x]
R2 avast! Firewall;avast! Firewall;c:\program files\AVAST Software\Avast\afwServ.exe [2011-07-04 121000]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [2010-12-21 30312]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [2011-01-03 121192]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [2011-01-03 12776]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [2011-01-03 136680]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-02 1343400]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2011-02-23 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service; [x]
S1 aswFW;avast! TDI Firewall driver; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
S2 dgdersvc;Device Error Recovery Service;c:\windows\system32\dgdersvc.exe [2011-01-20 95568]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2011-01-20 217088]
S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-03-28 86792]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-01-20 18120]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2011-01-20 36640]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-04-22 381032]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - FSUSBEXDISK
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-05 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-08-26 06:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Télécharger avec IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger tous les liens avec IDM - c:\program files\Internet Download Manager\IEGetAll.htm
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{C9804463-A972-4732-BC30-E60A3B9790E9}: NameServer = 8.8.8.8 8.8.4.4
FF - ProfilePath -
.
.
------- File Associations -------
.
.txt=STDUViewerFile.TXT
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{4DAAC69C-CBA7-45E2-9BC8-1044483D3352} - (no file)
HKCU-Run-L07FXLRD_7740031 - c:\program files\Microsoft Etudes\Microsoft Encarta 2007 - Etudes DVD\EDICT.EXE
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-12_Symbian_USB_Download_Driver - c:\program files\Samsung\USB Drivers\12_Symbian_USB_Download_Driver\Uninstall.exe
AddRemove-15_Symbian_Samsung_PC_DLC_Driver - c:\program files\Samsung\USB Drivers\15_Symbian_Samsung_PC_DLC_Driver\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-24_flashusbdriver - c:\program files\Samsung\USB Drivers\24_flashusbdriver\Uninstall.exe
AddRemove-25_escape - c:\program files\Samsung\USB Drivers\25_escape\Uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):92,5e,73,d9,9a,e2,4e,ae,2e,6a,c5,b0,d2,21,45,df,b9,8d,4f,74,65,
e0,b3,bc,8a,f9,09,3e,85,c4,a7,8a,15,bc,dc,5b,0b,3d,2a,df,00,00,00,00,00,00,\
.
[HKEY_USERS\S-1-5-21-2485720209-627279451-2519433081-1000_Classes\CLSID\{e90a8491-d13c-49f9-ad96-25b12a7ca4d4}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000042
"Therad"=dword:0000001d
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-07-05 19:50:58
ComboFix-quarantined-files.txt 2011-07-05 17:50
.
Pre-Run: 7 979 356 160 octets libres
Post-Run: 8 012 120 064 octets libres
.
- - End Of File - - D51542504FE476FBDDB17E18B7F31C7F
0
Utilisateur anonyme
7 juil. 2011 à 14:39
non tu ne lis pas ce que je te demande de faire
0