Pc infecté need help... - Page 2

Précédent
  • 1
  • 2
  1. math31
     
    et le dernier rapport combo :

    ComboFix 11-07-15.03 - math 20/07/2011 14:24:23.3.2 - x86
    Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.2200 [GMT 2:00]
    Lancé depuis: c:\users\math\Desktop\mathieu.exe.exe
    Commutateurs utilisés :: c:\users\math\Desktop\CFScript.txt
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    FILE ::
    "c:\users\math\AppData\Local\BIT31F9.tmp"
    "c:\users\math\appdata\local\feogfqh.exe"
    "c:\users\math\winternet.exe"
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\mathieu.exe
    c:\mathieu.exe\PEV.exe
    c:\mathieu.exe\snapshot.00.dat
    c:\users\math\AppData\Local\BIT31F9.tmp
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-06-20 au 2011-07-20 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-07-20 12:28 . 2011-07-20 12:30 -------- d-----w- c:\users\math\AppData\Local\temp
    2011-07-20 12:28 . 2011-07-20 12:28 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-07-20 12:21 . 2011-07-20 12:21 -------- d-----w- C:\32788R22FWJFW
    2011-07-16 22:40 . 2011-07-19 13:35 -------- d-----w- c:\users\math\DoctorWeb
    2011-07-16 15:20 . 2011-07-16 15:22 -------- d-----w- C:\Kill'em
    2011-07-14 08:47 . 2011-07-14 08:47 -------- d-----w- c:\programdata\WindowsSearch
    2011-07-13 15:01 . 2011-06-02 12:59 2042368 ----a-w- c:\windows\system32\win32k.sys
    2011-07-13 11:22 . 2011-07-13 11:25 -------- d-----w- c:\programdata\SecTaskMan
    2011-07-13 11:22 . 2011-07-13 11:22 -------- d-----w- c:\program files\Security Task Manager
    2011-07-13 11:18 . 2011-04-20 14:47 375808 ----a-w- c:\windows\system32\winsrv.dll
    2011-07-13 11:18 . 2011-04-20 14:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
    2011-07-11 12:46 . 2011-05-04 02:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-07-11 12:00 . 2011-07-11 12:00 -------- d-----w- c:\program files\VideoLAN
    2011-06-29 19:18 . 2011-06-29 19:18 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
    2011-06-29 19:18 . 2011-06-29 19:18 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
    2011-06-29 14:12 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
    2011-06-21 12:13 . 2010-09-20 09:25 231936 ----a-w- c:\windows\system32\msshsq.dll
    2011-06-21 12:13 . 2011-06-21 12:13 -------- d-----w- c:\windows\SQL9_KB2494113_ENU
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-07-11 11:16 . 2011-06-13 08:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-07-06 17:52 . 2011-05-04 12:10 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-07-06 17:52 . 2011-05-04 12:10 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-06-13 13:54 . 2011-06-13 13:54 102400 ----a-w- c:\windows\RegBootClean.exe
    2011-06-13 08:07 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
    2011-06-13 08:07 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
    2011-05-24 17:14 . 2009-10-04 13:27 222080 ------w- c:\windows\system32\MpSigStub.exe
    2011-05-24 17:12 . 2011-06-12 20:38 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{39760014-D7C4-4A91-9F8B-E08B0AD168E8}\mpengine.dll
    2011-05-02 15:58 . 2011-06-17 14:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
    2011-04-29 12:49 . 2011-06-17 14:40 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
    2011-04-29 12:49 . 2011-06-17 14:40 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
    2011-04-29 12:49 . 2011-06-17 14:43 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-04-29 12:49 . 2011-06-17 14:43 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
    2011-04-29 12:49 . 2011-06-17 14:43 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-04-21 15:00 . 2011-06-17 14:43 833024 ----a-w- c:\windows\system32\wininet.dll
    2011-04-21 14:57 . 2011-06-17 14:43 78336 ----a-w- c:\windows\system32\ieencode.dll
    2011-04-21 13:28 . 2011-06-17 14:43 389632 ----a-w- c:\windows\system32\html.iec
    2011-04-21 13:16 . 2011-06-17 14:40 273408 ----a-w- c:\windows\system32\drivers\afd.sys
    2011-04-21 13:08 . 2011-06-17 14:43 1383424 ----a-w- c:\windows\system32\mshtml.tlb
    2011-06-29 19:18 . 2011-06-13 08:30 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    [code]<pre>
    c:\program files\Windows Live\Messenger\msnmsgr .exe
    c:\program files\Windows Media Player\WMPNSCFG .exe
    </pre>/code
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-08-25 4669440]
    "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-11-16 86016]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-16 8497696]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-16 81920]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
    2007-06-10 00:12 118784 ----a-w- c:\program files\Apoint\Apoint.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
    2009-04-16 07:41 102400 ----a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    2007-11-27 08:40 1838592 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
    2007-09-19 10:09 311296 ----a-w- c:\program files\Sony\ISB Utility\ISBMgr.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MarketingTools]
    2007-11-27 08:41 36864 ----a-w- c:\program files\Sony\Marketing Tools\MarketingTools.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2006-01-12 14:40 155648 ----a-w- c:\windows\System32\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSUFloatingUI]
    c:\program files\Sony\Network Utility\LANUtil.exe [N/A]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
    2007-09-12 00:29 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-02-15 17:50 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2009-01-22 10:44 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
    2007-01-24 11:21 563080 ----a-w- c:\windows\WindowsMobile\wmdc.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 135664]
    R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 135664]
    R3 V0010bVd;Creative WebCam Vista 36758DA8675F058C82E216D342F8F8EC4E36DE135C50FAF256BED1FE;c:\windows\system32\DRIVERS\V0010bVd.sys [2003-04-21 186551]
    R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-28 292128]
    R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2007-09-20 79136]
    S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-04-07 233472]
    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
    S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
    S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2007-08-29 9344]
    S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-06-06 812544]
    .
    .
    --- Autres Services/Pilotes en mémoire ---
    .
    *NewlyCreated* - FSUSBEXDISK
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    bthsvcs REG_MULTI_SZ BthServ
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-07-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:03]
    .
    2011-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:03]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://www.google.com
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\math\AppData\Roaming\Mozilla\Firefox\Profiles\6vf8fck6.default\
    FF - prefs.js: network.proxy.type - 0
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-07-20 14:30
    Windows 6.0.6001 Service Pack 1 NTFS
    .
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés: 0
    .
    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:0000003d
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\Sony\VAIO Event Service\VESMgr.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    c:\windows\system32\DRIVERS\xaudio.exe
    c:\windows\system32\WUDFHost.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    c:\windows\system32\conime.exe
    c:\windows\System32\rundll32.exe
    c:\windows\System32\rundll32.exe
    .
    **************************************************************************
    .
    Heure de fin: 2011-07-20 14:35:42 - La machine a redémarré
    ComboFix-quarantined-files.txt 2011-07-20 12:34
    ComboFix2.txt 2011-07-19 16:24
    .
    Avant-CF: 156 578 304 000 octets libres
    Après-CF: 155 848 876 032 octets libres
    .
    - - End Of File - - F804DBDE03253A120F3F5589D5585EFA
    0
  2. g3n-h@ckm@n
     
    que contient ce dossier ?

    c:\windows\SQL9_KB2494113_ENU
    0
  3. math31
     
    le dossier contient une application nommée "hotfix" et ses sous dossiers je ne sais pas a quoi elle sert (j'ai preferé ne pas la lancer) mais je dirais que c'est un anti spyware ou quelque chose dans le genre pourquoi?
    0
  4. g3n-h@ckm@n
     

    __________________________________________________
    =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
    =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
    ----------------------------------------------------------------------------


    Toujours avec toutes les protections désactivées, fais ceci :

    ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
    ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

    ----------------------------------------------------------
    KillAll::
    
    RenV::
    c:\program files\Windows Live\Messenger\msnmsgr .exe 
    c:\program files\Windows Media Player\WMPNSCFG .exe          
    
    

    ------------------------------------------------------------------

    ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
    ▶ Quitte le Bloc Notes

    ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

    ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
    ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. math31
     
    desole pour le retard voici le nouveau rapport :

    ComboFix 11-07-23.01 - math 23/07/2011 15:06:15.4.2 - x86 MINIMAL
    Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3070.2577 [GMT 2:00]
    Lancé depuis: c:\users\math\Desktop\mathieu.exe.exe
    Commutateurs utilisés :: c:\users\math\Desktop\CFScript.txt
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Un nouveau point de restauration a été créé
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-06-23 au 2011-07-23 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-07-23 13:11 . 2011-07-23 13:12 -------- d-----w- c:\users\math\AppData\Local\temp
    2011-07-23 13:11 . 2011-07-23 13:11 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-07-22 23:14 . 2011-07-22 23:14 -------- d-----w- c:\program files\Microsoft Silverlight
    2011-07-16 22:40 . 2011-07-19 13:35 -------- d-----w- c:\users\math\DoctorWeb
    2011-07-16 15:20 . 2011-07-16 15:22 -------- d-----w- C:\Kill'em
    2011-07-14 08:47 . 2011-07-14 08:47 -------- d-----w- c:\programdata\WindowsSearch
    2011-07-13 15:01 . 2011-06-02 12:59 2042368 ----a-w- c:\windows\system32\win32k.sys
    2011-07-13 11:22 . 2011-07-13 11:25 -------- d-----w- c:\programdata\SecTaskMan
    2011-07-13 11:22 . 2011-07-13 11:22 -------- d-----w- c:\program files\Security Task Manager
    2011-07-13 11:18 . 2011-04-20 14:47 375808 ----a-w- c:\windows\system32\winsrv.dll
    2011-07-13 11:18 . 2011-04-20 14:44 49152 ----a-w- c:\windows\system32\csrsrv.dll
    2011-07-11 12:46 . 2011-05-04 02:52 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-07-11 12:00 . 2011-07-11 12:00 -------- d-----w- c:\program files\VideoLAN
    2011-06-29 19:18 . 2011-06-29 19:18 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
    2011-06-29 19:18 . 2011-06-29 19:18 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
    2011-06-29 14:12 . 2011-04-29 14:54 276992 ----a-w- c:\windows\system32\schannel.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-07-11 11:16 . 2011-06-13 08:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-07-06 17:52 . 2011-05-04 12:10 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-07-06 17:52 . 2011-05-04 12:10 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-06-13 13:54 . 2011-06-13 13:54 102400 ----a-w- c:\windows\RegBootClean.exe
    2011-06-13 08:07 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
    2011-06-13 08:07 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
    2011-05-24 17:14 . 2009-10-04 13:27 222080 ------w- c:\windows\system32\MpSigStub.exe
    2011-05-24 17:12 . 2011-06-12 20:38 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{39760014-D7C4-4A91-9F8B-E08B0AD168E8}\mpengine.dll
    2011-05-02 15:58 . 2011-06-17 14:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
    2011-04-29 12:49 . 2011-06-17 14:40 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
    2011-04-29 12:49 . 2011-06-17 14:40 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
    2011-04-29 12:49 . 2011-06-17 14:43 213504 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-04-29 12:49 . 2011-06-17 14:43 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
    2011-04-29 12:49 . 2011-06-17 14:43 105984 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-06-29 19:18 . 2011-06-13 08:30 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    .
    [code]<pre>
    c:\program files\Windows Live\Messenger\msnmsgr .exe
    c:\program files\Windows Media Player\WMPNSCFG .exe
    </pre>/code
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-08-25 4669440]
    "NvSvc"="c:\windows\system32\nvsvc.dll" [2007-11-16 86016]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-16 8497696]
    "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-16 81920]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2007-08-14 19:05 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
    2007-06-10 00:12 118784 ----a-w- c:\program files\Apoint\Apoint.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoStartNPSAgent]
    2009-04-16 07:41 102400 ----a-w- c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    2007-11-27 08:40 1838592 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISBMgr.exe]
    2007-09-19 10:09 311296 ----a-w- c:\program files\Sony\ISB Utility\ISBMgr.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MarketingTools]
    2007-11-27 08:41 36864 ----a-w- c:\program files\Sony\Marketing Tools\MarketingTools.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2006-01-12 14:40 155648 ----a-w- c:\windows\System32\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSUFloatingUI]
    c:\program files\Sony\Network Utility\LANUtil.exe [N/A]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
    2007-09-12 00:29 443968 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-02-15 17:50 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2009-01-22 10:44 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
    2007-01-24 11:21 563080 ----a-w- c:\windows\WindowsMobile\wmdc.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    .
    R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 135664]
    R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 135664]
    R3 V0010bVd;Creative WebCam Vista 36758DA8675F058C82E216D342F8F8EC4E36DE135C50FAF256BED1FE;c:\windows\system32\DRIVERS\V0010bVd.sys [2003-04-21 186551]
    R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-28 292128]
    R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2007-09-20 79136]
    S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-04-07 233472]
    S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
    S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
    S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
    S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
    S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2007-08-29 9344]
    S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-06-06 812544]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    bthsvcs REG_MULTI_SZ BthServ
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:03]
    .
    2011-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:03]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Search_URL = hxxp://www.google.com
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
    TCP: DhcpNameServer = 192.168.1.254
    FF - ProfilePath - c:\users\math\AppData\Roaming\Mozilla\Firefox\Profiles\6vf8fck6.default\
    FF - prefs.js: network.proxy.type - 0
    .
    .
    **************************************************************************
    Recherche de processus cachés ...
    .
    Recherche d'éléments en démarrage automatique cachés ...
    .
    Recherche de fichiers cachés ...
    .
    Scan terminé avec succès
    Fichiers cachés:
    .
    **************************************************************************
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:0000003d
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\system32\conime.exe
    c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\Sony\VAIO Event Service\VESMgr.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    c:\windows\system32\DRIVERS\xaudio.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    c:\windows\system32\WUDFHost.exe
    c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
    c:\windows\System32\rundll32.exe
    c:\windows\System32\rundll32.exe
    .
    **************************************************************************
    .
    Heure de fin: 2011-07-23 15:17:01 - La machine a redémarré
    ComboFix-quarantined-files.txt 2011-07-23 13:16
    ComboFix2.txt 2011-07-20 12:35
    ComboFix3.txt 2011-07-19 16:24
    .
    Avant-CF: 153 932 320 768 octets libres
    Après-CF: 153 907 589 120 octets libres
    .
    - - End Of File - - 6AA16541C76C6BE8B48AB73A5FD7598F
    0
  7. g3n-h@ckm@n
     
    re

    supprime Pre_Scan et son rapport , retelecharge-le et refais un scan avec
    0
  8. math31
     
    http://www.cijoint.fr/cjlink.php?file=cj201107/cij7a24X7M.txt
    0
  9. g3n-h@ckm@n
     
    re

    desinstalle adobe reader 8.1.2

    fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

    ouvre Pre_script et colle ce qui suit en gras, à l'interieur du texte qui s'ouvre ,
    sans les lignes , en une seule fois en le mettant en surbrillance :
    ___________________________________________________
    Registry::
    [-HKEY_CURRENT_USER\Software\freezefrogsa]
    [-HKEY_LOCAL_MACHINE\Software\FREEzeFrog]
    [-HKEY_LOCAL_MACHINE\Software\Trymedia Systems]

    file::
    C:\ProgramData\4166v4834c8eel0t7p
    C:\ProgramData\w7hT0hg.dat
    C:\Users\math\AppData\Local\4166v4834c8eel0t7p

    folder::
    C:\ProgramData\41934584
    C:\ProgramData\Games-Attack

    attrib::

    ___________________________________________________

    copie-le (ctrl+c ou clique droit sur la selection puis => copier)

    puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

    des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

    poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

    si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
    0
Précédent
  • 1
  • 2