A voir également:
- Impossible de cliquer sur "oui"
- Vérifier un lien avant de cliquer - Guide
- Cliquez sur ce lien. en n'utilisant que le clavier, quel mot obtenez-vous ? ✓ - Forum Windows
- Selectionner sans souris =) ✓ - Forum Windows
- Cliquer sur le lien ✓ - Forum Matériel & Système
- Formule =si oui ou non excel - Guide
69 réponses
Voilà le rapport :
ComboFix 12-05-02.03 - Return 02/05/2012 22:00:26.1.2 - x86
Microsoft Windows 7 Édition Intégrale 6.1.7601.1.1252.1.1033.18.3071.2175 [GMT 2:00]
Running from: c:\users\Return\Desktop\Return.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\windows\system32\check.txt
.
.
((((((((((((((((((((((((( Files Created from 2012-04-02 to 2012-05-02 )))))))))))))))))))))))))))))))
.
.
2012-05-02 20:06 . 2012-05-02 20:06 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-05-02 20:06 . 2012-05-02 20:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-02 19:54 . 2012-05-02 19:54 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4F245356-5F8D-40EC-9E13-EE753BD6286A}\offreg.dll
2012-05-01 19:43 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4F245356-5F8D-40EC-9E13-EE753BD6286A}\mpengine.dll
2012-05-01 19:23 . 2012-05-02 14:58 -------- d-----w- C:\Pre_Scan
2012-04-29 17:04 . 2012-04-29 17:04 -------- d-----w- c:\windows\Sun
2012-04-25 20:31 . 2012-04-25 20:31 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 20:31 . 2012-04-25 20:31 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-25 20:31 . 2012-04-25 20:31 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-19 15:29 . 2012-05-01 17:36 -------- d-----w- C:\UsbFix
2012-04-19 15:29 . 2012-04-19 15:29 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-14 07:18 . 2012-04-14 07:19 -------- d-----w- c:\users\Return\AppData\Local\Chromium
2012-04-13 20:31 . 2012-04-13 20:31 -------- d-----w- c:\users\Administrator
2012-04-13 19:14 . 2012-04-13 19:14 -------- d-----w- c:\program files\Adobe Download Assistant
2012-04-12 01:00 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 01:00 . 2012-03-01 05:37 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-04-12 01:00 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-12 01:00 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-12 01:00 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-12 01:00 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-09 20:29 . 2012-04-19 15:35 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-05 01:00 . 2012-04-05 01:00 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2012-04-04 19:16 . 2012-04-04 19:26 -------- d-----w- c:\users\Return\AppData\Roaming\TS3Client
2012-04-04 19:16 . 2012-04-04 19:16 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-04-04 13:30 . 2012-04-04 13:30 -------- d-----w- c:\programdata\LogiShrd
2012-04-04 13:28 . 2012-04-04 13:28 -------- d-----w- c:\users\Return\AppData\Local\LogiShrd
2012-04-04 13:24 . 2012-04-04 13:24 53248 ----a-r- c:\users\Return\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-04-04 13:24 . 2012-04-04 13:24 -------- d-----w- c:\users\Return\AppData\Roaming\Leadertech
2012-04-04 13:21 . 2012-04-04 13:21 -------- d-----w- c:\programdata\Logitech
2012-04-04 13:21 . 2012-04-04 13:21 -------- d-----w- c:\program files\Common Files\LWS
2012-04-04 13:20 . 2012-04-04 13:25 -------- d-----w- c:\program files\Common Files\LogiShrd
2012-04-04 13:20 . 2012-04-04 13:25 -------- d-----w- c:\program files\Logitech
2012-04-02 20:54 . 2012-04-02 20:54 -------- d-----w- c:\users\Return\AppData\Roaming\Avira
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-01 17:36 . 2012-04-19 15:34 161055895 ----a-w- C:\UsbFix_Upload_Me_GAME.zip
2012-04-28 19:53 . 2012-04-02 19:48 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-19 15:35 . 2011-08-22 13:54 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 13:56 . 2011-12-23 19:45 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-28 07:14 . 2012-03-27 15:39 11333 ------w- C:\XTrapd11.vxd
2012-02-29 18:45 . 2012-02-29 18:40 286173 ----a-w- c:\windows\system32\HOSTS_Anti-Adware.exe
2012-02-29 18:29 . 2011-08-29 08:45 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-23 08:18 . 2011-08-22 11:52 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-19 02:01 . 2012-02-19 02:01 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-02-19 02:01 . 2012-02-19 02:01 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-02-19 02:01 . 2012-02-19 02:01 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-02-19 02:01 . 2012-02-19 02:01 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-02-19 02:01 . 2012-02-19 02:01 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-02-19 02:01 . 2012-02-19 02:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-02-19 02:01 . 2012-02-19 02:01 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-02-19 02:01 . 2012-02-19 02:01 367104 ----a-w- c:\windows\system32\html.iec
2012-02-19 02:01 . 2012-02-19 02:01 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-02-19 02:01 . 2012-02-19 02:01 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-02-19 02:01 . 2012-02-19 02:01 161792 ----a-w- c:\windows\system32\msls31.dll
2012-02-19 02:01 . 2012-02-19 02:01 152064 ----a-w- c:\windows\system32\wextract.exe
2012-02-19 02:01 . 2012-02-19 02:01 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-02-19 02:01 . 2012-02-19 02:01 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-02-19 02:01 . 2012-02-19 02:01 11776 ----a-w- c:\windows\system32\mshta.exe
2012-02-19 02:01 . 2012-02-19 02:01 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-02-19 02:01 . 2012-02-19 02:01 101888 ----a-w- c:\windows\system32\admparse.dll
2012-02-17 05:34 . 2012-03-14 08:32 919040 ----a-w- c:\windows\system32\rdpcorets.dll
2012-02-17 05:34 . 2012-03-14 08:32 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 04:14 . 2012-03-14 08:32 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:13 . 2012-03-14 08:32 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 05:38 . 2012-03-14 08:33 1077248 ----a-w- c:\windows\system32\DWrite.dll
2012-02-03 03:54 . 2012-03-14 08:33 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-04-25 20:31 . 2011-09-15 16:18 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-22 26104104]
"Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-12-01 258512]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-01 190808]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
.
[HKLM\~\startupfolder\C:^Users^Return^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\Return\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
2010-08-09 12:47 248832 ----a-w- c:\program files\FileHippo.com\UpdateChecker.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-04-04 13:56 462408 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2012-04-04 13:56 981680 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-08-10 17:44 4217720 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 13:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 253088]
R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 136176]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2011-11-25 311928]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-05-11 4330168]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt; [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-12-01 36000]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AntiVirSchedulerService;Avira Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-12-01 86224]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 1373576]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 15:35]
.
2012-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 13:55]
.
2012-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 13:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Return\AppData\Roaming\Mozilla\Firefox\Profiles\2d20scz9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-51014960.sys
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\DTLite.exe
MSConfigStartUp-SwitchBoard - c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2656635725-449782252-1615114488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2656635725-449782252-1615114488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-05-02 22:08:11
ComboFix-quarantined-files.txt 2012-05-02 20:08
.
Pre-Run: 195 123 314 688 octets libres
Post-Run: 195 051 393 024 octets libres
.
- - End Of File - - 136EFC269C49CE9AC8F20567E4618402
ComboFix 12-05-02.03 - Return 02/05/2012 22:00:26.1.2 - x86
Microsoft Windows 7 Édition Intégrale 6.1.7601.1.1252.1.1033.18.3071.2175 [GMT 2:00]
Running from: c:\users\Return\Desktop\Return.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\windows\system32\check.txt
.
.
((((((((((((((((((((((((( Files Created from 2012-04-02 to 2012-05-02 )))))))))))))))))))))))))))))))
.
.
2012-05-02 20:06 . 2012-05-02 20:06 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp
2012-05-02 20:06 . 2012-05-02 20:06 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-02 19:54 . 2012-05-02 19:54 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4F245356-5F8D-40EC-9E13-EE753BD6286A}\offreg.dll
2012-05-01 19:43 . 2012-04-13 07:36 6734704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4F245356-5F8D-40EC-9E13-EE753BD6286A}\mpengine.dll
2012-05-01 19:23 . 2012-05-02 14:58 -------- d-----w- C:\Pre_Scan
2012-04-29 17:04 . 2012-04-29 17:04 -------- d-----w- c:\windows\Sun
2012-04-25 20:31 . 2012-04-25 20:31 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 20:31 . 2012-04-25 20:31 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-25 20:31 . 2012-04-25 20:31 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-19 15:29 . 2012-05-01 17:36 -------- d-----w- C:\UsbFix
2012-04-19 15:29 . 2012-04-19 15:29 -------- d-----w- C:\TDSSKiller_Quarantine
2012-04-14 07:18 . 2012-04-14 07:19 -------- d-----w- c:\users\Return\AppData\Local\Chromium
2012-04-13 20:31 . 2012-04-13 20:31 -------- d-----w- c:\users\Administrator
2012-04-13 19:14 . 2012-04-13 19:14 -------- d-----w- c:\program files\Adobe Download Assistant
2012-04-12 01:00 . 2012-03-01 05:46 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 01:00 . 2012-03-01 05:37 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-04-12 01:00 . 2012-03-01 05:33 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-12 01:00 . 2012-03-01 05:29 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-12 01:00 . 2012-03-06 05:59 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-12 01:00 . 2012-03-06 05:59 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-09 20:29 . 2012-04-19 15:35 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-05 01:00 . 2012-04-05 01:00 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2012-04-04 19:16 . 2012-04-04 19:26 -------- d-----w- c:\users\Return\AppData\Roaming\TS3Client
2012-04-04 19:16 . 2012-04-04 19:16 -------- d-----w- c:\program files\TeamSpeak 3 Client
2012-04-04 13:30 . 2012-04-04 13:30 -------- d-----w- c:\programdata\LogiShrd
2012-04-04 13:28 . 2012-04-04 13:28 -------- d-----w- c:\users\Return\AppData\Local\LogiShrd
2012-04-04 13:24 . 2012-04-04 13:24 53248 ----a-r- c:\users\Return\AppData\Roaming\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-04-04 13:24 . 2012-04-04 13:24 -------- d-----w- c:\users\Return\AppData\Roaming\Leadertech
2012-04-04 13:21 . 2012-04-04 13:21 -------- d-----w- c:\programdata\Logitech
2012-04-04 13:21 . 2012-04-04 13:21 -------- d-----w- c:\program files\Common Files\LWS
2012-04-04 13:20 . 2012-04-04 13:25 -------- d-----w- c:\program files\Common Files\LogiShrd
2012-04-04 13:20 . 2012-04-04 13:25 -------- d-----w- c:\program files\Logitech
2012-04-02 20:54 . 2012-04-02 20:54 -------- d-----w- c:\users\Return\AppData\Roaming\Avira
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-01 17:36 . 2012-04-19 15:34 161055895 ----a-w- C:\UsbFix_Upload_Me_GAME.zip
2012-04-28 19:53 . 2012-04-02 19:48 137416 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-04-19 15:35 . 2011-08-22 13:54 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 13:56 . 2011-12-23 19:45 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-28 07:14 . 2012-03-27 15:39 11333 ------w- C:\XTrapd11.vxd
2012-02-29 18:45 . 2012-02-29 18:40 286173 ----a-w- c:\windows\system32\HOSTS_Anti-Adware.exe
2012-02-29 18:29 . 2011-08-29 08:45 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-23 08:18 . 2011-08-22 11:52 237072 ------w- c:\windows\system32\MpSigStub.exe
2012-02-19 02:01 . 2012-02-19 02:01 86528 ----a-w- c:\windows\system32\iesysprep.dll
2012-02-19 02:01 . 2012-02-19 02:01 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2012-02-19 02:01 . 2012-02-19 02:01 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2012-02-19 02:01 . 2012-02-19 02:01 74752 ----a-w- c:\windows\system32\iesetup.dll
2012-02-19 02:01 . 2012-02-19 02:01 63488 ----a-w- c:\windows\system32\tdc.ocx
2012-02-19 02:01 . 2012-02-19 02:01 48640 ----a-w- c:\windows\system32\mshtmler.dll
2012-02-19 02:01 . 2012-02-19 02:01 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-02-19 02:01 . 2012-02-19 02:01 367104 ----a-w- c:\windows\system32\html.iec
2012-02-19 02:01 . 2012-02-19 02:01 35840 ----a-w- c:\windows\system32\imgutil.dll
2012-02-19 02:01 . 2012-02-19 02:01 23552 ----a-w- c:\windows\system32\licmgr10.dll
2012-02-19 02:01 . 2012-02-19 02:01 161792 ----a-w- c:\windows\system32\msls31.dll
2012-02-19 02:01 . 2012-02-19 02:01 152064 ----a-w- c:\windows\system32\wextract.exe
2012-02-19 02:01 . 2012-02-19 02:01 150528 ----a-w- c:\windows\system32\iexpress.exe
2012-02-19 02:01 . 2012-02-19 02:01 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-02-19 02:01 . 2012-02-19 02:01 11776 ----a-w- c:\windows\system32\mshta.exe
2012-02-19 02:01 . 2012-02-19 02:01 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2012-02-19 02:01 . 2012-02-19 02:01 101888 ----a-w- c:\windows\system32\admparse.dll
2012-02-17 05:34 . 2012-03-14 08:32 919040 ----a-w- c:\windows\system32\rdpcorets.dll
2012-02-17 05:34 . 2012-03-14 08:32 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 04:14 . 2012-03-14 08:32 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:13 . 2012-03-14 08:32 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 05:38 . 2012-03-14 08:33 1077248 ----a-w- c:\windows\system32\DWrite.dll
2012-02-03 03:54 . 2012-03-14 08:33 2343424 ----a-w- c:\windows\system32\win32k.sys
2012-04-25 20:31 . 2011-09-15 16:18 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-22 26104104]
"Logitech Vid"="c:\program files\Logitech\Vid HD\Vid.exe" [2011-01-13 6129496]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-02-28 1987976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-12-01 258512]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2011-03-01 190808]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-15 499608]
"AdobeCS5.5ServiceManager"="c:\program files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
.
[HKLM\~\startupfolder\C:^Users^Return^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
path=c:\users\Return\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
backup=c:\windows\pss\OpenOffice.org 3.3.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
2010-08-09 12:47 248832 ----a-w- c:\program files\FileHippo.com\UpdateChecker.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-04-04 13:56 462408 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2012-04-04 13:56 981680 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-08-10 17:44 4217720 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 13:02 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 136176]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-19 253088]
R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 136176]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2011-11-25 311928]
R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [2012-04-25 129976]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-05-11 4330168]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt; [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [2011-12-01 36000]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 AntiVirSchedulerService;Avira Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-12-01 86224]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [2012-02-28 1373576]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-05-21 2214504]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 22344]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-02 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-09 15:35]
.
2012-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 13:55]
.
2012-05-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-22 13:55]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Return\AppData\Roaming\Mozilla\Firefox\Profiles\2d20scz9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - prefs.js: keyword.URL - hxxp://fr.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-51014960.sys
SafeBoot-dmboot.sys
SafeBoot-dmio.sys
SafeBoot-dmload.sys
SafeBoot-dmadmin
SafeBoot-dmserver
SafeBoot-SRService
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\DTLite.exe
MSConfigStartUp-SwitchBoard - c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2656635725-449782252-1615114488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-2656635725-449782252-1615114488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-05-02 22:08:11
ComboFix-quarantined-files.txt 2012-05-02 20:08
.
Pre-Run: 195 123 314 688 octets libres
Post-Run: 195 051 393 024 octets libres
.
- - End Of File - - 136EFC269C49CE9AC8F20567E4618402
Fais analyser le(s) fichier(s) suivants sur Virustotal :
Virus Total
clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :
c:\windows\system32\HOSTS_Anti-Adware.exe
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.
Virus Total
clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :
c:\windows\system32\HOSTS_Anti-Adware.exe
* Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
* Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
* Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Hey,
c:\windows\system32\HOSTS_Anti-Adware.exe ->>>>>>>>
C'est le hosts anti-pubs de Malekal il me semble ;-).
c:\windows\system32\HOSTS_Anti-Adware.exe ->>>>>>>>
C'est le hosts anti-pubs de Malekal il me semble ;-).
Tu peux retélécharger Pre_Scan, Démarrer en mode sans échec, lancer Pre_Scan et nous dire ce qu'il en est ?
J'ai lancer en mode sans échec, l'outil a redémarré l'ordi et là il y a juste le menu qui s'ouvre et rien d'autre..