Spyware secure encore et toujours - Page 2

Précédent
  • 1
  • 2
  1. Alpha007
     
    Voili voilou

    "Sylvain" - 2007-07-01 15:04:09 - ComboFix 07-06-27.7 - Service Pack 2 NTFS

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    C:\WINDOWS\installer\3af71b.msi

    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    -------\LEGACY_NWSAPAGENT
    -------\NwSapAgent

    ((((((((((((((((((((((((( Files Created from 2007-06-01 to 2007-07-01 )))))))))))))))))))))))))))))))

    2007-07-01 14:47 49,152 --a------ C:\WINDOWS\nircmd.exe
    2007-07-01 13:20 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
    2007-06-30 19:26 <REP> d-------- C:\Program Files\Windows Live
    2007-06-30 19:26 <REP> d-------- C:\Program Files\Messenger Plus! Live
    2007-06-26 21:32 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2007-06-26 21:26 <REP> d-------- C:\Program Files\SpywareBlaster
    2007-06-26 20:09 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-06-24 19:25 <REP> d-------- C:\DOCUME~1\JEAN-M~1\APPLIC~1\ispnews
    2007-06-24 12:06 <REP> d-------- C:\DOCUME~1\Sylvain\APPLIC~1\ispnews
    2007-06-24 12:06 <REP> d-------- C:\DOCUME~1\Sylvain\APPLIC~1\F-Secure
    2007-06-24 12:00 <REP> d-------- C:\Program Files\F-Secure Internet Security
    2007-06-20 07:28 <REP> d-------- C:\DOCUME~1\Fabien\APPLIC~1\Thunderbird
    2007-06-17 14:00 <REP> d-------- C:\DOCUME~1\JEAN-M~1\APPLIC~1\Canon
    2007-06-17 13:51 <REP> d-------- C:\Program Files\Canon
    2007-06-17 13:50 <REP> d-------- C:\Program Files\ScanSoft
    2007-06-17 13:50 <REP> d-------- C:\Program Files\Fichiers communs\ScanSoft Shared
    2007-06-17 13:50 <REP> d-------- C:\DOCUME~1\JEAN-M~1\APPLIC~1\ScanSoft
    2007-06-17 13:50 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
    2007-06-17 13:48 57,344 --a------ C:\WINDOWS\system32\CNQU110.DLL
    2007-06-17 13:48 352,256 --a------ C:\WINDOWS\system32\CNQL1213.DLL
    2007-06-17 13:48 <REP> d--h----- C:\CanoScan
    2007-06-17 12:30 <REP> d-------- C:\Program Files\OpenOffice.org 2.2
    2007-06-16 02:26 <REP> d-------- C:\Program Files\Alwil Software
    2007-06-16 02:16 <REP> d-------- C:\WINDOWS\system32\ActiveScan
    2007-06-14 22:47 <REP> d-------- C:\Program Files\AVPersonal
    2007-06-11 20:21 <REP> d-------- C:\Program Files\SpeedSim

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-07-01 08:56:29 -------- d-----w C:\Program Files\Mozilla Thunderbird
    2007-06-30 17:26:15 -------- d-----w C:\Program Files\MSN Messenger
    2007-06-26 21:46:19 75,506 ----a-w C:\WINDOWS\system32\perfc00C.dat
    2007-06-26 21:46:19 468,490 ----a-w C:\WINDOWS\system32\perfh00C.dat
    2007-06-24 12:20:25 -------- d-----w C:\Program Files\eMule
    2007-06-24 12:17:58 -------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-06-24 12:16:18 -------- d-----w C:\Program Files\Valve Hammer Editor
    2007-06-24 12:15:23 -------- d-----w C:\DOCUME~1\Sylvain\APPLIC~1\Skype
    2007-06-17 10:29:48 -------- d-----w C:\Program Files\OpenOffice.org 2.1
    2007-05-20 13:00:33 -------- d-----w C:\Program Files\QuickTime
    2007-05-16 15:13:53 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
    2007-05-09 18:53:40 -------- d-----w C:\Program Files\Warcraft III
    2007-05-07 13:24:30 55,129 ----a-w C:\WINDOWS\War3Unin.dat
    2007-05-07 13:23:56 2,829 ----a-w C:\WINDOWS\War3Unin.pif
    2007-05-07 13:23:56 139,264 ----a-w C:\WINDOWS\War3Unin.exe
    2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
    2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
    2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
    2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
    2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
    2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
    2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
    2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
    2007-04-10 18:58:28 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-19 16:28]
    "NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-20 17:12]
    "NvMediaCenter"="NvMCTray.dll" [2006-10-22 13:22 C:\WINDOWS\system32\nvmctray.dll]
    "TomcatStartup"="C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 20:28]
    "DXDllRegExe"="dxdllreg.exe" []
    "SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 13:16]
    "OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 12:45]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 08:38]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28]
    "StatusClient"="C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 17:51]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
    "Steam"="" []
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=0 (0x0)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 14:29]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    Usnsvc usnsvc

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{96f2a644-f8a7-11da-9893-806d6172696f}]
    AutoRun\command- D:\setup.exe

    Contents of the 'Scheduled Tasks' folder
    2007-06-24 12:57:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    2007-06-30 11:43:39 C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job

    **************************************************************************

    catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-01 15:08:47
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    Completion time: 2007-07-01 15:10:24 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-07-01 15:10

    --- E O F ---

    et hop
    0
  2. moK´s@ Messages postés 4410 Statut Membre 89
     
    re,

    ¤ Télécharge Clean
    ----> http://www.malekal.com/download/clean.zip

    Dézippe tout le contenu dans le même dossier. Double clic sur clean ou clean.cmd choisissez l'option 1.
    Un rapport va s'ouvrir, copie et colle le contenu ici
    0
  3. Alpha0007
     
    02/07/2007 a 1:35:52,32

    *** Recherche des fichiers dans C:

    *** Recherche des fichiers dans C:\WINDOWS\

    *** Recherche des fichiers dans C:\WINDOWS\system32

    *** Recherche des fichiers dans C:\Program Files
    *** Fin du rapport !
    0
  4. moK´s@ Messages postés 4410 Statut Membre 89
     
    salut alpha0007,

    comment se porte ton pc maintenant?
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Alpha007
     
    Bes hier, il a lager servère. (les page qui fond des vague quand on monte ou on descend, les paramétres partie, et l'option veille grisé et il ramait).

    Mais depuis se matin, y'a pas de souci avec les page. Il rame plus, pour le moment sa va loool.

    Donc merci encore, je t'en reparle dans quelque jour pour te dire si sa s'arenge.
    0
  7. moK´s@ Messages postés 4410 Statut Membre 89
     
    ok alpha

    @+
    0
  8. nancyjose Messages postés 2 Statut Membre
     
    SmitFraudFix v2.197

    Rapport fait à 17:34:05,65, 2007-06-30
    Executé à partir de C:\Documents and Settings\steve cote\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url supprimé
    C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url supprimé
    C:\DOCUME~1\STEVEC~1\Favoris\Online Security Test.url supprimé
    Problème suppression C:\Program Files\Video ActiveX Access\

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    Description: Carte Fast Ethernet PCI de base SiS 900 - Miniport d'ordonnancement de paquets
    DNS Server Search Order: 24.200.241.37
    DNS Server Search Order: 24.201.245.77
    DNS Server Search Order: 24.200.243.189

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{C93FA787-4474-4F74-B7EA-C6314172E0F9}: DhcpNameServer=24.200.241.37 24.201.245.77 24.200.243.189
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{C93FA787-4474-4F74-B7EA-C6314172E0F9}: DhcpNameServer=24.200.241.37 24.201.245.77 24.200.243.189
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{C93FA787-4474-4F74-B7EA-C6314172E0F9}: DhcpNameServer=24.200.241.37 24.201.245.77 24.200.243.189
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77 24.200.243.189
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77 24.200.243.189
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=24.200.241.37 24.201.245.77 24.200.243.189

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Reboot

    C:\Program Files\Video ActiveX Access supprimé

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    -1
    1. moK´s@ Messages postés 4410 Statut Membre 89
       
      oui c bien smitfraud a supprimé des fichiers mais je ne sais meme pas la nature de ton probleme...

      Il serait préférable que tu fasses ton message personnel, cela rendra les postes plus compréhensibles et la réponse à ton problème sera plus efficace
      Procèdes comme ceci :
      http://pageperso.aol.fr/balltrap34/demofairesontmessage.htm

      A bientôt
      0
Précédent
  • 1
  • 2