J'ai un probléme dee spyware je ne sias plus
Résolu/Fermé
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
-
19 juil. 2007 à 13:09
Regis59 Messages postés 21143 Date d'inscription mardi 27 juin 2006 Statut Contributeur sécurité Dernière intervention 22 juin 2016 - 22 juil. 2007 à 21:57
Regis59 Messages postés 21143 Date d'inscription mardi 27 juin 2006 Statut Contributeur sécurité Dernière intervention 22 juin 2016 - 22 juil. 2007 à 21:57
A voir également:
- J'ai un probléme dee spyware je ne sias plus
- Spyware doctor - Télécharger - Antivirus & Antimalwares
- Temu spyware - Accueil - Applications & Logiciels
- Spyware gratuit - Télécharger - Antivirus & Antimalwares
- Spyware terminator - Télécharger - Antivirus & Antimalwares
- Spyware blaster - Télécharger - Antivirus & Antimalwares
43 réponses
bonjour, télécharge ,Spyware,terminator ici sur le forum , tape spyware terminator ,tu tombe dessus
fait une analyse approfondie pas rapide tout de suite , sa prend pas mal de temps ,le critique va être en rouge , et a la fin tu supprime tout de ton DD, bonne chance
fait une analyse approfondie pas rapide tout de suite , sa prend pas mal de temps ,le critique va être en rouge , et a la fin tu supprime tout de ton DD, bonne chance
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
19 juil. 2007 à 13:30
19 juil. 2007 à 13:30
bah merci beaucoup j'essaye tout ca, puis j vous dis ca quand j'ai finis mon analyse.
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
19 juil. 2007 à 16:19
19 juil. 2007 à 16:19
voila je viens de faire toutes les analyses avec spyware terminator mais en reverifiant avec spybot il met toujours que j ai les spyware DOUBLECLICK TRADEDOUBLER et VIRTUMONDE.
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
19 juil. 2007 à 17:43
19 juil. 2007 à 17:43
personne pour m'aider ?
re bonjour, demarre spybot
clik sur aide , puis sur Search et destroyer,puis sur recherche
balayer le système, lis le bien et suis les instructions
pour supprimer tes spaywares a la fin de l'analyse, ce qui est cocher en rouge sais être supprimé
j'ai le même programme,
clik sur aide , puis sur Search et destroyer,puis sur recherche
balayer le système, lis le bien et suis les instructions
pour supprimer tes spaywares a la fin de l'analyse, ce qui est cocher en rouge sais être supprimé
j'ai le même programme,
a la fin de l'analyse, tu clic sur toutes les croix cochées en rouge, et tu clic sur corriger les problèmes
ce qui est coché en rouge devient en vert.
ce qui est coché en rouge devient en vert.
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
19 juil. 2007 à 20:29
19 juil. 2007 à 20:29
Non spyware terminator ne m'a rien mentioné de special. Merci pour l'aide j'ai viré quand meme 2 fichiers à haut risque mais il me reste quand meme des trucs, je verrais bien, pour l'instant j'ai plus de publicitées mais je ne le concidere pas encore tout a fait resolus parce que je ne sais comment ca va faire avec les fichier temporaires il m en a déjà recréé plein mais il ne se lance pas dans le gestionnaire des taches je verrais demain matin. Puis je n ai toujours pas viré VIRTUMONDE et je n'arrive vraiment pas à l'enlever avec VUNDOFIX.
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
20 juil. 2007 à 11:47
20 juil. 2007 à 11:47
spywaree n'a rien changé mes pubs sont revenues des ce matin que dois-je faire ? aidez moi svp
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
20 juil. 2007 à 17:01
20 juil. 2007 à 17:01
Bienvenue sur le forum d’entraide de CommentCaMarche.net
Nous connaissons votre situation et nous vous conseillons de ne surtout pas vous inquiéter.
De plus, au vu du nombre croissant de désinfections effectuées sur le forum, nous vous demandons un peu de patience et surtout de ne pas créer plusieurs postes pour le même problème.
Merci de votre compréhension.
Télécharge HijackThis ici:
http://telechargement.zebulon.fr/138-hijackthis-1991.html
Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre le bien dans c : !
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Lance le puis:
clique sur "do a system scan and save logfile" (cf démo)
faire un copier coller du log entier sur le forum
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm
Bon courage
A+
Nous connaissons votre situation et nous vous conseillons de ne surtout pas vous inquiéter.
De plus, au vu du nombre croissant de désinfections effectuées sur le forum, nous vous demandons un peu de patience et surtout de ne pas créer plusieurs postes pour le même problème.
Merci de votre compréhension.
Télécharge HijackThis ici:
http://telechargement.zebulon.fr/138-hijackthis-1991.html
Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre le bien dans c : !
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/Hijenr.gif
Lance le puis:
clique sur "do a system scan and save logfile" (cf démo)
faire un copier coller du log entier sur le forum
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm
Bon courage
A+
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
21 juil. 2007 à 13:50
21 juil. 2007 à 13:50
comme demandé voila mon rapport HIJACKTHIS:
Logfile of HijackThis v1.99.1
Scan saved at 13:49:34, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll
O2 - BHO: (no name) - {DCD53738-C4F9-414A-A03C-C7405A4AC844} - C:\WINDOWS\system32\mljgeda.dll
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geedc - C:\WINDOWS\system32\geedc.dll
O20 - Winlogon Notify: mljgeda - C:\WINDOWS\SYSTEM32\mljgeda.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
Logfile of HijackThis v1.99.1
Scan saved at 13:49:34, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll
O2 - BHO: (no name) - {DCD53738-C4F9-414A-A03C-C7405A4AC844} - C:\WINDOWS\system32\mljgeda.dll
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: geedc - C:\WINDOWS\system32\geedc.dll
O20 - Winlogon Notify: mljgeda - C:\WINDOWS\SYSTEM32\mljgeda.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
21 juil. 2007 à 14:01
21 juil. 2007 à 14:01
Ok :)
Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer.
Coche Run VundoFix as a task.
Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
Clique sur le bouton Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
Démarre ton PC à nouveau.
Copie/colle le contenu du rapport situé dans C:\vundofix.txt.
Puis,
Télécharge Combofix sUBs :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
Attends que combofix ait terminé, ne touche a rien pendant qu'il travaille, un rapport sera créé. Poste le rapport.
Copie/colle un nouveau rapport HiJackThis avec.
A++
Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer.
Coche Run VundoFix as a task.
Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
Clique sur le bouton Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
Démarre ton PC à nouveau.
Copie/colle le contenu du rapport situé dans C:\vundofix.txt.
Puis,
Télécharge Combofix sUBs :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
Attends que combofix ait terminé, ne touche a rien pendant qu'il travaille, un rapport sera créé. Poste le rapport.
Copie/colle un nouveau rapport HiJackThis avec.
A++
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
21 juil. 2007 à 14:21
21 juil. 2007 à 14:21
voila le rapport combo FIX :
"kirchener" - 2007-07-21 14:12:40 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\mljgeda.dll
C:\WINDOWS\system32\mljgeda.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\epkoihuu.exe
C:\WINDOWS\system32\gdpffmit.exe
C:\WINDOWS\system32\gdxxnhvh.exe
C:\WINDOWS\system32\gtamptst.exe
C:\WINDOWS\system32\kkbdyiuw.exe
C:\WINDOWS\system32\ohxykqvu.exe
C:\WINDOWS\system32\pdyevlum.exe
C:\WINDOWS\system32\tjmmnwey.exe
C:\WINDOWS\system32\uhngjver.exe
C:\WINDOWS\system32\vgyfmpdl.exe
C:\WINDOWS\system32\W007T32W.DLL
C:\WINDOWS\system32\wgpyrpjw.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-21 to 2007-07-21 )))))))))))))))))))))))))))))))
2007-07-21 14:12 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-21 13:49 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
2007-07-19 14:08 138,368 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-07-19 13:23 <REP> d-------- C:\Program Files\Spyware Terminator
2007-07-19 13:23 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\Spyware Terminator
2007-07-19 13:23 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spyware Terminator
2007-07-18 20:22 <REP> d-------- C:\Program Files\Micro Application
2007-07-18 16:30 <REP> d-------- C:\Program Files\Lavasoft
2007-07-18 16:30 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-18 10:15 <REP> d-------- C:\Program Files\ThinkNet
2007-07-14 18:38 <REP> d-------- C:\VundoFix Backups
2007-07-12 14:26 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\ScanSoft
2007-07-12 14:19 <REP> d-------- C:\Program Files\Fichiers communs\Scansoft Shared
2007-07-12 14:19 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
2007-07-12 14:18 <REP> d-------- C:\Program Files\ScanSoft
2007-07-12 14:17 <REP> d-------- C:\WINDOWS\speech
2007-07-12 10:32 <REP> d-------- C:\Program Files\CDisplay
2007-07-11 14:29 <REP> d-------- C:\Program Files\Combined Community Codec Pack
2007-07-02 21:27 <REP> d-------- C:\Program Files\Artefacts Studio
2007-06-30 18:11 1,726 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-30 17:16 6,108 --a------ C:\dnsbak.reg
2007-06-30 16:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-29 20:30 <REP> d-------- C:\Program Files\a-squared Free
2007-06-27 11:59 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\ItsLabel
2007-06-27 11:58 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\EoRezo
2007-06-22 18:25 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-06-22 18:25 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-06-22 18:25 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-06-22 18:25 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-06-22 18:24 <REP> d-------- C:\WINDOWS\system32\AGEIA
2007-06-22 18:24 <REP> d-------- C:\Program Files\AGEIA Technologies
2007-06-22 18:18 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\dp3d
2007-06-22 18:17 <REP> d-------- C:\Program Files\Two Worlds Pinball
2007-06-22 18:11 <REP> d-------- C:\Program Files\Reality Pump
2007-06-21 13:15 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\SystemRequirementsLab
2007-06-21 10:17 <REP> d-------- C:\Program Files\Mindscape
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-21 12:09:47 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\Azureus
2007-07-21 11:49:34 -------- d-----w C:\Program Files\Hijackthis Version Française
2007-07-19 16:10:23 -------- d-----w C:\Program Files\World of Warcraft
2007-07-19 11:07:36 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\OpenOffice.org2
2007-07-18 18:21:59 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-18 14:30:19 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\Lavasoft
2007-07-18 14:29:13 -------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-07-12 16:49:14 541,290 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-07-12 16:49:13 90,974 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-07-12 15:56:38 -------- d-----w C:\Program Files\MatroskaProp
2007-07-11 10:36:09 -------- d-----w C:\Program Files\Matroska Pack
2007-07-06 08:47:11 -------- d-----w C:\Program Files\MSN Messenger
2007-07-05 15:44:00 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-06-22 09:14:21 -------- d-----w C:\Program Files\Azureus
2007-06-20 13:49:40 -------- d-----w C:\Program Files\WowCartographe
2007-06-18 09:12:52 -------- d-----w C:\Program Files\Fichiers communs\Cheewoo
2007-06-18 09:12:31 -------- d-----w C:\Program Files\Cheewoo
2007-06-16 11:42:03 51,650 ----a-w C:\WINDOWS\htrefreghreger.exe
2007-06-14 19:37:10 -------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2007-06-14 13:50:55 71,625 ----a-w C:\WINDOWS\twesdwdewewd.exe
2007-06-14 13:26:50 1,156 ----a-w C:\WINDOWS\mozver.dat
2007-06-14 13:08:39 -------- d-----w C:\Program Files\Sygate
2007-06-14 10:04:46 0 ----a-w C:\WINDOWS\nsreg.dat
2007-06-09 09:57:14 -------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2007-06-09 09:17:16 -------- d-----w C:\Program Files\MSXML 4.0
2007-06-08 16:37:28 -------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-06-05 09:29:22 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\Gearbox Software
2007-06-04 13:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 13:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 13:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-04 06:40:02 -------- d--h--r C:\DOCUME~1\KIRCHE~1\APPLIC~1\SecuROM
2007-06-04 06:40:00 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-06-01 08:50:32 -------- d-----w C:\Program Files\DivX
2007-05-31 11:31:27 -------- d-----w C:\Program Files\Fichiers communs\DirectX
2007-05-31 06:45:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-31 06:44:55 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 06:44:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 06:44:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 06:44:54 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-05-29 10:20:33 -------- d-----w C:\Program Files\Canon
2007-05-28 08:06:07 -------- d-----w C:\Program Files\directx
2007-05-27 10:44:28 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\InstallShield
2007-05-22 09:21:45 -------- d-----w C:\Program Files\CONEXANT
2007-05-16 15:13:53 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-07 11:59:32 2,553 ----a-w C:\WINDOWS\system32\sdbackup.reg
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2004-08-05 12:00:00 87,057 --sh--r C:\WINDOWS\system32\comyobap.exe
2004-08-05 12:00:00 75,017 --sh--r C:\WINDOWS\system32\edconss.exe
2004-08-05 12:00:00 70,376 --sh--r C:\WINDOWS\system32\escsn.exe
2004-08-05 12:00:00 71,625 --sh--r C:\WINDOWS\system32\ikern32.exe
2004-08-05 12:00:00 72,458 --sh--r C:\WINDOWS\system32\rdsruns.exe
2004-08-05 12:00:00 51,650 --sh--r C:\WINDOWS\system32\xmlemppt.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6247682A-C262-4371-A5D7-BF3BCE550B11}]
C:\WINDOWS\system32\mljji.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A2191984-2E78-4444-834E-B89669BAAD92}]
C:\WINDOWS\system32\geedc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F01277D0-7EB3-456F-9D37-EE6B69B8BE3C}]
C:\WINDOWS\system32\pmnno.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2}]
C:\WINDOWS\system32\vtsqo.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 11:22 C:\WINDOWS\system32\nvmctray.dll]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 16:00]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-03-21 02:34]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-07-19 13:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winmqx32]
winmqx32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{075e67eb-2303-11dc-a114-000c6ebc693d}]
AutoRun\command- F:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7644764d-0205-11dc-a0da-000c6ebc693d}]
AutoRun\command- I:\autorun\autorun.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-21 14:18:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-21 14:19:12 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-21 14:18
--- E O F ---
et le rapport HIJACKTHIS :
Logfile of HijackThis v1.99.1
Scan saved at 14:20:09, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
"kirchener" - 2007-07-21 14:12:40 - ComboFix 07-07-14.6 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\mljgeda.dll
C:\WINDOWS\system32\mljgeda.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\epkoihuu.exe
C:\WINDOWS\system32\gdpffmit.exe
C:\WINDOWS\system32\gdxxnhvh.exe
C:\WINDOWS\system32\gtamptst.exe
C:\WINDOWS\system32\kkbdyiuw.exe
C:\WINDOWS\system32\ohxykqvu.exe
C:\WINDOWS\system32\pdyevlum.exe
C:\WINDOWS\system32\tjmmnwey.exe
C:\WINDOWS\system32\uhngjver.exe
C:\WINDOWS\system32\vgyfmpdl.exe
C:\WINDOWS\system32\W007T32W.DLL
C:\WINDOWS\system32\wgpyrpjw.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-21 to 2007-07-21 )))))))))))))))))))))))))))))))
2007-07-21 14:12 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-21 13:49 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
2007-07-19 14:08 138,368 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-07-19 13:23 <REP> d-------- C:\Program Files\Spyware Terminator
2007-07-19 13:23 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\Spyware Terminator
2007-07-19 13:23 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spyware Terminator
2007-07-18 20:22 <REP> d-------- C:\Program Files\Micro Application
2007-07-18 16:30 <REP> d-------- C:\Program Files\Lavasoft
2007-07-18 16:30 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-18 10:15 <REP> d-------- C:\Program Files\ThinkNet
2007-07-14 18:38 <REP> d-------- C:\VundoFix Backups
2007-07-12 14:26 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\ScanSoft
2007-07-12 14:19 <REP> d-------- C:\Program Files\Fichiers communs\Scansoft Shared
2007-07-12 14:19 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
2007-07-12 14:18 <REP> d-------- C:\Program Files\ScanSoft
2007-07-12 14:17 <REP> d-------- C:\WINDOWS\speech
2007-07-12 10:32 <REP> d-------- C:\Program Files\CDisplay
2007-07-11 14:29 <REP> d-------- C:\Program Files\Combined Community Codec Pack
2007-07-02 21:27 <REP> d-------- C:\Program Files\Artefacts Studio
2007-06-30 18:11 1,726 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-30 17:16 6,108 --a------ C:\dnsbak.reg
2007-06-30 16:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-29 20:30 <REP> d-------- C:\Program Files\a-squared Free
2007-06-27 11:59 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\ItsLabel
2007-06-27 11:58 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\EoRezo
2007-06-22 18:25 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-06-22 18:25 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-06-22 18:25 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-06-22 18:25 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-06-22 18:24 <REP> d-------- C:\WINDOWS\system32\AGEIA
2007-06-22 18:24 <REP> d-------- C:\Program Files\AGEIA Technologies
2007-06-22 18:18 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\dp3d
2007-06-22 18:17 <REP> d-------- C:\Program Files\Two Worlds Pinball
2007-06-22 18:11 <REP> d-------- C:\Program Files\Reality Pump
2007-06-21 13:15 <REP> d-------- C:\DOCUME~1\KIRCHE~1\APPLIC~1\SystemRequirementsLab
2007-06-21 10:17 <REP> d-------- C:\Program Files\Mindscape
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-21 12:09:47 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\Azureus
2007-07-21 11:49:34 -------- d-----w C:\Program Files\Hijackthis Version Française
2007-07-19 16:10:23 -------- d-----w C:\Program Files\World of Warcraft
2007-07-19 11:07:36 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\OpenOffice.org2
2007-07-18 18:21:59 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-18 14:30:19 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\Lavasoft
2007-07-18 14:29:13 -------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-07-12 16:49:14 541,290 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-07-12 16:49:13 90,974 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-07-12 15:56:38 -------- d-----w C:\Program Files\MatroskaProp
2007-07-11 10:36:09 -------- d-----w C:\Program Files\Matroska Pack
2007-07-06 08:47:11 -------- d-----w C:\Program Files\MSN Messenger
2007-07-05 15:44:00 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2007-06-22 09:14:21 -------- d-----w C:\Program Files\Azureus
2007-06-20 13:49:40 -------- d-----w C:\Program Files\WowCartographe
2007-06-18 09:12:52 -------- d-----w C:\Program Files\Fichiers communs\Cheewoo
2007-06-18 09:12:31 -------- d-----w C:\Program Files\Cheewoo
2007-06-16 11:42:03 51,650 ----a-w C:\WINDOWS\htrefreghreger.exe
2007-06-14 19:37:10 -------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2007-06-14 13:50:55 71,625 ----a-w C:\WINDOWS\twesdwdewewd.exe
2007-06-14 13:26:50 1,156 ----a-w C:\WINDOWS\mozver.dat
2007-06-14 13:08:39 -------- d-----w C:\Program Files\Sygate
2007-06-14 10:04:46 0 ----a-w C:\WINDOWS\nsreg.dat
2007-06-09 09:57:14 -------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2007-06-09 09:17:16 -------- d-----w C:\Program Files\MSXML 4.0
2007-06-08 16:37:28 -------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-06-05 09:29:22 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\Gearbox Software
2007-06-04 13:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 13:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 13:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-04 06:40:02 -------- d--h--r C:\DOCUME~1\KIRCHE~1\APPLIC~1\SecuROM
2007-06-04 06:40:00 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-06-01 08:50:32 -------- d-----w C:\Program Files\DivX
2007-05-31 11:31:27 -------- d-----w C:\Program Files\Fichiers communs\DirectX
2007-05-31 06:45:07 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-31 06:44:55 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-31 06:44:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-31 06:44:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-31 06:44:54 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-05-29 10:20:33 -------- d-----w C:\Program Files\Canon
2007-05-28 08:06:07 -------- d-----w C:\Program Files\directx
2007-05-27 10:44:28 -------- d-----w C:\DOCUME~1\KIRCHE~1\APPLIC~1\InstallShield
2007-05-22 09:21:45 -------- d-----w C:\Program Files\CONEXANT
2007-05-16 15:13:53 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-07 11:59:32 2,553 ----a-w C:\WINDOWS\system32\sdbackup.reg
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-04-25 14:22:35 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-23 00:15:29 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-04-23 00:15:18 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-04-23 00:15:18 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-04-23 00:02:34 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-04-23 00:02:34 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-04-23 00:02:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-04-23 00:02:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-04-23 00:02:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-04-23 00:02:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-04-23 00:02:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-04-23 00:01:47 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-23 00:01:46 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2004-08-05 12:00:00 87,057 --sh--r C:\WINDOWS\system32\comyobap.exe
2004-08-05 12:00:00 75,017 --sh--r C:\WINDOWS\system32\edconss.exe
2004-08-05 12:00:00 70,376 --sh--r C:\WINDOWS\system32\escsn.exe
2004-08-05 12:00:00 71,625 --sh--r C:\WINDOWS\system32\ikern32.exe
2004-08-05 12:00:00 72,458 --sh--r C:\WINDOWS\system32\rdsruns.exe
2004-08-05 12:00:00 51,650 --sh--r C:\WINDOWS\system32\xmlemppt.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-10-22 23:08 62080 --a------ C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6247682A-C262-4371-A5D7-BF3BCE550B11}]
C:\WINDOWS\system32\mljji.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A2191984-2E78-4444-834E-B89669BAAD92}]
C:\WINDOWS\system32\geedc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F01277D0-7EB3-456F-9D37-EE6B69B8BE3C}]
C:\WINDOWS\system32\pmnno.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2}]
C:\WINDOWS\system32\vtsqo.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 11:22 C:\WINDOWS\system32\nvmctray.dll]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-29 16:00]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-03-21 02:34]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-07-19 13:28]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winmqx32]
winmqx32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{075e67eb-2303-11dc-a114-000c6ebc693d}]
AutoRun\command- F:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7644764d-0205-11dc-a0da-000c6ebc693d}]
AutoRun\command- I:\autorun\autorun.exe
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-21 14:18:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-21 14:19:12 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-21 14:18
--- E O F ---
et le rapport HIJACKTHIS :
Logfile of HijackThis v1.99.1
Scan saved at 14:20:09, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
21 juil. 2007 à 15:14
21 juil. 2007 à 15:14
ok
As tu le rapport de Vundofix?
A quel moment as tu fais Combofix, avant ou apres Vundofix?
A+
As tu le rapport de Vundofix?
A quel moment as tu fais Combofix, avant ou apres Vundofix?
A+
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
21 juil. 2007 à 15:21
21 juil. 2007 à 15:21
voila le rapport VUNDOFIX j sais pas pourquoi j l'ai bien executé avant combo comme demandé
VundoFix V6.5.4
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 18:38:21 14/07/2007
Listing files found while scanning....
C:\windows\system32\awtrrpm.dll
C:\windows\system32\efcbbcy.dll
C:\windows\system32\gpskdwix.dll
C:\windows\system32\hbpcmtsy.dll
C:\WINDOWS\system32\hvtbewfq.dll
C:\windows\system32\nnnmkhe.dll
C:\WINDOWS\system32\nxsqhnvu.dll
C:\windows\system32\opnmmmk.dll
C:\WINDOWS\system32\oqstv.bak1
C:\WINDOWS\system32\oqstv.bak2
C:\WINDOWS\system32\oqstv.ini
C:\WINDOWS\system32\oqstv.ini2
C:\WINDOWS\system32\oqstv.tmp
C:\windows\system32\uvnhqsxn.ini
C:\WINDOWS\system32\vtsqo.dll
C:\windows\system32\xiwdkspg.ini
C:\windows\system32\ystmcpbh.ini
Beginning removal...
Attempting to delete C:\windows\system32\awtrrpm.dll
C:\windows\system32\awtrrpm.dll Has been deleted!
Attempting to delete C:\windows\system32\efcbbcy.dll
C:\windows\system32\efcbbcy.dll Has been deleted!
Attempting to delete C:\windows\system32\gpskdwix.dll
C:\windows\system32\gpskdwix.dll Has been deleted!
Attempting to delete C:\windows\system32\hbpcmtsy.dll
C:\windows\system32\hbpcmtsy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hvtbewfq.dll
C:\WINDOWS\system32\hvtbewfq.dll Has been deleted!
Attempting to delete C:\windows\system32\nnnmkhe.dll
C:\windows\system32\nnnmkhe.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\nxsqhnvu.dll
C:\WINDOWS\system32\nxsqhnvu.dll Has been deleted!
Attempting to delete C:\windows\system32\opnmmmk.dll
C:\windows\system32\opnmmmk.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.bak1
C:\WINDOWS\system32\oqstv.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.bak2
C:\WINDOWS\system32\oqstv.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.ini
C:\WINDOWS\system32\oqstv.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.ini2
C:\WINDOWS\system32\oqstv.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.tmp
C:\WINDOWS\system32\oqstv.tmp Has been deleted!
Attempting to delete C:\windows\system32\uvnhqsxn.ini
C:\windows\system32\uvnhqsxn.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtsqo.dll
C:\WINDOWS\system32\vtsqo.dll Has been deleted!
Attempting to delete C:\windows\system32\xiwdkspg.ini
C:\windows\system32\xiwdkspg.ini Has been deleted!
Attempting to delete C:\windows\system32\ystmcpbh.ini
C:\windows\system32\ystmcpbh.ini Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.4
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 18:48:28 14/07/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.5.4
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 19:14:20 14/07/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 11:59:25 19/07/2007
Listing files found while scanning....
C:\windows\system32\bifolouo.dll
C:\WINDOWS\system32\efcbbcy.dll
C:\windows\system32\eyudnyyi.dll
C:\windows\system32\ircxfter.ini
C:\windows\system32\kcxkvlmn.dll
C:\windows\system32\lcwpikrf.dll
C:\windows\system32\mahhbdvb.dll
C:\windows\system32\mhcybact.dll
C:\windows\system32\nibcshmq.dll
C:\WINDOWS\system32\onnmp.bak1
C:\WINDOWS\system32\onnmp.bak2
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.tmp
C:\WINDOWS\system32\ouolofib.ini
C:\WINDOWS\system32\pmnno.dll
C:\windows\system32\qmxhabmy.ini
C:\WINDOWS\system32\qupxuenn.dll
C:\windows\system32\retfxcri.dll
C:\windows\system32\uaoonnmu.ini
C:\windows\system32\uayxnsvt.dll
C:\windows\system32\umnnooau.dll
C:\windows\system32\vngthdqw.dll
C:\windows\system32\wqdhtgnv.ini
C:\windows\system32\ymbahxmq.dll
Beginning removal...
Attempting to delete C:\windows\system32\bifolouo.dll
C:\windows\system32\bifolouo.dll Could not be deleted.
Attempting to delete C:\windows\system32\eyudnyyi.dll
C:\windows\system32\eyudnyyi.dll Has been deleted!
Attempting to delete C:\windows\system32\ircxfter.ini
C:\windows\system32\ircxfter.ini Has been deleted!
Attempting to delete C:\windows\system32\kcxkvlmn.dll
C:\windows\system32\kcxkvlmn.dll Has been deleted!
Attempting to delete C:\windows\system32\lcwpikrf.dll
C:\windows\system32\lcwpikrf.dll Has been deleted!
Attempting to delete C:\windows\system32\mahhbdvb.dll
C:\windows\system32\mahhbdvb.dll Has been deleted!
Attempting to delete C:\windows\system32\mhcybact.dll
C:\windows\system32\mhcybact.dll Has been deleted!
Attempting to delete C:\windows\system32\nibcshmq.dll
C:\windows\system32\nibcshmq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.bak1
C:\WINDOWS\system32\onnmp.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.bak2
C:\WINDOWS\system32\onnmp.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.tmp
C:\WINDOWS\system32\onnmp.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\ouolofib.ini
C:\WINDOWS\system32\ouolofib.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\pmnno.dll Has been deleted!
Attempting to delete C:\windows\system32\qmxhabmy.ini
C:\windows\system32\qmxhabmy.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\qupxuenn.dll
C:\WINDOWS\system32\qupxuenn.dll Has been deleted!
Attempting to delete C:\windows\system32\retfxcri.dll
C:\windows\system32\retfxcri.dll Has been deleted!
Attempting to delete C:\windows\system32\uaoonnmu.ini
C:\windows\system32\uaoonnmu.ini Has been deleted!
Attempting to delete C:\windows\system32\uayxnsvt.dll
C:\windows\system32\uayxnsvt.dll Has been deleted!
Attempting to delete C:\windows\system32\umnnooau.dll
C:\windows\system32\umnnooau.dll Has been deleted!
Attempting to delete C:\windows\system32\vngthdqw.dll
C:\windows\system32\vngthdqw.dll Has been deleted!
Attempting to delete C:\windows\system32\wqdhtgnv.ini
C:\windows\system32\wqdhtgnv.ini Has been deleted!
Attempting to delete C:\windows\system32\ymbahxmq.dll
C:\windows\system32\ymbahxmq.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 12:06:08 19/07/2007
Listing files found while scanning....
C:\windows\system32\bifolouo.dll
Beginning removal...
Attempting to delete C:\windows\system32\bifolouo.dll
C:\windows\system32\bifolouo.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 12:11:57 19/07/2007
Listing files found while scanning....
C:\WINDOWS\system32\ijjlm.bak1
C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\mljji.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ijjlm.bak1
C:\WINDOWS\system32\ijjlm.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\ijjlm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\mljji.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\mljji.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 14:06:39 21/07/2007
Listing files found while scanning....
C:\WINDOWS\system32\cdeeg.bak1
C:\WINDOWS\system32\cdeeg.bak2
C:\WINDOWS\system32\cdeeg.ini
C:\WINDOWS\system32\cdeeg.ini2
C:\WINDOWS\system32\cdeeg.tmp
C:\windows\system32\cgdrjfcy.dll
C:\windows\system32\cpkhacjv.dll
C:\windows\system32\flmwdnvs.dll
C:\windows\system32\fpfvjwbl.dll
C:\WINDOWS\system32\geedc.dll
C:\windows\system32\jjorfoqe.dll
C:\windows\system32\rbyimaid.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\cdeeg.bak1
C:\WINDOWS\system32\cdeeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.bak2
C:\WINDOWS\system32\cdeeg.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.ini
C:\WINDOWS\system32\cdeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.ini2
C:\WINDOWS\system32\cdeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.tmp
C:\WINDOWS\system32\cdeeg.tmp Has been deleted!
Attempting to delete C:\windows\system32\cgdrjfcy.dll
C:\windows\system32\cgdrjfcy.dll Has been deleted!
Attempting to delete C:\windows\system32\cpkhacjv.dll
C:\windows\system32\cpkhacjv.dll Has been deleted!
Attempting to delete C:\windows\system32\flmwdnvs.dll
C:\windows\system32\flmwdnvs.dll Has been deleted!
Attempting to delete C:\windows\system32\fpfvjwbl.dll
C:\windows\system32\fpfvjwbl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\geedc.dll
C:\WINDOWS\system32\geedc.dll Has been deleted!
Attempting to delete C:\windows\system32\jjorfoqe.dll
C:\windows\system32\jjorfoqe.dll Has been deleted!
Attempting to delete C:\windows\system32\rbyimaid.dll
C:\windows\system32\rbyimaid.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.4
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 18:38:21 14/07/2007
Listing files found while scanning....
C:\windows\system32\awtrrpm.dll
C:\windows\system32\efcbbcy.dll
C:\windows\system32\gpskdwix.dll
C:\windows\system32\hbpcmtsy.dll
C:\WINDOWS\system32\hvtbewfq.dll
C:\windows\system32\nnnmkhe.dll
C:\WINDOWS\system32\nxsqhnvu.dll
C:\windows\system32\opnmmmk.dll
C:\WINDOWS\system32\oqstv.bak1
C:\WINDOWS\system32\oqstv.bak2
C:\WINDOWS\system32\oqstv.ini
C:\WINDOWS\system32\oqstv.ini2
C:\WINDOWS\system32\oqstv.tmp
C:\windows\system32\uvnhqsxn.ini
C:\WINDOWS\system32\vtsqo.dll
C:\windows\system32\xiwdkspg.ini
C:\windows\system32\ystmcpbh.ini
Beginning removal...
Attempting to delete C:\windows\system32\awtrrpm.dll
C:\windows\system32\awtrrpm.dll Has been deleted!
Attempting to delete C:\windows\system32\efcbbcy.dll
C:\windows\system32\efcbbcy.dll Has been deleted!
Attempting to delete C:\windows\system32\gpskdwix.dll
C:\windows\system32\gpskdwix.dll Has been deleted!
Attempting to delete C:\windows\system32\hbpcmtsy.dll
C:\windows\system32\hbpcmtsy.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hvtbewfq.dll
C:\WINDOWS\system32\hvtbewfq.dll Has been deleted!
Attempting to delete C:\windows\system32\nnnmkhe.dll
C:\windows\system32\nnnmkhe.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\nxsqhnvu.dll
C:\WINDOWS\system32\nxsqhnvu.dll Has been deleted!
Attempting to delete C:\windows\system32\opnmmmk.dll
C:\windows\system32\opnmmmk.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.bak1
C:\WINDOWS\system32\oqstv.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.bak2
C:\WINDOWS\system32\oqstv.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.ini
C:\WINDOWS\system32\oqstv.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.ini2
C:\WINDOWS\system32\oqstv.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\oqstv.tmp
C:\WINDOWS\system32\oqstv.tmp Has been deleted!
Attempting to delete C:\windows\system32\uvnhqsxn.ini
C:\windows\system32\uvnhqsxn.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\vtsqo.dll
C:\WINDOWS\system32\vtsqo.dll Has been deleted!
Attempting to delete C:\windows\system32\xiwdkspg.ini
C:\windows\system32\xiwdkspg.ini Has been deleted!
Attempting to delete C:\windows\system32\ystmcpbh.ini
C:\windows\system32\ystmcpbh.ini Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.4
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 18:48:28 14/07/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.5.4
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 19:14:20 14/07/2007
Listing files found while scanning....
No infected files were found.
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 11:59:25 19/07/2007
Listing files found while scanning....
C:\windows\system32\bifolouo.dll
C:\WINDOWS\system32\efcbbcy.dll
C:\windows\system32\eyudnyyi.dll
C:\windows\system32\ircxfter.ini
C:\windows\system32\kcxkvlmn.dll
C:\windows\system32\lcwpikrf.dll
C:\windows\system32\mahhbdvb.dll
C:\windows\system32\mhcybact.dll
C:\windows\system32\nibcshmq.dll
C:\WINDOWS\system32\onnmp.bak1
C:\WINDOWS\system32\onnmp.bak2
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.tmp
C:\WINDOWS\system32\ouolofib.ini
C:\WINDOWS\system32\pmnno.dll
C:\windows\system32\qmxhabmy.ini
C:\WINDOWS\system32\qupxuenn.dll
C:\windows\system32\retfxcri.dll
C:\windows\system32\uaoonnmu.ini
C:\windows\system32\uayxnsvt.dll
C:\windows\system32\umnnooau.dll
C:\windows\system32\vngthdqw.dll
C:\windows\system32\wqdhtgnv.ini
C:\windows\system32\ymbahxmq.dll
Beginning removal...
Attempting to delete C:\windows\system32\bifolouo.dll
C:\windows\system32\bifolouo.dll Could not be deleted.
Attempting to delete C:\windows\system32\eyudnyyi.dll
C:\windows\system32\eyudnyyi.dll Has been deleted!
Attempting to delete C:\windows\system32\ircxfter.ini
C:\windows\system32\ircxfter.ini Has been deleted!
Attempting to delete C:\windows\system32\kcxkvlmn.dll
C:\windows\system32\kcxkvlmn.dll Has been deleted!
Attempting to delete C:\windows\system32\lcwpikrf.dll
C:\windows\system32\lcwpikrf.dll Has been deleted!
Attempting to delete C:\windows\system32\mahhbdvb.dll
C:\windows\system32\mahhbdvb.dll Has been deleted!
Attempting to delete C:\windows\system32\mhcybact.dll
C:\windows\system32\mhcybact.dll Has been deleted!
Attempting to delete C:\windows\system32\nibcshmq.dll
C:\windows\system32\nibcshmq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.bak1
C:\WINDOWS\system32\onnmp.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.bak2
C:\WINDOWS\system32\onnmp.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\onnmp.tmp
C:\WINDOWS\system32\onnmp.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\ouolofib.ini
C:\WINDOWS\system32\ouolofib.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmnno.dll
C:\WINDOWS\system32\pmnno.dll Has been deleted!
Attempting to delete C:\windows\system32\qmxhabmy.ini
C:\windows\system32\qmxhabmy.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\qupxuenn.dll
C:\WINDOWS\system32\qupxuenn.dll Has been deleted!
Attempting to delete C:\windows\system32\retfxcri.dll
C:\windows\system32\retfxcri.dll Has been deleted!
Attempting to delete C:\windows\system32\uaoonnmu.ini
C:\windows\system32\uaoonnmu.ini Has been deleted!
Attempting to delete C:\windows\system32\uayxnsvt.dll
C:\windows\system32\uayxnsvt.dll Has been deleted!
Attempting to delete C:\windows\system32\umnnooau.dll
C:\windows\system32\umnnooau.dll Has been deleted!
Attempting to delete C:\windows\system32\vngthdqw.dll
C:\windows\system32\vngthdqw.dll Has been deleted!
Attempting to delete C:\windows\system32\wqdhtgnv.ini
C:\windows\system32\wqdhtgnv.ini Has been deleted!
Attempting to delete C:\windows\system32\ymbahxmq.dll
C:\windows\system32\ymbahxmq.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 12:06:08 19/07/2007
Listing files found while scanning....
C:\windows\system32\bifolouo.dll
Beginning removal...
Attempting to delete C:\windows\system32\bifolouo.dll
C:\windows\system32\bifolouo.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 12:11:57 19/07/2007
Listing files found while scanning....
C:\WINDOWS\system32\ijjlm.bak1
C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\mljji.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ijjlm.bak1
C:\WINDOWS\system32\ijjlm.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ijjlm.ini
C:\WINDOWS\system32\ijjlm.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\mljji.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\mljji.dll
C:\WINDOWS\system32\mljji.dll Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 14:06:39 21/07/2007
Listing files found while scanning....
C:\WINDOWS\system32\cdeeg.bak1
C:\WINDOWS\system32\cdeeg.bak2
C:\WINDOWS\system32\cdeeg.ini
C:\WINDOWS\system32\cdeeg.ini2
C:\WINDOWS\system32\cdeeg.tmp
C:\windows\system32\cgdrjfcy.dll
C:\windows\system32\cpkhacjv.dll
C:\windows\system32\flmwdnvs.dll
C:\windows\system32\fpfvjwbl.dll
C:\WINDOWS\system32\geedc.dll
C:\windows\system32\jjorfoqe.dll
C:\windows\system32\rbyimaid.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\cdeeg.bak1
C:\WINDOWS\system32\cdeeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.bak2
C:\WINDOWS\system32\cdeeg.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.ini
C:\WINDOWS\system32\cdeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.ini2
C:\WINDOWS\system32\cdeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\cdeeg.tmp
C:\WINDOWS\system32\cdeeg.tmp Has been deleted!
Attempting to delete C:\windows\system32\cgdrjfcy.dll
C:\windows\system32\cgdrjfcy.dll Has been deleted!
Attempting to delete C:\windows\system32\cpkhacjv.dll
C:\windows\system32\cpkhacjv.dll Has been deleted!
Attempting to delete C:\windows\system32\flmwdnvs.dll
C:\windows\system32\flmwdnvs.dll Has been deleted!
Attempting to delete C:\windows\system32\fpfvjwbl.dll
C:\windows\system32\fpfvjwbl.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\geedc.dll
C:\WINDOWS\system32\geedc.dll Has been deleted!
Attempting to delete C:\windows\system32\jjorfoqe.dll
C:\windows\system32\jjorfoqe.dll Has been deleted!
Attempting to delete C:\windows\system32\rbyimaid.dll
C:\windows\system32\rbyimaid.dll Has been deleted!
Performing Repairs to the registry.
Done!
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
21 juil. 2007 à 15:33
21 juil. 2007 à 15:33
Re,
Télécharge OTMoveIt
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\mljgeda.dll
C:\WINDOWS\system32\mljgeda.dll
C:\WINDOWS\system32\epkoihuu.exe
C:\WINDOWS\system32\gdpffmit.exe
C:\WINDOWS\system32\gdxxnhvh.exe
C:\WINDOWS\system32\gtamptst.exe
C:\WINDOWS\system32\kkbdyiuw.exe
C:\WINDOWS\system32\ohxykqvu.exe
C:\WINDOWS\system32\pdyevlum.exe
C:\WINDOWS\system32\tjmmnwey.exe
C:\WINDOWS\system32\uhngjver.exe
C:\WINDOWS\system32\vgyfmpdl.exe
C:\WINDOWS\system32\wgpyrpjw.exe
C:\WINDOWS\htrefreghreger.exe
C:\WINDOWS\twesdwdewewd.exe
Clique sur MoveIt! pour lancer la suppression.
Le résultat apparaitra dans le cadre Results.
Clique sur Exit pour fermer.
Il te sera peut-être demander de redémarrer le PC pour achever la suppression. Si c'est le cas accepte par Yes.
Poste le rapport situé dans C:\\_OTMoveIt\MovedFiles avec un nouveau HijackThis.
Rajoute un rapport Combofix car il en restera a supprimer...
A+
Télécharge OTMoveIt
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\fcccawu.dll
C:\WINDOWS\system32\gebbaab.dll
C:\WINDOWS\system32\urqppmn.dll
C:\WINDOWS\system32\vtutqpn.dll
C:\WINDOWS\system32\mljgeda.dll
C:\WINDOWS\system32\mljgeda.dll
C:\WINDOWS\system32\epkoihuu.exe
C:\WINDOWS\system32\gdpffmit.exe
C:\WINDOWS\system32\gdxxnhvh.exe
C:\WINDOWS\system32\gtamptst.exe
C:\WINDOWS\system32\kkbdyiuw.exe
C:\WINDOWS\system32\ohxykqvu.exe
C:\WINDOWS\system32\pdyevlum.exe
C:\WINDOWS\system32\tjmmnwey.exe
C:\WINDOWS\system32\uhngjver.exe
C:\WINDOWS\system32\vgyfmpdl.exe
C:\WINDOWS\system32\wgpyrpjw.exe
C:\WINDOWS\htrefreghreger.exe
C:\WINDOWS\twesdwdewewd.exe
Clique sur MoveIt! pour lancer la suppression.
Le résultat apparaitra dans le cadre Results.
Clique sur Exit pour fermer.
Il te sera peut-être demander de redémarrer le PC pour achever la suppression. Si c'est le cas accepte par Yes.
Poste le rapport situé dans C:\\_OTMoveIt\MovedFiles avec un nouveau HijackThis.
Rajoute un rapport Combofix car il en restera a supprimer...
A+
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
21 juil. 2007 à 15:46
21 juil. 2007 à 15:46
voila pour OTMOVIT
File/Folder C:\WINDOWS\system32\fcccawu.dll not found.
File/Folder C:\WINDOWS\system32\gebbaab.dll not found.
File/Folder C:\WINDOWS\system32\urqppmn.dll not found.
File/Folder C:\WINDOWS\system32\vtutqpn.dll not found.
File/Folder C:\WINDOWS\system32\fcccawu.dll not found.
File/Folder C:\WINDOWS\system32\gebbaab.dll not found.
File/Folder C:\WINDOWS\system32\urqppmn.dll not found.
File/Folder C:\WINDOWS\system32\vtutqpn.dll not found.
File/Folder C:\WINDOWS\system32\mljgeda.dll not found.
File/Folder C:\WINDOWS\system32\mljgeda.dll not found.
File/Folder C:\WINDOWS\system32\epkoihuu.exe not found.
File/Folder C:\WINDOWS\system32\gdpffmit.exe not found.
File/Folder C:\WINDOWS\system32\gdxxnhvh.exe not found.
File/Folder C:\WINDOWS\system32\gtamptst.exe not found.
File/Folder C:\WINDOWS\system32\kkbdyiuw.exe not found.
File/Folder C:\WINDOWS\system32\ohxykqvu.exe not found.
File/Folder C:\WINDOWS\system32\pdyevlum.exe not found.
File/Folder C:\WINDOWS\system32\tjmmnwey.exe not found.
File/Folder C:\WINDOWS\system32\uhngjver.exe not found.
File/Folder C:\WINDOWS\system32\vgyfmpdl.exe not found.
File/Folder C:\WINDOWS\system32\wgpyrpjw.exe not found.
C:\WINDOWS\htrefreghreger.exe moved successfully.
C:\WINDOWS\twesdwdewewd.exe moved successfully.
Created on 07/21/2007 15:43:13
et voila pour HIJACKTHIS :
Logfile of HijackThis v1.99.1
Scan saved at 15:46:08, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\kirchener\Bureau\OTMoveIt.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
File/Folder C:\WINDOWS\system32\fcccawu.dll not found.
File/Folder C:\WINDOWS\system32\gebbaab.dll not found.
File/Folder C:\WINDOWS\system32\urqppmn.dll not found.
File/Folder C:\WINDOWS\system32\vtutqpn.dll not found.
File/Folder C:\WINDOWS\system32\fcccawu.dll not found.
File/Folder C:\WINDOWS\system32\gebbaab.dll not found.
File/Folder C:\WINDOWS\system32\urqppmn.dll not found.
File/Folder C:\WINDOWS\system32\vtutqpn.dll not found.
File/Folder C:\WINDOWS\system32\mljgeda.dll not found.
File/Folder C:\WINDOWS\system32\mljgeda.dll not found.
File/Folder C:\WINDOWS\system32\epkoihuu.exe not found.
File/Folder C:\WINDOWS\system32\gdpffmit.exe not found.
File/Folder C:\WINDOWS\system32\gdxxnhvh.exe not found.
File/Folder C:\WINDOWS\system32\gtamptst.exe not found.
File/Folder C:\WINDOWS\system32\kkbdyiuw.exe not found.
File/Folder C:\WINDOWS\system32\ohxykqvu.exe not found.
File/Folder C:\WINDOWS\system32\pdyevlum.exe not found.
File/Folder C:\WINDOWS\system32\tjmmnwey.exe not found.
File/Folder C:\WINDOWS\system32\uhngjver.exe not found.
File/Folder C:\WINDOWS\system32\vgyfmpdl.exe not found.
File/Folder C:\WINDOWS\system32\wgpyrpjw.exe not found.
C:\WINDOWS\htrefreghreger.exe moved successfully.
C:\WINDOWS\twesdwdewewd.exe moved successfully.
Created on 07/21/2007 15:43:13
et voila pour HIJACKTHIS :
Logfile of HijackThis v1.99.1
Scan saved at 15:46:08, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\kirchener\Bureau\OTMoveIt.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
Regis59
Messages postés
21143
Date d'inscription
mardi 27 juin 2006
Statut
Contributeur sécurité
Dernière intervention
22 juin 2016
1 321
21 juil. 2007 à 16:02
21 juil. 2007 à 16:02
Ok.
¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
Ferme HijackThis.
Redemarre ton PC et remet moi un nouveau Hijackthis et un nouveau combofix stp
A+
¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :
O2 - BHO: (no name) - {6247682A-C262-4371-A5D7-BF3BCE550B11} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A2191984-2E78-4444-834E-B89669BAAD92} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: (no name) - {F01277D0-7EB3-456F-9D37-EE6B69B8BE3C} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {F8A9BE2A-4DBF-4630-9ED3-8E4147DDC8C2} - C:\WINDOWS\system32\vtsqo.dll (file missing)
O20 - Winlogon Notify: winmqx32 - winmqx32.dll (file missing)
Ferme HijackThis.
Redemarre ton PC et remet moi un nouveau Hijackthis et un nouveau combofix stp
A+
kirchener
Messages postés
33
Date d'inscription
jeudi 19 juillet 2007
Statut
Membre
Dernière intervention
7 août 2008
21 juil. 2007 à 16:09
21 juil. 2007 à 16:09
j'met deja le rapporrt HIJACKTHIS et je m occupe de COMBOFIX de suite
Logfile of HijackThis v1.99.1
Scan saved at 16:07:09, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
Logfile of HijackThis v1.99.1
Scan saved at 16:07:09, on 21/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe