J'ai un malware nommé cyberlog x hlep
Résolu
wolfas13
Messages postés
60
Statut
Membre
-
wolfas13 Messages postés 60 Statut Membre -
wolfas13 Messages postés 60 Statut Membre -
Bonjour,
je ce malware qui me gene enormement g intsallesmitfraudfix et j'ai chhoisit l'option 1 . je vous poste le raport dites moi ce qu'il fo faire pls!!
SmitFraudFix v2.250
Rapport fait à 20:30:07,35, 06/11/2007
Executé à partir de C:\Documents and Settings\nicolas\Bureau\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\STK017_V2.01\STK017M.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\nicolas
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\nicolas\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\nicolas\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=dword:00000001
"AppInit_DLLs"="C:\\WINDOWS\\system32\\__c0020400.dat"
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: ATMEL USB FastVNET (AR) - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{7636EF0F-96FF-47E5-A7BE-1B10E717B0E1}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{7636EF0F-96FF-47E5-A7BE-1B10E717B0E1}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{7636EF0F-96FF-47E5-A7BE-1B10E717B0E1}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
je ce malware qui me gene enormement g intsallesmitfraudfix et j'ai chhoisit l'option 1 . je vous poste le raport dites moi ce qu'il fo faire pls!!
SmitFraudFix v2.250
Rapport fait à 20:30:07,35, 06/11/2007
Executé à partir de C:\Documents and Settings\nicolas\Bureau\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\NCH Swift Sound\Recordpad\recordpad.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\STK017_V2.01\STK017M.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\nicolas
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\nicolas\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\nicolas\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=dword:00000001
"AppInit_DLLs"="C:\\WINDOWS\\system32\\__c0020400.dat"
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: ATMEL USB FastVNET (AR) - Miniport d'ordonnancement de paquets
DNS Server Search Order: 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{7636EF0F-96FF-47E5-A7BE-1B10E717B0E1}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{7636EF0F-96FF-47E5-A7BE-1B10E717B0E1}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{7636EF0F-96FF-47E5-A7BE-1B10E717B0E1}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
A voir également:
- J'ai un malware nommé cyberlog x hlep
- Site x - Guide
- Sites X : Pornhub, YouPorn et Redtube sont de nouveau accessibles en France - Guide
- Malwarebytes anti-malware - Télécharger - Antivirus & Antimalwares
- Photoscape x - Télécharger - Retouche d'image
- Direct x - Télécharger - Pilotes & Matériel
29 réponses
voila le rapport de combofix
ComboFix 07-11-08.1 - nicolas 2007-11-11 16:40:46.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1160 [GMT 1:00]
Running from: C:\Documents and Settings\nicolas\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-11 to 2007-11-11 ))))))))))))))))))))))))))))))))))))
.
2007-11-11 10:27 <REP> d-------- C:\New Folder
2007-11-11 10:27 <REP> d-------- C:\hijackthis
2007-11-11 10:07 <REP> d-------- C:\VundoFix Backups
2007-11-09 18:30 <REP> d-------- C:\Program Files\Navilog1
2007-11-07 20:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Grisoft
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-06 20:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-06 20:30 4,080 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-06 19:07 <REP> d-------- C:\Program Files\Avira
2007-11-06 19:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-06 18:49 <REP> d-------- C:\Program Files\Panda Security
2007-10-29 12:38 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\ArcSoft
2007-10-29 12:37 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2007-10-29 12:36 <REP> d-------- C:\Program Files\Hercules
2007-10-29 12:36 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2007-10-29 12:36 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-10-29 12:36 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2007-10-29 12:34 <REP> d-------- C:\WINDOWS\OvtCam
2007-10-29 12:34 161,792 --------- C:\WINDOWS\system32\drivers\ov530vid.sys
2007-10-29 12:34 61,440 --------- C:\WINDOWS\ov530dib.dll
2007-10-29 12:34 40,960 --------- C:\WINDOWS\system32\ov530ext.dll
2007-10-29 12:34 25,177 --------- C:\WINDOWS\system32\drivers\ov530cmd.sys
2007-10-29 12:34 16,440 --------- C:\WINDOWS\system32\ov530usd.dll
2007-10-29 09:57 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Recordpad
2007-10-29 09:19 589 --a------ C:\WINDOWS\system32\ehvecyts.dll
2007-10-27 16:21 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-10-27 16:21 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-10-27 16:21 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-10-27 16:21 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-10-27 16:21 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-10-27 16:21 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-10-27 16:21 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-10-27 16:17 <REP> d-------- C:\Program Files\Electronic Arts
2007-10-24 15:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-24 12:48 <REP> d-------- C:\Program Files\MediaCoder
2007-10-24 12:42 <REP> d-------- C:\Program Files\GXTranscoder.net AWE
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\AVS4YOU
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2007-10-24 10:27 <REP> d-------- C:\Program Files\Fichiers communs\AVSMedia
2007-10-24 10:25 <REP> d-------- C:\Program Files\AVS4YOU
2007-10-24 10:23 1,700,352 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-10-24 10:23 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-10-24 10:23 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2007-10-24 10:23 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2007-10-24 10:23 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-10-24 10:10 <REP> d-------- C:\Temp
2007-10-24 10:05 <REP> d-------- C:\Program Files\QuickTime
2007-10-24 10:05 <REP> d-------- C:\Program Files\ImTOO
2007-10-21 11:00 <REP> d-------- C:\Program Files\oZone3D
2007-10-20 13:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Program Files\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Program Files\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\NCH Swift Sound
2007-10-14 13:31 <REP> d-------- C:\Program Files\Winamp
2007-10-14 13:31 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Winamp
2007-10-13 17:31 <REP> d-------- C:\Program Files\GT2002
2007-10-13 11:16 <REP> d-------- C:\WINDOWS\pss
2007-10-11 20:23 <REP> d-------- C:\Program Files\WinMX
2007-10-11 19:37 <REP> d-------- C:\Program Files\WinISO
2007-10-11 18:33 <REP> d-------- C:\Program Files\Smart Projects
2007-10-11 16:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 15:36 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OpenOffice.org2
2007-11-11 11:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-11 11:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-11 09:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-07 16:33 --------- d-----w C:\Program Files\STK017_V2.01
2007-10-29 11:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-24 08:28 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia Multimedia Player
2007-10-22 19:23 --------- d-----w C:\Documents and Settings\nicolas\Application Data\DivX
2007-10-22 19:10 --------- d-----w C:\Program Files\Picasa2
2007-10-21 15:33 --------- d-----w C:\Program Files\Java
2007-10-20 10:31 --------- d-----w C:\Program Files\DeskSpace
2007-10-12 18:36 --------- d-----w C:\Program Files\Silkroad
2007-10-07 08:06 --------- d-----w C:\Program Files\Elaborate Bytes
2007-10-06 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-06 16:20 --------- d-----w C:\Program Files\SlySoft
2007-10-06 16:17 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Skype
2007-10-06 16:08 --------- d-----w C:\Program Files\DiskTrix
2007-10-06 16:03 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OtakuSoftware
2007-10-06 15:44 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Joost
2007-10-05 17:12 --------- d-----w C:\Program Files\AxBx
2007-10-04 16:09 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-04 16:09 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-04 16:09 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-04 16:09 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-04 16:09 --------- d-----w C:\Program Files\Symantec
2007-09-29 09:32 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Fichiers communs\Nokia
2007-09-23 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2007-09-21 19:41 --------- d-----w C:\Program Files\DivX
2007-09-18 12:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 12:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 12:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 12:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 12:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 12:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 12:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 12:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 12:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-16 14:21 --------- d-----w C:\Program Files\PhotoFiltre
2007-09-15 19:12 --------- d-----w C:\Program Files\eRightSoft
2007-09-13 11:54 --------- d-----w C:\Program Files\Skype
2007-09-13 11:54 --------- d-----w C:\Program Files\Fichiers communs\Skype
2007-09-13 11:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-08-15 22:33 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-18 16:40 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-08_21.06.23.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-07 11:05:19 62,016 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-11-11 09:40:15 61,632 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-11-11 15:37:29 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_288.dat
+ 2007-11-11 15:35:53 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_bb8.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{790fd541-85b9-410d-aabf-05288a74242c}]
C:\WINDOWS\system32\ybmyonaa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 17:22]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-12-06 11:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 08:29]
"nwiz"="nwiz.exe" [2006-03-09 08:29 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 08:29]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 C:\WINDOWS\soundman.exe]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-11 10:40]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-18 18:07]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"La_View Mouse"="C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe" [2006-01-04 17:32]
"DeskSpace"="C:\Program Files\DeskSpace\deskspace.exe" []
"ares"="C:\Program Files\Ares\Ares.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\nicolas\Menu D‚marrer\Programmes\D‚marrage\
Alienware Dock.lnk - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe [2007-07-01 10:24:53 nicolas]
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-01-25 18:42:22 nicolas]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-05-18 18:07:34 nicolas]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h
R2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys
R3 ATMELFVNETusb(AR)(R);ATMEL FVNETusb(AR)(R) Service for ATMEL USB FastVNET (AR);C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys
S3 SaiHFF0C;SaiHFF0C;C:\WINDOWS\system32\DRIVERS\SaiHFF0C.sys
S3 SaiUFF0C;SaiUFF0C;C:\WINDOWS\system32\DRIVERS\SaiUFF0C.sys
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINDOWS\system32\Drivers\SilvrLnk.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{634bfe42-0566-11dc-9e73-806d6172696f}]
\Shell\AutoRun\command - F:\POV.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd5ec2a8-055f-11dc-9694-0006f404143d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - G:\Boot.exe e
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 16:44:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-11 16:45:41
C:\ComboFix2.txt ... 2007-11-11 13:33
C:\ComboFix3.txt ... 2007-11-08 21:07
.
--- E O F ---
ComboFix 07-11-08.1 - nicolas 2007-11-11 16:40:46.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1160 [GMT 1:00]
Running from: C:\Documents and Settings\nicolas\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-11 to 2007-11-11 ))))))))))))))))))))))))))))))))))))
.
2007-11-11 10:27 <REP> d-------- C:\New Folder
2007-11-11 10:27 <REP> d-------- C:\hijackthis
2007-11-11 10:07 <REP> d-------- C:\VundoFix Backups
2007-11-09 18:30 <REP> d-------- C:\Program Files\Navilog1
2007-11-07 20:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Grisoft
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-06 20:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-06 20:30 4,080 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-06 19:07 <REP> d-------- C:\Program Files\Avira
2007-11-06 19:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-06 18:49 <REP> d-------- C:\Program Files\Panda Security
2007-10-29 12:38 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\ArcSoft
2007-10-29 12:37 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2007-10-29 12:36 <REP> d-------- C:\Program Files\Hercules
2007-10-29 12:36 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2007-10-29 12:36 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-10-29 12:36 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2007-10-29 12:34 <REP> d-------- C:\WINDOWS\OvtCam
2007-10-29 12:34 161,792 --------- C:\WINDOWS\system32\drivers\ov530vid.sys
2007-10-29 12:34 61,440 --------- C:\WINDOWS\ov530dib.dll
2007-10-29 12:34 40,960 --------- C:\WINDOWS\system32\ov530ext.dll
2007-10-29 12:34 25,177 --------- C:\WINDOWS\system32\drivers\ov530cmd.sys
2007-10-29 12:34 16,440 --------- C:\WINDOWS\system32\ov530usd.dll
2007-10-29 09:57 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Recordpad
2007-10-29 09:19 589 --a------ C:\WINDOWS\system32\ehvecyts.dll
2007-10-27 16:21 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-10-27 16:21 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-10-27 16:21 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-10-27 16:21 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-10-27 16:21 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-10-27 16:21 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-10-27 16:21 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-10-27 16:17 <REP> d-------- C:\Program Files\Electronic Arts
2007-10-24 15:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-24 12:48 <REP> d-------- C:\Program Files\MediaCoder
2007-10-24 12:42 <REP> d-------- C:\Program Files\GXTranscoder.net AWE
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\AVS4YOU
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2007-10-24 10:27 <REP> d-------- C:\Program Files\Fichiers communs\AVSMedia
2007-10-24 10:25 <REP> d-------- C:\Program Files\AVS4YOU
2007-10-24 10:23 1,700,352 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-10-24 10:23 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-10-24 10:23 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2007-10-24 10:23 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2007-10-24 10:23 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-10-24 10:10 <REP> d-------- C:\Temp
2007-10-24 10:05 <REP> d-------- C:\Program Files\QuickTime
2007-10-24 10:05 <REP> d-------- C:\Program Files\ImTOO
2007-10-21 11:00 <REP> d-------- C:\Program Files\oZone3D
2007-10-20 13:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Program Files\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Program Files\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\NCH Swift Sound
2007-10-14 13:31 <REP> d-------- C:\Program Files\Winamp
2007-10-14 13:31 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Winamp
2007-10-13 17:31 <REP> d-------- C:\Program Files\GT2002
2007-10-13 11:16 <REP> d-------- C:\WINDOWS\pss
2007-10-11 20:23 <REP> d-------- C:\Program Files\WinMX
2007-10-11 19:37 <REP> d-------- C:\Program Files\WinISO
2007-10-11 18:33 <REP> d-------- C:\Program Files\Smart Projects
2007-10-11 16:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-11 15:36 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OpenOffice.org2
2007-11-11 11:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-11 11:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-11 09:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-07 16:33 --------- d-----w C:\Program Files\STK017_V2.01
2007-10-29 11:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-24 08:28 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia Multimedia Player
2007-10-22 19:23 --------- d-----w C:\Documents and Settings\nicolas\Application Data\DivX
2007-10-22 19:10 --------- d-----w C:\Program Files\Picasa2
2007-10-21 15:33 --------- d-----w C:\Program Files\Java
2007-10-20 10:31 --------- d-----w C:\Program Files\DeskSpace
2007-10-12 18:36 --------- d-----w C:\Program Files\Silkroad
2007-10-07 08:06 --------- d-----w C:\Program Files\Elaborate Bytes
2007-10-06 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-06 16:20 --------- d-----w C:\Program Files\SlySoft
2007-10-06 16:17 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Skype
2007-10-06 16:08 --------- d-----w C:\Program Files\DiskTrix
2007-10-06 16:03 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OtakuSoftware
2007-10-06 15:44 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Joost
2007-10-05 17:12 --------- d-----w C:\Program Files\AxBx
2007-10-04 16:09 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-10-04 16:09 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-10-04 16:09 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-10-04 16:09 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-10-04 16:09 --------- d-----w C:\Program Files\Symantec
2007-09-29 09:32 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Fichiers communs\Nokia
2007-09-23 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2007-09-21 19:41 --------- d-----w C:\Program Files\DivX
2007-09-18 12:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 12:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 12:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 12:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 12:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 12:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 12:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 12:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 12:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-16 14:21 --------- d-----w C:\Program Files\PhotoFiltre
2007-09-15 19:12 --------- d-----w C:\Program Files\eRightSoft
2007-09-13 11:54 --------- d-----w C:\Program Files\Skype
2007-09-13 11:54 --------- d-----w C:\Program Files\Fichiers communs\Skype
2007-09-13 11:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-08-15 22:33 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-18 16:40 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-08_21.06.23.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-07 11:05:19 62,016 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-11-11 09:40:15 61,632 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-11-11 15:37:29 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_288.dat
+ 2007-11-11 15:35:53 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_bb8.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{790fd541-85b9-410d-aabf-05288a74242c}]
C:\WINDOWS\system32\ybmyonaa.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 17:22]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-12-06 11:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 08:29]
"nwiz"="nwiz.exe" [2006-03-09 08:29 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 08:29]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 C:\WINDOWS\soundman.exe]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-11 10:40]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-18 18:07]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"La_View Mouse"="C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe" [2006-01-04 17:32]
"DeskSpace"="C:\Program Files\DeskSpace\deskspace.exe" []
"ares"="C:\Program Files\Ares\Ares.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\nicolas\Menu D‚marrer\Programmes\D‚marrage\
Alienware Dock.lnk - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe [2007-07-01 10:24:53 nicolas]
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-01-25 18:42:22 nicolas]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-05-18 18:07:34 nicolas]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h
R2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys
R3 ATMELFVNETusb(AR)(R);ATMEL FVNETusb(AR)(R) Service for ATMEL USB FastVNET (AR);C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys
S3 SaiHFF0C;SaiHFF0C;C:\WINDOWS\system32\DRIVERS\SaiHFF0C.sys
S3 SaiUFF0C;SaiUFF0C;C:\WINDOWS\system32\DRIVERS\SaiUFF0C.sys
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINDOWS\system32\Drivers\SilvrLnk.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{634bfe42-0566-11dc-9e73-806d6172696f}]
\Shell\AutoRun\command - F:\POV.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd5ec2a8-055f-11dc-9694-0006f404143d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - G:\Boot.exe e
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-11 16:44:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-11 16:45:41
C:\ComboFix2.txt ... 2007-11-11 13:33
C:\ComboFix3.txt ... 2007-11-08 21:07
.
--- E O F ---
j'ai reinstallé norton 360 pour enlever le probleme de li'nstall de CCC Common.msi.apparemment cette boite de message n'apparait plus. je continue quand meme a suivre tes indications. ++
Re
¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :
O2 - BHO: {c24247a8-8250-fbaa-d014-9b58145df097} - {790fd541-85b9-410d-aabf-05288a74242c} - C:\WINDOWS\system32\ybmyonaa.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
Ferme HijackThis.
Supprime ceci avec Otmoveit:
C:\WINDOWS\system32\ehvecyts.dll
C:\WINDOWS\system32\ybmyonaa.dll
Copie colle le rapport + un HijackThis + un combofix + les soucis actuels.
a+
¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :
O2 - BHO: {c24247a8-8250-fbaa-d014-9b58145df097} - {790fd541-85b9-410d-aabf-05288a74242c} - C:\WINDOWS\system32\ybmyonaa.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
Ferme HijackThis.
Supprime ceci avec Otmoveit:
C:\WINDOWS\system32\ehvecyts.dll
C:\WINDOWS\system32\ybmyonaa.dll
Copie colle le rapport + un HijackThis + un combofix + les soucis actuels.
a+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
voila le rapport de OTmoveit
LoadLibrary failed for C:\WINDOWS\system32\ehvecyts.dll
C:\WINDOWS\system32\ehvecyts.dll NOT unregistered.
C:\WINDOWS\system32\ehvecyts.dll moved successfully.
File/Folder C:\WINDOWS\system32\ybmyonaa.dll not found.
Created on 11/12/2007 10:25:31
RAPPORT de HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26 nicolas, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.avast.com/fr-fr/index
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TP CfgWiz] "C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe" -G:{2D617065-1C52-4240-B5BC-C0AE12157777} -T:Config
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [La_View Mouse] C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe
O4 - HKCU\..\Run: [DeskSpace] C:\Program Files\DeskSpace\deskspace.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: STK017 PNP Monitor.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
LoadLibrary failed for C:\WINDOWS\system32\ehvecyts.dll
C:\WINDOWS\system32\ehvecyts.dll NOT unregistered.
C:\WINDOWS\system32\ehvecyts.dll moved successfully.
File/Folder C:\WINDOWS\system32\ybmyonaa.dll not found.
Created on 11/12/2007 10:25:31
RAPPORT de HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26 nicolas, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Inventel\Gateway\wlancfg.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.avast.com/fr-fr/index
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Afficher Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TP CfgWiz] "C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe" -G:{2D617065-1C52-4240-B5BC-C0AE12157777} -T:Config
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [La_View Mouse] C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe
O4 - HKCU\..\Run: [DeskSpace] C:\Program Files\DeskSpace\deskspace.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Alienware Dock.lnk = C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: STK017 PNP Monitor.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe
voila le rapport de combofix
ComboFix 07-11-08.1 - nicolas 2007-11-12 10:29:09.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1113 [GMT 1:00]
Running from: C:\Documents and Settings\nicolas\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-12 to 2007-11-12 ))))))))))))))))))))))))))))))))))))
.
2007-11-11 17:16 <REP> d-------- C:\Program Files\Norton 360
2007-11-11 17:15 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-11 17:15 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-11 10:27 <REP> d-------- C:\New Folder
2007-11-11 10:27 <REP> d-------- C:\hijackthis
2007-11-11 10:07 <REP> d-------- C:\VundoFix Backups
2007-11-09 18:30 <REP> d-------- C:\Program Files\Navilog1
2007-11-07 20:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Grisoft
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-06 20:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-06 20:30 4,080 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-06 19:07 <REP> d-------- C:\Program Files\Avira
2007-11-06 19:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-06 18:49 <REP> d-------- C:\Program Files\Panda Security
2007-10-29 12:38 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\ArcSoft
2007-10-29 12:37 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2007-10-29 12:36 <REP> d-------- C:\Program Files\Hercules
2007-10-29 12:36 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2007-10-29 12:36 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-10-29 12:36 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2007-10-29 12:34 <REP> d-------- C:\WINDOWS\OvtCam
2007-10-29 12:34 161,792 --------- C:\WINDOWS\system32\drivers\ov530vid.sys
2007-10-29 12:34 61,440 --------- C:\WINDOWS\ov530dib.dll
2007-10-29 12:34 40,960 --------- C:\WINDOWS\system32\ov530ext.dll
2007-10-29 12:34 25,177 --------- C:\WINDOWS\system32\drivers\ov530cmd.sys
2007-10-29 12:34 16,440 --------- C:\WINDOWS\system32\ov530usd.dll
2007-10-29 09:57 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Recordpad
2007-10-27 16:21 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-10-27 16:21 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-10-27 16:21 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-10-27 16:21 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-10-27 16:21 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-10-27 16:21 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-10-27 16:21 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-10-27 16:17 <REP> d-------- C:\Program Files\Electronic Arts
2007-10-24 15:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-24 12:48 <REP> d-------- C:\Program Files\MediaCoder
2007-10-24 12:42 <REP> d-------- C:\Program Files\GXTranscoder.net AWE
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\AVS4YOU
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2007-10-24 10:27 <REP> d-------- C:\Program Files\Fichiers communs\AVSMedia
2007-10-24 10:25 <REP> d-------- C:\Program Files\AVS4YOU
2007-10-24 10:23 1,700,352 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-10-24 10:23 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-10-24 10:23 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2007-10-24 10:23 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2007-10-24 10:23 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-10-24 10:10 <REP> d-------- C:\Temp
2007-10-24 10:05 <REP> d-------- C:\Program Files\QuickTime
2007-10-24 10:05 <REP> d-------- C:\Program Files\ImTOO
2007-10-21 11:00 <REP> d-------- C:\Program Files\oZone3D
2007-10-20 13:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Program Files\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Program Files\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\NCH Swift Sound
2007-10-14 13:31 <REP> d-------- C:\Program Files\Winamp
2007-10-14 13:31 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Winamp
2007-10-13 17:31 <REP> d-------- C:\Program Files\GT2002
2007-10-13 11:16 <REP> d-------- C:\WINDOWS\pss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 09:20 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OpenOffice.org2
2007-11-11 16:35 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-11 16:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-11 16:19 806 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-11 16:19 8,014 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-11 16:19 --------- d-----w C:\Program Files\Symantec
2007-11-11 09:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-07 16:33 --------- d-----w C:\Program Files\STK017_V2.01
2007-10-29 11:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-24 08:28 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia Multimedia Player
2007-10-22 19:23 --------- d-----w C:\Documents and Settings\nicolas\Application Data\DivX
2007-10-22 19:10 --------- d-----w C:\Program Files\Picasa2
2007-10-21 15:33 --------- d-----w C:\Program Files\Java
2007-10-20 10:31 --------- d-----w C:\Program Files\DeskSpace
2007-10-12 18:36 --------- d-----w C:\Program Files\Silkroad
2007-10-11 19:25 --------- d-----w C:\Program Files\WinMX
2007-10-11 18:39 --------- d-----w C:\Program Files\WinISO
2007-10-11 17:33 --------- d-----w C:\Program Files\Smart Projects
2007-10-11 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-07 08:06 --------- d-----w C:\Program Files\Elaborate Bytes
2007-10-06 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-06 16:20 --------- d-----w C:\Program Files\SlySoft
2007-10-06 16:17 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Skype
2007-10-06 16:08 --------- d-----w C:\Program Files\DiskTrix
2007-10-06 16:03 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OtakuSoftware
2007-10-06 15:44 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Joost
2007-10-05 17:12 --------- d-----w C:\Program Files\AxBx
2007-09-29 09:32 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Fichiers communs\Nokia
2007-09-23 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2007-09-21 19:41 --------- d-----w C:\Program Files\DivX
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-16 14:21 --------- d-----w C:\Program Files\PhotoFiltre
2007-09-15 19:12 --------- d-----w C:\Program Files\eRightSoft
2007-09-13 11:54 --------- d-----w C:\Program Files\Skype
2007-09-13 11:54 --------- d-----w C:\Program Files\Fichiers communs\Skype
2007-09-13 11:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-08-15 22:33 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-18 16:40 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-08_21.06.23.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-07 11:05:19 62,016 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-11-11 09:40:15 61,632 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
- 2006-09-19 10:44:04 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
+ 2006-09-19 11:44:04 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
- 2007-09-18 12:43:36 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
+ 2007-01-12 02:22:14 247,608 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
- 2007-09-18 12:43:36 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
+ 2007-01-12 02:22:20 276,792 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
- 2007-09-18 12:43:36 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
+ 2007-01-12 02:22:18 25,400 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
- 2006-10-03 15:47:52 109,360 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2006-10-03 16:47:52 109,360 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2007-08-07 12:37:56 53,248 ----a-w C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
+ 2007-08-07 16:20:44 182,248 ----a-w C:\WINDOWS\system32\Macromed\Director\SwDir.dll
+ 2007-08-07 12:35:56 585,728 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
+ 2007-08-07 12:19:40 1,490,944 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\dirapi.dll
+ 2007-08-07 12:36:32 24,576 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2007-08-07 15:52:32 1,113,600 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gi.dll
+ 2007-08-07 12:08:48 52,288 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gtapi.dll
+ 2007-08-07 12:17:24 606,208 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\iml32.dll
+ 2007-08-07 12:35:22 339,968 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Plugin.dll
+ 2007-08-07 12:35:32 483,328 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2007-08-07 12:28:38 180,224 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Proj.dll
+ 2007-08-07 16:20:28 391,144 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwHelper_1020023.exe
+ 2007-08-07 12:37:56 77,824 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exe
+ 2007-08-07 12:35:18 86,016 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwMenu.dll
+ 2007-08-07 12:37:58 98,304 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwOnce.dll
+ 2007-08-07 12:08:46 50,808 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SYMCCHECKER.DLL
+ 1999-06-25 09:55:30 149,504 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\UNWISE.EXE
- 2007-07-12 00:49:26 186,256 ----a-w C:\WINDOWS\system32\SymNPPWA.dll
+ 2007-02-19 03:23:04 185,496 ----a-r C:\WINDOWS\system32\SymNppWA.dll
+ 2007-11-12 09:22:00 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_7d4.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 17:22]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-12-06 11:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 08:29]
"nwiz"="nwiz.exe" [2006-03-09 08:29 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 08:29]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 C:\WINDOWS\soundman.exe]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-11 10:40]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-03-15 04:10]
"TP CfgWiz"="C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe" [2007-02-08 15:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-18 18:07]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"La_View Mouse"="C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe" [2006-01-04 17:32]
"DeskSpace"="C:\Program Files\DeskSpace\deskspace.exe" []
"ares"="C:\Program Files\Ares\Ares.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\nicolas\Menu D‚marrer\Programmes\D‚marrage\
Alienware Dock.lnk - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe [2007-07-01 10:24:53 nicolas]
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-01-25 18:42:22 nicolas]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-05-18 18:07:34 nicolas]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h
R2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys
R3 ATMELFVNETusb(AR)(R);ATMEL FVNETusb(AR)(R) Service for ATMEL USB FastVNET (AR);C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys
S3 SaiHFF0C;SaiHFF0C;C:\WINDOWS\system32\DRIVERS\SaiHFF0C.sys
S3 SaiUFF0C;SaiUFF0C;C:\WINDOWS\system32\DRIVERS\SaiUFF0C.sys
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINDOWS\system32\Drivers\SilvrLnk.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{634bfe42-0566-11dc-9e73-806d6172696f}]
\Shell\AutoRun\command - F:\POV.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd5ec2a8-055f-11dc-9694-0006f404143d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - G:\Boot.exe e
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-12 10:33:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-12 10:35:07
C:\ComboFix2.txt ... 2007-11-11 16:45
C:\ComboFix3.txt ... 2007-11-11 13:33
.
--- E O F ---
quand j'ai fait, combofix il m'est arrivé qu'un message de antivir me demandant de choisir ce que je voulais faire du fichier nlihtsrl.dll ( Inject jt) apparaisse. Sinon, je n'ai plus de soucis. L'ordinateur ne rame plus; pas de trianlge jaunedans la barre de notificatin, ni d'icone de one life stafety et autres du même genre sur le bureau. Ca m'a l'air ok; j'attends juste que tu vérifie mais rapports pour le confirmer. Je conclurai la discussin au prochain message si tu me dis que tout est reparti comme en l'an 40. A+
ComboFix 07-11-08.1 - nicolas 2007-11-12 10:29:09.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1113 [GMT 1:00]
Running from: C:\Documents and Settings\nicolas\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-12 to 2007-11-12 ))))))))))))))))))))))))))))))))))))
.
2007-11-11 17:16 <REP> d-------- C:\Program Files\Norton 360
2007-11-11 17:15 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-11 17:15 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-11 10:27 <REP> d-------- C:\New Folder
2007-11-11 10:27 <REP> d-------- C:\hijackthis
2007-11-11 10:07 <REP> d-------- C:\VundoFix Backups
2007-11-09 18:30 <REP> d-------- C:\Program Files\Navilog1
2007-11-07 20:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Grisoft
2007-11-06 20:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-06 20:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-06 20:30 4,080 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-06 19:07 <REP> d-------- C:\Program Files\Avira
2007-11-06 19:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-11-06 18:49 <REP> d-------- C:\Program Files\Panda Security
2007-10-29 12:38 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\ArcSoft
2007-10-29 12:37 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
2007-10-29 12:36 <REP> d-------- C:\Program Files\Hercules
2007-10-29 12:36 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
2007-10-29 12:36 245,408 --a------ C:\WINDOWS\system32\unicows.dll
2007-10-29 12:36 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2007-10-29 12:34 <REP> d-------- C:\WINDOWS\OvtCam
2007-10-29 12:34 161,792 --------- C:\WINDOWS\system32\drivers\ov530vid.sys
2007-10-29 12:34 61,440 --------- C:\WINDOWS\ov530dib.dll
2007-10-29 12:34 40,960 --------- C:\WINDOWS\system32\ov530ext.dll
2007-10-29 12:34 25,177 --------- C:\WINDOWS\system32\drivers\ov530cmd.sys
2007-10-29 12:34 16,440 --------- C:\WINDOWS\system32\ov530usd.dll
2007-10-29 09:57 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Recordpad
2007-10-27 16:21 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2007-10-27 16:21 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2007-10-27 16:21 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2007-10-27 16:21 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2007-10-27 16:21 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2007-10-27 16:21 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2007-10-27 16:21 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-10-27 16:17 <REP> d-------- C:\Program Files\Electronic Arts
2007-10-24 15:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-24 12:48 <REP> d-------- C:\Program Files\MediaCoder
2007-10-24 12:42 <REP> d-------- C:\Program Files\GXTranscoder.net AWE
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\AVS4YOU
2007-10-24 10:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2007-10-24 10:27 <REP> d-------- C:\Program Files\Fichiers communs\AVSMedia
2007-10-24 10:25 <REP> d-------- C:\Program Files\AVS4YOU
2007-10-24 10:23 1,700,352 --a------ C:\WINDOWS\system32\GdiPlus.dll
2007-10-24 10:23 524,288 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-10-24 10:23 413,760 --a------ C:\WINDOWS\system32\mpg4c32.dll
2007-10-24 10:23 261,632 --a------ C:\WINDOWS\system32\mcdvd_32.dll
2007-10-24 10:23 139,264 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-10-24 10:10 <REP> d-------- C:\Temp
2007-10-24 10:05 <REP> d-------- C:\Program Files\QuickTime
2007-10-24 10:05 <REP> d-------- C:\Program Files\ImTOO
2007-10-21 11:00 <REP> d-------- C:\Program Files\oZone3D
2007-10-20 13:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Program Files\NCH Software
2007-10-14 13:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Program Files\NCH Swift Sound
2007-10-14 13:32 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\NCH Swift Sound
2007-10-14 13:31 <REP> d-------- C:\Program Files\Winamp
2007-10-14 13:31 <REP> d-------- C:\Documents and Settings\nicolas\Application Data\Winamp
2007-10-13 17:31 <REP> d-------- C:\Program Files\GT2002
2007-10-13 11:16 <REP> d-------- C:\WINDOWS\pss
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-12 09:20 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OpenOffice.org2
2007-11-11 16:35 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-11-11 16:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-11 16:19 806 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-11 16:19 8,014 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-11 16:19 --------- d-----w C:\Program Files\Symantec
2007-11-11 09:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-11-07 16:33 --------- d-----w C:\Program Files\STK017_V2.01
2007-10-29 11:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-24 08:28 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia Multimedia Player
2007-10-22 19:23 --------- d-----w C:\Documents and Settings\nicolas\Application Data\DivX
2007-10-22 19:10 --------- d-----w C:\Program Files\Picasa2
2007-10-21 15:33 --------- d-----w C:\Program Files\Java
2007-10-20 10:31 --------- d-----w C:\Program Files\DeskSpace
2007-10-12 18:36 --------- d-----w C:\Program Files\Silkroad
2007-10-11 19:25 --------- d-----w C:\Program Files\WinMX
2007-10-11 18:39 --------- d-----w C:\Program Files\WinISO
2007-10-11 17:33 --------- d-----w C:\Program Files\Smart Projects
2007-10-11 15:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-07 08:06 --------- d-----w C:\Program Files\Elaborate Bytes
2007-10-06 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-10-06 16:20 --------- d-----w C:\Program Files\SlySoft
2007-10-06 16:17 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Skype
2007-10-06 16:08 --------- d-----w C:\Program Files\DiskTrix
2007-10-06 16:03 --------- d-----w C:\Documents and Settings\nicolas\Application Data\OtakuSoftware
2007-10-06 15:44 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Joost
2007-10-05 17:12 --------- d-----w C:\Program Files\AxBx
2007-09-29 09:32 --------- d-----w C:\Documents and Settings\nicolas\Application Data\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Nokia
2007-09-23 17:19 --------- d-----w C:\Program Files\Fichiers communs\Nokia
2007-09-23 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2007-09-21 19:41 --------- d-----w C:\Program Files\DivX
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-17 18:23 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-17 18:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-17 18:22 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-16 14:21 --------- d-----w C:\Program Files\PhotoFiltre
2007-09-15 19:12 --------- d-----w C:\Program Files\eRightSoft
2007-09-13 11:54 --------- d-----w C:\Program Files\Skype
2007-09-13 11:54 --------- d-----w C:\Program Files\Fichiers communs\Skype
2007-09-13 11:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-09-11 23:14 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 00:26 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-08-21 00:26 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-08-15 22:33 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-08-15 22:33 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-08-15 22:33 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-08-15 22:33 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-08-15 22:33 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-15 22:33 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-08-15 22:33 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-08-15 22:31 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-08-15 22:31 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-08-15 22:31 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-08-15 22:31 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-08-15 22:31 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-08-15 22:30 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-18 16:40 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-08_21.06.23.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-09-07 11:05:19 62,016 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
+ 2007-11-11 09:40:15 61,632 ----a-w C:\WINDOWS\system32\drivers\avipbb.sys
- 2006-09-19 10:44:04 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
+ 2006-09-19 11:44:04 15,664 ----a-w C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
- 2007-09-18 12:43:36 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
+ 2007-01-12 02:22:14 247,608 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
- 2007-09-18 12:43:36 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
+ 2007-01-12 02:22:20 276,792 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
- 2007-09-18 12:43:36 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
+ 2007-01-12 02:22:18 25,400 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
- 2006-10-03 15:47:52 109,360 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2006-10-03 16:47:52 109,360 ----a-w C:\WINDOWS\system32\GEARAspi.dll
+ 2007-08-07 12:37:56 53,248 ----a-w C:\WINDOWS\system32\Macromed\Common\SwSupport.dll
+ 2007-08-07 16:20:44 182,248 ----a-w C:\WINDOWS\system32\Macromed\Director\SwDir.dll
+ 2007-08-07 12:35:56 585,728 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Control.dll
+ 2007-08-07 12:19:40 1,490,944 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\dirapi.dll
+ 2007-08-07 12:36:32 24,576 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\DynaPlayer.dll
+ 2007-08-07 15:52:32 1,113,600 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gi.dll
+ 2007-08-07 12:08:48 52,288 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\gtapi.dll
+ 2007-08-07 12:17:24 606,208 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\iml32.dll
+ 2007-08-07 12:35:22 339,968 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Plugin.dll
+ 2007-08-07 12:35:32 483,328 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\PluginPing.dll
+ 2007-08-07 12:28:38 180,224 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\Proj.dll
+ 2007-08-07 16:20:28 391,144 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwHelper_1020023.exe
+ 2007-08-07 12:37:56 77,824 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwInit.exe
+ 2007-08-07 12:35:18 86,016 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwMenu.dll
+ 2007-08-07 12:37:58 98,304 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SwOnce.dll
+ 2007-08-07 12:08:46 50,808 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\SYMCCHECKER.DLL
+ 1999-06-25 09:55:30 149,504 ----a-w C:\WINDOWS\system32\Macromed\Shockwave 10\UNWISE.EXE
- 2007-07-12 00:49:26 186,256 ----a-w C:\WINDOWS\system32\SymNPPWA.dll
+ 2007-02-19 03:23:04 185,496 ----a-r C:\WINDOWS\system32\SymNppWA.dll
+ 2007-11-12 09:22:00 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_7d4.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 17:22]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-12-06 11:06]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 08:29]
"nwiz"="nwiz.exe" [2006-03-09 08:29 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 08:29]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 C:\WINDOWS\soundman.exe]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-06-18 14:10]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 14:53]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-11 10:40]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-03-15 04:10]
"TP CfgWiz"="C:\Program Files\Fichiers communs\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe" [2007-02-08 15:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-18 18:07]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"La_View Mouse"="C:\PROGRA~1\nicolas\1TEKCO~1\F1Driver.exe" [2006-01-04 17:32]
"DeskSpace"="C:\Program Files\DeskSpace\deskspace.exe" []
"ares"="C:\Program Files\Ares\Ares.exe" []
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
C:\Documents and Settings\nicolas\Menu D‚marrer\Programmes\D‚marrage\
Alienware Dock.lnk - C:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe [2007-07-01 10:24:53 nicolas]
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-01-25 18:42:22 nicolas]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-05-18 18:07:34 nicolas]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ares]
"C:\Program Files\Ares\Ares.exe" -h
R2 TICalc;TICalc;C:\WINDOWS\system32\drivers\TICalc.sys
R3 ATMELFVNETusb(AR)(R);ATMEL FVNETusb(AR)(R) Service for ATMEL USB FastVNET (AR);C:\WINDOWS\system32\DRIVERS\vnetusbr.sys
S3 ovt530;Webcam Classic;C:\WINDOWS\system32\Drivers\ov530vid.sys
S3 SaiHFF0C;SaiHFF0C;C:\WINDOWS\system32\DRIVERS\SaiHFF0C.sys
S3 SaiUFF0C;SaiUFF0C;C:\WINDOWS\system32\DRIVERS\SaiUFF0C.sys
S3 SilverLink;Texas Instruments SilverLink (USB GraphLink) Cable;C:\WINDOWS\system32\Drivers\SilvrLnk.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{634bfe42-0566-11dc-9e73-806d6172696f}]
\Shell\AutoRun\command - F:\POV.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd5ec2a8-055f-11dc-9694-0006f404143d}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Boot.exe e
\Shell\Open\command - G:\Boot.exe e
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-12 10:33:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-12 10:35:07
C:\ComboFix2.txt ... 2007-11-11 16:45
C:\ComboFix3.txt ... 2007-11-11 13:33
.
--- E O F ---
quand j'ai fait, combofix il m'est arrivé qu'un message de antivir me demandant de choisir ce que je voulais faire du fichier nlihtsrl.dll ( Inject jt) apparaisse. Sinon, je n'ai plus de soucis. L'ordinateur ne rame plus; pas de trianlge jaunedans la barre de notificatin, ni d'icone de one life stafety et autres du même genre sur le bureau. Ca m'a l'air ok; j'attends juste que tu vérifie mais rapports pour le confirmer. Je conclurai la discussin au prochain message si tu me dis que tout est reparti comme en l'an 40. A+
Salut
Norton est mal desinstallé, as tu supprimé tous les fichiers ?
As tu un nettoyeur de registre?
A+
Norton est mal desinstallé, as tu supprimé tous les fichiers ?
As tu un nettoyeur de registre?
A+
j'ai ccleaner. il a dû mal se réinstaller ou mal se désintaller. j'ai supprimer le dossier norton 360 avant de réinstaller. Il m'est impossible quand j'ouvre la fen^tre principal d'aller dans mon compte maius il faut d'abord que je mette le code d'enregistrment et c'est mno père qui l'a reçu dnas son mail.J'ai antivir en attendant parce que norton me saoule trop ^^