Pubs intempestves
Fermé
kevin596
-
11 déc. 2007 à 14:26
g!rly Messages postés 18206 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 - 10 janv. 2008 à 20:00
g!rly Messages postés 18206 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 - 10 janv. 2008 à 20:00
27 réponses
bonsoir,voici le rapport de combofix
ComboFix 07-12-12.3 - kevin 2007-12-12 18:25:57.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.142 [GMT 1:00]
Running from: C:\Downloads\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Fichiers communs\{584E7~1
C:\WINDOWS\IA
C:\WINDOWS\system32\winnb58.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_FOPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-12 to 2007-12-12 ))))))))))))))))))))))))))))))))))))
.
2007-12-12 15:53 . 2007-12-12 15:54 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-11 18:05 . 2007-12-11 18:05 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\Grisoft
2007-12-11 18:05 . 2007-12-11 18:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-11 18:05 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 17:51 . 2007-12-11 17:51 <REP> d-------- C:\Program Files\Avira
2007-12-11 17:51 . 2007-12-11 17:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-11 17:41 . 2007-12-11 17:41 <REP> d-------- C:\Program Files\Sunbelt Software
2007-12-11 15:55 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-12-11 15:37 . 2007-12-11 15:37 13,233,454 --a------ C:\upload_moi_ALLART.tar.gz
2007-12-11 14:01 . 2007-12-11 21:44 <REP> d-------- C:\Program Files\Navilog1
2007-12-09 00:29 . 2007-12-09 00:29 <REP> d-------- C:\Program Files\Change Extension
2007-12-09 00:29 . 2007-12-09 00:29 88,064 --a------ C:\WINDOWS\AMUninst01c.exe
2007-12-08 16:08 . 2007-12-08 16:10 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\DeepBurner
2007-12-08 12:01 . 2007-12-09 19:32 <REP> d-------- C:\Program Files\Incomplete
2007-12-08 09:33 . 2007-12-08 19:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-08 09:33 . 2007-12-08 09:33 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-06 22:44 . 2007-12-06 22:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-06 22:43 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp59C06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp58C06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp4DC06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp21D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp15D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp13D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp06D06.FOT
2007-12-05 14:22 . 2007-12-05 14:34 <REP> d-------- C:\Program Files\AlienSky
2007-12-04 23:50 . 2007-12-05 16:31 <REP> d-------- C:\Program Files\Zone.com Deluxe Games
2007-12-04 17:11 . 2007-12-04 17:11 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\Windows Live Writer
2007-12-02 19:12 . 2007-12-02 19:13 <REP> d-------- C:\WINDOWS\AU_Temp
2007-12-02 17:22 . 2007-12-02 17:22 <REP> d-------- C:\WINDOWS\report
2007-12-02 17:22 . 2007-12-02 17:21 39,801,177 --a------ C:\WINDOWS\LPT$VPN.855
2007-12-02 17:21 . 2007-12-02 19:13 <REP> d-------- C:\WINDOWS\AU_Backup
2007-12-02 17:21 . 2007-12-02 17:21 39,801,177 --a------ C:\WINDOWS\VPTNFILE.855
2007-12-02 17:21 . 2007-12-02 17:21 1,899,383 --a------ C:\WINDOWS\tsc.ptn
2007-12-02 17:21 . 2007-12-02 19:13 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-12-02 17:21 . 2007-12-02 17:21 267,845 --a------ C:\WINDOWS\tsc.exe
2007-12-02 17:21 . 2007-12-02 19:13 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-12-02 17:21 . 2007-12-02 17:21 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-12-02 17:21 . 2007-12-02 19:13 823 --a------ C:\WINDOWS\tsc.ini
2007-12-02 17:13 . 2007-12-02 17:13 <REP> d-------- C:\WINDOWS\AU_Log
2007-12-02 17:13 . 2007-12-02 17:13 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-12-02 17:13 . 2007-12-02 17:13 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-12-02 17:13 . 2007-12-02 17:13 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-12-02 17:13 . 2007-12-02 19:12 170 --a------ C:\WINDOWS\GetServer.ini
2007-12-02 15:11 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-12-02 15:09 . 2007-12-02 15:09 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-02 14:52 . 2007-12-02 14:55 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-11-30 18:02 . 2004-01-02 01:04 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-11-30 18:02 . 2006-10-26 21:41 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-11-30 18:02 . 2006-10-26 21:40 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-11-30 18:02 . 2006-10-26 21:40 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-11-30 18:02 . 2006-10-26 14:06 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-11-30 18:02 . 2004-01-01 21:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2007-11-30 18:02 . 2004-01-02 01:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
2007-11-30 18:02 . 2004-01-02 00:55 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intervideo
2007-11-30 18:02 . 2004-01-02 01:04 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
2007-11-30 16:02 . 2007-11-30 16:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-11-29 14:54 . 2007-11-29 14:54 <REP> d-------- C:\temp
2007-11-21 15:44 . 2007-12-12 17:11 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\OpenOffice.org2
2007-11-19 23:15 . 2007-11-19 23:15 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\MySpace
2007-11-19 13:47 . 2007-11-19 13:47 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 17:26 --------- d-----w C:\Program Files\FlashGet
2007-12-12 17:21 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-12-12 17:13 --------- d-----w C:\Program Files\Wanadoo
2007-12-12 14:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 14:10 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\Lavasoft
2007-12-11 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-11 10:35 --------- d-----w C:\Program Files\Windows Journal Viewer
2007-12-11 09:48 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\MSNInstaller
2007-12-09 18:32 --------- d-----w C:\Program Files\LimeWire
2007-12-05 18:54 --------- d-----w C:\Program Files\GOM
2007-12-05 18:35 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-05 18:06 --------- d-----w C:\Program Files\Windows Media Connect
2007-12-05 17:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-05 15:11 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\LimeWire
2007-12-04 16:12 --------- d-----w C:\Program Files\Windows Live
2007-12-04 13:53 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-04 12:30 --------- d-----w C:\Program Files\Symantec
2007-12-04 12:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-02 13:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-01 21:45 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-11-29 14:01 --------- d-----w C:\Program Files\Microsoft Works
2007-11-20 11:54 --------- d-----w C:\Program Files\Java
2007-11-16 07:08 --------- d-----w C:\Program Files\InterCasino France
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 13:55 151,552 ----a-w C:\WINDOWS\system32\Netlog24Uninstaller.exe
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-10-02 22:44 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 61,440 2003-02-11 19:02:48 C:\hp\KBD\bak\KBD.EXE
----a-w 61,440 2003-02-11 19:02:48 C:\hp\KBD\kbd.exe
----a-w 155,896 2006-09-19 08:34:39 C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe
----a-w 286,720 2004-05-10 23:48:38 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 256,576 2006-10-30 08:36:36 C:\Program Files\iTunes\iTunesHelper.exe
----a-w 98,304 2004-01-02 00:03:59 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 282,624 2006-10-25 17:58:18 C:\Program Files\QuickTime\qttask.exe
----a-w 24,576 2004-10-13 14:12:06 C:\Program Files\Wanadoo\bak\CnxMon.exe
----a-w 24,576 2004-10-13 15:12:06 C:\Program Files\Wanadoo\CnxMon.exe
----a-w 49,152 2004-10-13 14:12:08 C:\Program Files\Wanadoo\bak\TaskbarIcon.exe
------w 49,152 2004-10-13 15:12:08 C:\Program Files\Wanadoo\TaskBarIcon.exe
----a-w 24,576 2004-10-13 14:12:08 C:\Program Files\Wanadoo\bak\Watch.exe
------w 24,576 2004-10-13 15:12:08 C:\Program Files\Wanadoo\Watch.exe
-c--a-w 118,784 2003-12-17 22:31:42 C:\WINDOWS\CREATOR\bak\Remind_XP.exe
----a-w 118,784 2003-12-17 22:31:42 C:\WINDOWS\CREATOR\Remind_XP.exe
-c--a-w 233,472 2004-04-14 19:43:46 C:\WINDOWS\SMINST\bak\RECGUARD.EXE
----a-w 233,472 2004-04-14 19:43:46 C:\WINDOWS\SMINST\Recguard.exe
-c--a-w 52,736 1998-05-07 15:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe
----a-w 52,736 1998-05-07 15:04:38 C:\WINDOWS\system\hpsysdrv.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 09:57]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 11:00 C:\WINDOWS\system32\rundll32.exe]
"MDNS"="C:\WINDOWS\system32\service.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-08 15:10]
"Mercora"="C:\Program Files\Mercora\MercoraClient.exe" []
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 16:12]
"EPSON Stylus Photo RX420 Series (Copie 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"EPSON Stylus Photo RX420 Series (Copie 2)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"zzzHPSETUP"="E:\Setup.exe" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-12 10:34]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="" []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\DSLMON.lnk
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kevin.ALLART^Menu Démarrer^Programmes^Démarrage^MSN Pictures Displayer.lnk]
path=C:\Documents and Settings\kevin.ALLART\Menu Démarrer\Programmes\Démarrage\MSN Pictures Displayer.lnk
backup=C:\WINDOWS\pss\MSN Pictures Displayer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kevin.ALLART^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\kevin.ALLART\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage]
C:\Program Files\AdVantage\AdVantage.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe /automount
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-05 11:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Efface Historique 2.0]
C:\PROGRA~1\EFFACE~1\EFFACE~1.EXE -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\FlashGet.exe /min
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 16:04 52736 --a------ c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2006-10-30 09:36 256576 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 20:02 61440 --a------ C:\HP\KBD\KBD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2003-09-12 20:13 98304 --a------ C:\WINDOWS\system32\ps2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2004-04-14 20:43 233472 --a------ C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2004-05-20 09:47 249856 --a------ C:\WINDOWS\system32\keyhook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-28 09:57 68856 --a------ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE]
C:\Program Files\DAEMON Tools SearchBar\whse.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
2004-10-13 16:12 24576 --a------ C:\PROGRA~1\Wanadoo\CnxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
2004-10-13 16:12 49152 --------- C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
2004-10-13 16:12 24576 --------- C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ykgfcqv]
c:\windows\system32\ykgfcqv.exe ykgfcqv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\_SetRes]
c:\hp\bin\cloaker c:\hp\bin\res.bat
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-08 12:46:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-07 19:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - kévin.job"
"2007-12-03 13:21:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 18:34:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-12 18:38:19 - machine was rebooted
.
2007-12-12 14:57:02 --- E O F ---
bonne nuit a tous ;;))
ComboFix 07-12-12.3 - kevin 2007-12-12 18:25:57.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.142 [GMT 1:00]
Running from: C:\Downloads\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Fichiers communs\{584E7~1
C:\WINDOWS\IA
C:\WINDOWS\system32\winnb58.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_FOPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-12 to 2007-12-12 ))))))))))))))))))))))))))))))))))))
.
2007-12-12 15:53 . 2007-12-12 15:54 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-11 18:05 . 2007-12-11 18:05 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\Grisoft
2007-12-11 18:05 . 2007-12-11 18:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-11 18:05 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 17:51 . 2007-12-11 17:51 <REP> d-------- C:\Program Files\Avira
2007-12-11 17:51 . 2007-12-11 17:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-11 17:41 . 2007-12-11 17:41 <REP> d-------- C:\Program Files\Sunbelt Software
2007-12-11 15:55 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-12-11 15:37 . 2007-12-11 15:37 13,233,454 --a------ C:\upload_moi_ALLART.tar.gz
2007-12-11 14:01 . 2007-12-11 21:44 <REP> d-------- C:\Program Files\Navilog1
2007-12-09 00:29 . 2007-12-09 00:29 <REP> d-------- C:\Program Files\Change Extension
2007-12-09 00:29 . 2007-12-09 00:29 88,064 --a------ C:\WINDOWS\AMUninst01c.exe
2007-12-08 16:08 . 2007-12-08 16:10 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\DeepBurner
2007-12-08 12:01 . 2007-12-09 19:32 <REP> d-------- C:\Program Files\Incomplete
2007-12-08 09:33 . 2007-12-08 19:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-08 09:33 . 2007-12-08 09:33 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-06 22:44 . 2007-12-06 22:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-06 22:43 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp59C06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp58C06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp4DC06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp21D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp15D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp13D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp06D06.FOT
2007-12-05 14:22 . 2007-12-05 14:34 <REP> d-------- C:\Program Files\AlienSky
2007-12-04 23:50 . 2007-12-05 16:31 <REP> d-------- C:\Program Files\Zone.com Deluxe Games
2007-12-04 17:11 . 2007-12-04 17:11 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\Windows Live Writer
2007-12-02 19:12 . 2007-12-02 19:13 <REP> d-------- C:\WINDOWS\AU_Temp
2007-12-02 17:22 . 2007-12-02 17:22 <REP> d-------- C:\WINDOWS\report
2007-12-02 17:22 . 2007-12-02 17:21 39,801,177 --a------ C:\WINDOWS\LPT$VPN.855
2007-12-02 17:21 . 2007-12-02 19:13 <REP> d-------- C:\WINDOWS\AU_Backup
2007-12-02 17:21 . 2007-12-02 17:21 39,801,177 --a------ C:\WINDOWS\VPTNFILE.855
2007-12-02 17:21 . 2007-12-02 17:21 1,899,383 --a------ C:\WINDOWS\tsc.ptn
2007-12-02 17:21 . 2007-12-02 19:13 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-12-02 17:21 . 2007-12-02 17:21 267,845 --a------ C:\WINDOWS\tsc.exe
2007-12-02 17:21 . 2007-12-02 19:13 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-12-02 17:21 . 2007-12-02 17:21 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-12-02 17:21 . 2007-12-02 19:13 823 --a------ C:\WINDOWS\tsc.ini
2007-12-02 17:13 . 2007-12-02 17:13 <REP> d-------- C:\WINDOWS\AU_Log
2007-12-02 17:13 . 2007-12-02 17:13 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-12-02 17:13 . 2007-12-02 17:13 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-12-02 17:13 . 2007-12-02 17:13 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-12-02 17:13 . 2007-12-02 19:12 170 --a------ C:\WINDOWS\GetServer.ini
2007-12-02 15:11 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-12-02 15:09 . 2007-12-02 15:09 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-02 14:52 . 2007-12-02 14:55 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-11-30 18:02 . 2004-01-02 01:04 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-11-30 18:02 . 2006-10-26 21:41 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-11-30 18:02 . 2006-10-26 21:40 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-11-30 18:02 . 2006-10-26 21:40 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-11-30 18:02 . 2006-10-26 14:06 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-11-30 18:02 . 2004-01-01 21:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2007-11-30 18:02 . 2004-01-02 01:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
2007-11-30 18:02 . 2004-01-02 00:55 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intervideo
2007-11-30 18:02 . 2004-01-02 01:04 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
2007-11-30 16:02 . 2007-11-30 16:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-11-29 14:54 . 2007-11-29 14:54 <REP> d-------- C:\temp
2007-11-21 15:44 . 2007-12-12 17:11 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\OpenOffice.org2
2007-11-19 23:15 . 2007-11-19 23:15 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\MySpace
2007-11-19 13:47 . 2007-11-19 13:47 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 17:26 --------- d-----w C:\Program Files\FlashGet
2007-12-12 17:21 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-12-12 17:13 --------- d-----w C:\Program Files\Wanadoo
2007-12-12 14:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 14:10 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\Lavasoft
2007-12-11 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-11 10:35 --------- d-----w C:\Program Files\Windows Journal Viewer
2007-12-11 09:48 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\MSNInstaller
2007-12-09 18:32 --------- d-----w C:\Program Files\LimeWire
2007-12-05 18:54 --------- d-----w C:\Program Files\GOM
2007-12-05 18:35 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-05 18:06 --------- d-----w C:\Program Files\Windows Media Connect
2007-12-05 17:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-05 15:11 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\LimeWire
2007-12-04 16:12 --------- d-----w C:\Program Files\Windows Live
2007-12-04 13:53 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-04 12:30 --------- d-----w C:\Program Files\Symantec
2007-12-04 12:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-02 13:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-01 21:45 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-11-29 14:01 --------- d-----w C:\Program Files\Microsoft Works
2007-11-20 11:54 --------- d-----w C:\Program Files\Java
2007-11-16 07:08 --------- d-----w C:\Program Files\InterCasino France
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 13:55 151,552 ----a-w C:\WINDOWS\system32\Netlog24Uninstaller.exe
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-10-02 22:44 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 61,440 2003-02-11 19:02:48 C:\hp\KBD\bak\KBD.EXE
----a-w 61,440 2003-02-11 19:02:48 C:\hp\KBD\kbd.exe
----a-w 155,896 2006-09-19 08:34:39 C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe
----a-w 286,720 2004-05-10 23:48:38 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 256,576 2006-10-30 08:36:36 C:\Program Files\iTunes\iTunesHelper.exe
----a-w 98,304 2004-01-02 00:03:59 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 282,624 2006-10-25 17:58:18 C:\Program Files\QuickTime\qttask.exe
----a-w 24,576 2004-10-13 14:12:06 C:\Program Files\Wanadoo\bak\CnxMon.exe
----a-w 24,576 2004-10-13 15:12:06 C:\Program Files\Wanadoo\CnxMon.exe
----a-w 49,152 2004-10-13 14:12:08 C:\Program Files\Wanadoo\bak\TaskbarIcon.exe
------w 49,152 2004-10-13 15:12:08 C:\Program Files\Wanadoo\TaskBarIcon.exe
----a-w 24,576 2004-10-13 14:12:08 C:\Program Files\Wanadoo\bak\Watch.exe
------w 24,576 2004-10-13 15:12:08 C:\Program Files\Wanadoo\Watch.exe
-c--a-w 118,784 2003-12-17 22:31:42 C:\WINDOWS\CREATOR\bak\Remind_XP.exe
----a-w 118,784 2003-12-17 22:31:42 C:\WINDOWS\CREATOR\Remind_XP.exe
-c--a-w 233,472 2004-04-14 19:43:46 C:\WINDOWS\SMINST\bak\RECGUARD.EXE
----a-w 233,472 2004-04-14 19:43:46 C:\WINDOWS\SMINST\Recguard.exe
-c--a-w 52,736 1998-05-07 15:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe
----a-w 52,736 1998-05-07 15:04:38 C:\WINDOWS\system\hpsysdrv.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 09:57]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 11:00 C:\WINDOWS\system32\rundll32.exe]
"MDNS"="C:\WINDOWS\system32\service.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-08 15:10]
"Mercora"="C:\Program Files\Mercora\MercoraClient.exe" []
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 16:12]
"EPSON Stylus Photo RX420 Series (Copie 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"EPSON Stylus Photo RX420 Series (Copie 2)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"zzzHPSETUP"="E:\Setup.exe" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-12 10:34]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="" []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\DSLMON.lnk
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kevin.ALLART^Menu Démarrer^Programmes^Démarrage^MSN Pictures Displayer.lnk]
path=C:\Documents and Settings\kevin.ALLART\Menu Démarrer\Programmes\Démarrage\MSN Pictures Displayer.lnk
backup=C:\WINDOWS\pss\MSN Pictures Displayer.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kevin.ALLART^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\kevin.ALLART\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage]
C:\Program Files\AdVantage\AdVantage.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe /automount
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-05 11:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Efface Historique 2.0]
C:\PROGRA~1\EFFACE~1\EFFACE~1.EXE -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\FlashGet.exe /min
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 16:04 52736 --a------ c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2006-10-30 09:36 256576 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 20:02 61440 --a------ C:\HP\KBD\KBD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2003-09-12 20:13 98304 --a------ C:\WINDOWS\system32\ps2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2004-04-14 20:43 233472 --a------ C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2004-05-20 09:47 249856 --a------ C:\WINDOWS\system32\keyhook.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-28 09:57 68856 --a------ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE]
C:\Program Files\DAEMON Tools SearchBar\whse.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
2004-10-13 16:12 24576 --a------ C:\PROGRA~1\Wanadoo\CnxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
2004-10-13 16:12 49152 --------- C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
2004-10-13 16:12 24576 --------- C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ykgfcqv]
c:\windows\system32\ykgfcqv.exe ykgfcqv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\_SetRes]
c:\hp\bin\cloaker c:\hp\bin\res.bat
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-08 12:46:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-07 19:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - kévin.job"
"2007-12-03 13:21:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 18:34:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-12 18:38:19 - machine was rebooted
.
2007-12-12 14:57:02 --- E O F ---
bonne nuit a tous ;;))
g!rly
Messages postés
18206
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
407
13 déc. 2007 à 13:09
13 déc. 2007 à 13:09
salut kevin,
Desinstalleur Norton:
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924
car il reste des traces
¤
1/Télécharge Brute Force Uninstaller (de Merijn)
http://www.merijn.org/files/bfu.zip
dezip le sur ton bureau et double click sur bfu.exe pour l´ouvrir
regarde ceci en guise de tutoriel pour la suite :
http://serveur1.archive-host.com/membres/up/1366464061/cbc8b13c.gif
2 coche les cases suivantes :
* Use settings specified in script for the above option
* Show log after script ends
3 click sur le boutton WEb dans le coin en haut a droite
4 copie et colle l´url suivante dans la barre d´adresse qui va s´afficher :
http://metallica.geekstogo.com/alcanshorty.bfu
5 execute le script en cliquant le bouton execute
6 quand il aura fini click sur le bouton save pour avoir une copie du rapport
7. post ce rapport ici
¤
supprime tous ce qui suit :
C:\WINDOWS\imsins.BAK
C:\upload_moi_ALLART.tar.gz
C:\Program Files\Navilog1 -> par le panneau de configuration ajoue et suppression de programme puis le dossier dans tes programme files
C:\Program Files\Incomplete
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\QTFont.for
c:\windows\system32\ykgfcqv.exe = si present
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe -> par le panneau de configuration ajoue et suppression de programme puis le dossier dans tes programme files
fais moi savoir si tu n´arrive pas a les supprimer
¤
Fix.reg
Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(X)) :
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ykgfcqv]
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
note : il y a une ligne balnache a la fin et regedit4 est sur la premiere ligne
Puis click sur "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : fix.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"
ca doit ressembler a ca une fois enrregistré :
http://img520.imageshack.us/img520/4251/screenshot005ps2.png
quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"
¤
fais un scan en mode sans echec a l´aide d´antivir et post le rapport ici stp
Comment redémarrer en mode sans echec?
Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
capture d´ecran : http://www.coupdepoucepc.com/images_cdppc4/fichespratiques/windowsxp/modese/modese2.jpg
Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
Ps : si F8 ne marche pas utilise la touche F5.
donc post le rapport de bfu et celui d´antivir dans ta reponse
@+
Desinstalleur Norton:
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924
car il reste des traces
¤
1/Télécharge Brute Force Uninstaller (de Merijn)
http://www.merijn.org/files/bfu.zip
dezip le sur ton bureau et double click sur bfu.exe pour l´ouvrir
regarde ceci en guise de tutoriel pour la suite :
http://serveur1.archive-host.com/membres/up/1366464061/cbc8b13c.gif
2 coche les cases suivantes :
* Use settings specified in script for the above option
* Show log after script ends
3 click sur le boutton WEb dans le coin en haut a droite
4 copie et colle l´url suivante dans la barre d´adresse qui va s´afficher :
http://metallica.geekstogo.com/alcanshorty.bfu
5 execute le script en cliquant le bouton execute
6 quand il aura fini click sur le bouton save pour avoir une copie du rapport
7. post ce rapport ici
¤
supprime tous ce qui suit :
C:\WINDOWS\imsins.BAK
C:\upload_moi_ALLART.tar.gz
C:\Program Files\Navilog1 -> par le panneau de configuration ajoue et suppression de programme puis le dossier dans tes programme files
C:\Program Files\Incomplete
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\QTFont.for
c:\windows\system32\ykgfcqv.exe = si present
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe -> par le panneau de configuration ajoue et suppression de programme puis le dossier dans tes programme files
fais moi savoir si tu n´arrive pas a les supprimer
¤
Fix.reg
Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(X)) :
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ykgfcqv]
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
note : il y a une ligne balnache a la fin et regedit4 est sur la premiere ligne
Puis click sur "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : fix.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"
ca doit ressembler a ca une fois enrregistré :
http://img520.imageshack.us/img520/4251/screenshot005ps2.png
quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"
¤
fais un scan en mode sans echec a l´aide d´antivir et post le rapport ici stp
Comment redémarrer en mode sans echec?
Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
capture d´ecran : http://www.coupdepoucepc.com/images_cdppc4/fichespratiques/windowsxp/modese/modese2.jpg
Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
Ps : si F8 ne marche pas utilise la touche F5.
donc post le rapport de bfu et celui d´antivir dans ta reponse
@+
bonjour,j'ai un probleme ds ce que tu me emande de faire.une fois brute force uninstaller téléchargé,je n'arrive pas a l'ouvrir.on me dit que le fichier est inconnu ou endommagé!!:s merci de me dire comment faire
g!rly
Messages postés
18206
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
407
14 déc. 2007 à 16:26
14 déc. 2007 à 16:26
salut kevin
essaie de le prendre directement sur le site de l´auteur
http://merijn.org/
essaie de le prendre directement sur le site de l´auteur
http://merijn.org/
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Bonsoir,désolé du retard j'ai eu quelques empêchements ;;))
voici le rapport de bfu
BFU v1.10.0
Windows XP SP2 (WinNT 5.01.2600 SP2)
Script started at 23:47:23, on 21/12/2007
Warning: unknown command 'OptionStatusOn' on line #7
Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)
Failed: DllUnregister C:\Program Files\Deskbar\deskbar.dll|1 (file not found)
Failed: DllUnregister \asappsrv.dll|1 (file not found)
Failed: DllUnregister \MyToolBar.dll|1 (file not found)
Failed: DllUnregister \888Bar.dll|1 (file not found)
Failed: ServiceStop Network Monitor (service not found)
Failed: ServiceStop cmdService (service not found)
Failed: ServiceDisable Network Monitor (service not found)
Failed: ServiceDisable cmdService (service not found)
Failed: ServiceDelete Network Monitor (service not found)
Failed: ServiceDelete cmdService (service not found)
Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)
Option pause between commands: 300 ms
Option pause between commands: 50 ms
Failed: FolderDelete C:\Program Files\MsConfigs (folder not found)
Failed: FolderDelete C:\Program Files\winupdates (folder not found)
Failed: FolderDelete C:\Program Files\winupdate (folder not found)
Failed: FolderDelete C:\Program Files\winsupdater (folder not found)
Failed: FolderDelete C:\Program Files\MsUpdate (folder not found)
Failed: FolderDelete C:\Program Files\MsMovies (folder not found)
Failed: FolderDelete C:\Program Files\wmplayer (folder not found)
Failed: FolderDelete C:\Program Files\outlook (folder not found)
Failed: FileDelete C:\Program Files\Common Files\Windows\mc-*-*.exe (operation failed)
Failed: FileDelete C:\Program Files\Common Files\Download\mc-*-*.exe (operation failed)
Failed: FolderDelete C:\WINDOWS\system32\nstlr (folder not found)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\update.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\services.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\activate.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\MyToolBar.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\update.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\services.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\activate.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\MyToolBar.dll (operation failed)
Failed: FolderDelete C:\Program Files\toolbar888 (folder not found)
Failed: FolderDelete C:\Program Files\e-mailpaysu toolbar (folder not found)
Failed: FolderDelete C:\Program Files\EMUSIC TOOLBAR (folder not found)
Failed: FolderDelete C:\Program Files\find dvd toolbar (folder not found)
Failed: FolderDelete C:\Program Files\GULESIDER VERKTøYLINJE (folder not found)
Failed: FolderDelete C:\Program Files\sesam-p4 toolbar (folder not found)
Failed: FolderDelete C:\Program Files\slownik ling (folder not found)
Failed: FolderDelete C:\Program Files\MediaPipe (folder not found)
Failed: FolderDelete C:\Program Files\p2pnetworks (folder not found)
Failed: FileDelete C:\Documents and Settings\kevin\LOADADV*.EXE (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFD713.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFE7CA.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFE85C.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFF9E1.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFFA0D.tmp (operation failed)
Failed: FolderDelete C:\Program Files\Maxifiles (folder not found)
Failed: FolderDelete C:\Program Files\DNS (folder not found)
Failed: FolderDelete C:\Program Files\EQAdvice (folder not found)
Failed: FolderDelete C:\Program Files\FCAdvice (folder not found)
Failed: FolderDelete C:\Program Files\PSCastor (folder not found)
Failed: FolderDelete C:\Program Files\CMIntex (folder not found)
Failed: FolderDelete C:\Program Files\PadsysAssistant (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\FreeProd1 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\FreeProd2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\InetGet (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\InetGet2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\svchostsys (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\simtest (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\misc001 (folder not found)
Failed: FolderDelete C:\Program Files\InetGet2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\VCClient (folder not found)
Failed: FolderDelete C:\Program Files\Network Monitor (folder not found)
Failed: FolderDelete C:\WINDOWS\inet20001 (folder not found)
Failed: FolderDelete C:\WINDOWS\inet20000 (folder not found)
Failed: FolderDelete C:\Program Files\Update06 (folder not found)
Failed: FolderDelete C:\Program Files\Update03 (folder not found)
Failed: FolderDelete C:\Program Files\Update04 (folder not found)
Failed: FolderDelete C:\Program Files\Update08 (folder not found)
Failed: FolderDelete C:\Program Files\W-Update (folder not found)
Failed: FolderDelete C:\Program Files\Yazzle Sudoku (folder not found)
Failed: FolderDelete C:\Program Files\Cas (folder not found)
Failed: FolderDelete C:\Program Files\CasStub (folder not found)
Failed: FolderDelete C:\Program Files\Cas2Stub (folder not found)
Failed: FolderDelete C:\Program Files\ipwins (folder not found)
Failed: FolderDelete C:\Program Files\Ipwindows (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\Snowball Wars (folder not found)
Failed: FolderDelete C:\Program Files\folder.js (folder not found)
Failed: FolderDelete C:\Program Files\ini.ini (folder not found)
Failed: FolderDelete C:\temp (folder not found)
Failed: FolderDelete C:\WINDOWS\mdrive (folder not found)
Failed: FolderDelete C:\WINDOWS\system32\crunner (folder not found)
Failed: FolderDelete C:\Program Files\PECarlin (folder not found)
Failed: FolderDelete C:\Program Files\AXVenore (folder not found)
Failed: FolderDelete C:\Program Files\SDVita (folder not found)
Failed: FolderDelete C:\Program Files\EQBranch (folder not found)
Failed: FolderDelete C:\Program Files\EQArticle (folder not found)
Failed: FolderDelete C:\Program Files\PSHope (folder not found)
Failed: FolderDelete C:\Program Files\Batty (folder not found)
Failed: FolderDelete C:\Program Files\Batty2 (folder not found)
Failed: FolderDelete C:\Program Files\AXFibula (folder not found)
Failed: FolderDelete C:\Program Files\CMFibula (folder not found)
Failed: FolderDelete C:\Program Files\PSLister (folder not found)
Failed: FolderDelete C:\Program Files\PSCloner (folder not found)
Failed: FolderDelete C:\Program Files\PSDream (folder not found)
Failed: FolderDelete C:\Program Files\cmapp (folder not found)
Failed: FolderDelete C:\Program Files\cmman (folder not found)
Failed: FolderDelete C:\Program Files\cmsystem (folder not found)
Failed: FolderDelete C:\Program Files\fcengine (folder not found)
Failed: FolderDelete C:\Program Files\wincmapp (folder not found)
Failed: FolderDelete C:\Program Files\Deskbar\Cache (folder not found)
Failed: FolderDelete C:\Program Files\popupwithcast (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\cloader (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\misc001 (folder not found)
Failed: FolderDelete C:\Program Files\Web Buying (folder not found)
Failed: FolderCreate C:\bintheredunthat (folder already exists)
Failed: FileMove C:\WINDOWS\win*-*.exe|C:\bintheredunthat (source file not found)
Script completed.
et le rapport de antivir :
AntiVir PersonalEdition Classic
Report file date: samedi 22 décembre 2007 00:57
Scanning for 985234 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:57:38
ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:57:38
ANTIVIR3.VDF : 7.0.1.138 185344 Bytes 21/12/2007 17:00:49
AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 21/12/2007 17:00:49
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.2 360488 Bytes 21/12/2007 17:00:49
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Rootkit search
Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\rootkit.avp
Logging..........................: high
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Scan memory......................: off
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: on
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: high
Expanded search settings.........: 0x00300922
Start of the scan: samedi 22 décembre 2007 00:57
Starting search for hidden objects.
The driver could not be initialized.
End of the scan: samedi 22 décembre 2007 00:57
Used time: 00:03 min
The scan has been done completely.
0 Scanning directories
0 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
0 Files not concerned
0 Archives were scanned
0 Warnings
0 Notes
voici le rapport de bfu
BFU v1.10.0
Windows XP SP2 (WinNT 5.01.2600 SP2)
Script started at 23:47:23, on 21/12/2007
Warning: unknown command 'OptionStatusOn' on line #7
Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)
Failed: DllUnregister C:\Program Files\Deskbar\deskbar.dll|1 (file not found)
Failed: DllUnregister \asappsrv.dll|1 (file not found)
Failed: DllUnregister \MyToolBar.dll|1 (file not found)
Failed: DllUnregister \888Bar.dll|1 (file not found)
Failed: ServiceStop Network Monitor (service not found)
Failed: ServiceStop cmdService (service not found)
Failed: ServiceDisable Network Monitor (service not found)
Failed: ServiceDisable cmdService (service not found)
Failed: ServiceDelete Network Monitor (service not found)
Failed: ServiceDelete cmdService (service not found)
Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)
Option pause between commands: 300 ms
Option pause between commands: 50 ms
Failed: FolderDelete C:\Program Files\MsConfigs (folder not found)
Failed: FolderDelete C:\Program Files\winupdates (folder not found)
Failed: FolderDelete C:\Program Files\winupdate (folder not found)
Failed: FolderDelete C:\Program Files\winsupdater (folder not found)
Failed: FolderDelete C:\Program Files\MsUpdate (folder not found)
Failed: FolderDelete C:\Program Files\MsMovies (folder not found)
Failed: FolderDelete C:\Program Files\wmplayer (folder not found)
Failed: FolderDelete C:\Program Files\outlook (folder not found)
Failed: FileDelete C:\Program Files\Common Files\Windows\mc-*-*.exe (operation failed)
Failed: FileDelete C:\Program Files\Common Files\Download\mc-*-*.exe (operation failed)
Failed: FolderDelete C:\WINDOWS\system32\nstlr (folder not found)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\update.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\services.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\activate.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\MyToolBar.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\update.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\services.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\activate.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\MyToolBar.dll (operation failed)
Failed: FolderDelete C:\Program Files\toolbar888 (folder not found)
Failed: FolderDelete C:\Program Files\e-mailpaysu toolbar (folder not found)
Failed: FolderDelete C:\Program Files\EMUSIC TOOLBAR (folder not found)
Failed: FolderDelete C:\Program Files\find dvd toolbar (folder not found)
Failed: FolderDelete C:\Program Files\GULESIDER VERKTøYLINJE (folder not found)
Failed: FolderDelete C:\Program Files\sesam-p4 toolbar (folder not found)
Failed: FolderDelete C:\Program Files\slownik ling (folder not found)
Failed: FolderDelete C:\Program Files\MediaPipe (folder not found)
Failed: FolderDelete C:\Program Files\p2pnetworks (folder not found)
Failed: FileDelete C:\Documents and Settings\kevin\LOADADV*.EXE (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFD713.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFE7CA.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFE85C.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFF9E1.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFFA0D.tmp (operation failed)
Failed: FolderDelete C:\Program Files\Maxifiles (folder not found)
Failed: FolderDelete C:\Program Files\DNS (folder not found)
Failed: FolderDelete C:\Program Files\EQAdvice (folder not found)
Failed: FolderDelete C:\Program Files\FCAdvice (folder not found)
Failed: FolderDelete C:\Program Files\PSCastor (folder not found)
Failed: FolderDelete C:\Program Files\CMIntex (folder not found)
Failed: FolderDelete C:\Program Files\PadsysAssistant (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\FreeProd1 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\FreeProd2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\InetGet (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\InetGet2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\svchostsys (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\simtest (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\misc001 (folder not found)
Failed: FolderDelete C:\Program Files\InetGet2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\VCClient (folder not found)
Failed: FolderDelete C:\Program Files\Network Monitor (folder not found)
Failed: FolderDelete C:\WINDOWS\inet20001 (folder not found)
Failed: FolderDelete C:\WINDOWS\inet20000 (folder not found)
Failed: FolderDelete C:\Program Files\Update06 (folder not found)
Failed: FolderDelete C:\Program Files\Update03 (folder not found)
Failed: FolderDelete C:\Program Files\Update04 (folder not found)
Failed: FolderDelete C:\Program Files\Update08 (folder not found)
Failed: FolderDelete C:\Program Files\W-Update (folder not found)
Failed: FolderDelete C:\Program Files\Yazzle Sudoku (folder not found)
Failed: FolderDelete C:\Program Files\Cas (folder not found)
Failed: FolderDelete C:\Program Files\CasStub (folder not found)
Failed: FolderDelete C:\Program Files\Cas2Stub (folder not found)
Failed: FolderDelete C:\Program Files\ipwins (folder not found)
Failed: FolderDelete C:\Program Files\Ipwindows (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\Snowball Wars (folder not found)
Failed: FolderDelete C:\Program Files\folder.js (folder not found)
Failed: FolderDelete C:\Program Files\ini.ini (folder not found)
Failed: FolderDelete C:\temp (folder not found)
Failed: FolderDelete C:\WINDOWS\mdrive (folder not found)
Failed: FolderDelete C:\WINDOWS\system32\crunner (folder not found)
Failed: FolderDelete C:\Program Files\PECarlin (folder not found)
Failed: FolderDelete C:\Program Files\AXVenore (folder not found)
Failed: FolderDelete C:\Program Files\SDVita (folder not found)
Failed: FolderDelete C:\Program Files\EQBranch (folder not found)
Failed: FolderDelete C:\Program Files\EQArticle (folder not found)
Failed: FolderDelete C:\Program Files\PSHope (folder not found)
Failed: FolderDelete C:\Program Files\Batty (folder not found)
Failed: FolderDelete C:\Program Files\Batty2 (folder not found)
Failed: FolderDelete C:\Program Files\AXFibula (folder not found)
Failed: FolderDelete C:\Program Files\CMFibula (folder not found)
Failed: FolderDelete C:\Program Files\PSLister (folder not found)
Failed: FolderDelete C:\Program Files\PSCloner (folder not found)
Failed: FolderDelete C:\Program Files\PSDream (folder not found)
Failed: FolderDelete C:\Program Files\cmapp (folder not found)
Failed: FolderDelete C:\Program Files\cmman (folder not found)
Failed: FolderDelete C:\Program Files\cmsystem (folder not found)
Failed: FolderDelete C:\Program Files\fcengine (folder not found)
Failed: FolderDelete C:\Program Files\wincmapp (folder not found)
Failed: FolderDelete C:\Program Files\Deskbar\Cache (folder not found)
Failed: FolderDelete C:\Program Files\popupwithcast (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\cloader (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\misc001 (folder not found)
Failed: FolderDelete C:\Program Files\Web Buying (folder not found)
Failed: FolderCreate C:\bintheredunthat (folder already exists)
Failed: FileMove C:\WINDOWS\win*-*.exe|C:\bintheredunthat (source file not found)
Script completed.
et le rapport de antivir :
AntiVir PersonalEdition Classic
Report file date: samedi 22 décembre 2007 00:57
Scanning for 985234 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:57:38
ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:57:38
ANTIVIR3.VDF : 7.0.1.138 185344 Bytes 21/12/2007 17:00:49
AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 21/12/2007 17:00:49
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.2 360488 Bytes 21/12/2007 17:00:49
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21
Configuration settings for the scan:
Jobname..........................: Rootkit search
Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\rootkit.avp
Logging..........................: high
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Scan memory......................: off
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: on
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: high
Expanded search settings.........: 0x00300922
Start of the scan: samedi 22 décembre 2007 00:57
Starting search for hidden objects.
The driver could not be initialized.
End of the scan: samedi 22 décembre 2007 00:57
Used time: 00:03 min
The scan has been done completely.
0 Scanning directories
0 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
0 Files not concerned
0 Archives were scanned
0 Warnings
0 Notes
g!rly
Messages postés
18206
Date d'inscription
vendredi 17 août 2007
Statut
Contributeur
Dernière intervention
30 novembre 2014
407
10 janv. 2008 à 20:00
10 janv. 2008 à 20:00
bonsoir kevin596,
je viens tout juste de rentrer de vacances, je te souhaite mes meilleurs voeux pour cette nouvelle année 2008 ;-)
comme cela fait un petit moment, peux tu poster un nouveau hijack this stp
@+
je viens tout juste de rentrer de vacances, je te souhaite mes meilleurs voeux pour cette nouvelle année 2008 ;-)
comme cela fait un petit moment, peux tu poster un nouveau hijack this stp
@+
^^Marie^^
Messages postés
113926
Date d'inscription
mardi 6 septembre 2005
Statut
Membre
Dernière intervention
28 août 2020
3 276
12 déc. 2007 à 11:04
12 déc. 2007 à 11:04
Salut
Pour avancer
AVG ► Aucune action entreprise. N'a pas fonctionné ;;))
Faut le refaire
Pour avancer
AVG ► Aucune action entreprise. N'a pas fonctionné ;;))
Faut le refaire
Tu l'installes. Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente! Lance AVG Anti-Spyware Clique sur le bouton Analyse (de la barre d'outils) Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Reviens à l'onglet Analyse. Clique sur Analyse complète du système. /!\ Si un fichier est infecté en fin d'analyse /!\ choisis l'option " Appliquer toutes les actions " en bas. Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous" Enregistre ce fichier texte sur ton bureau. Copie/colle le rapport