Ouverture de fenêtre intenpestive!!

Résolu/Fermé
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009 - 12 janv. 2008 à 00:25
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 - 23 févr. 2008 à 18:57
Bonjour,

Ayant lu les autre posts j'ai téléchargé Navilog1
Et voici le rapport, merci de votre aide :
Search Navipromo version 3.4.0 commencé le 11/01/2008 à 23:56:04,46

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 09.01.2008 à 20h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***




*** Recherche dossiers dans C:\WINDOWS ***



*** Recherche dossiers dans C:\Program Files ***



*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***




*** Recherche dossiers dans "C:\Documents and Settings\Gusanodx\application data" ***

...\MessengerSkinner trouvé !


*** Recherche dossiers dans "C:\Documents and Settings\Gusanodx\MENUDM~1\PROGRA~1" ***


*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Fichier(s) caché(s) :

C:\Documents and Settings\Gusanodx\Local Settings\Application Data\paajsbenwg.dat
C:\Documents and Settings\Gusanodx\Local Settings\Application Data\paajsbenwg.exe
C:\Documents and Settings\Gusanodx\Local Settings\Application Data\paajsbenwg_nav.dat
C:\Documents and Settings\Gusanodx\Local Settings\Application Data\paajsbenwg_navps.dat



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans "C:\Documents and Settings\Gusanodx\local settings\application data" *

Fichiers trouvés :

paajsbenwg.exe trouvé !



*** Recherche fichiers ***


C:\WINDOWS\system32\nvs2.inf trouvé !


*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans C:\WINDOWS\system32 :


* Dans "C:\Documents and Settings\Gusanodx\local settings\application data" :

paajsbenwg.dat trouvé !

3)Recherche Certificats :

Certificat Egroup trouvé !

4)Recherche fichiers connus :



*** Analyse terminée le 12/01/2008 à 0:15:12,77 ***

Merci pour votre réponse
A voir également:

116 réponses

Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 03:27
VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Scan started at 21:45:38 28/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\awtrspn.dll
C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\lfdlugwv.dll
C:\WINDOWS\system32\nnnljjk.dll
C:\WINDOWS\system32\qomnnnm.dll
C:\WINDOWS\system32\ssqpmnn.dll
C:\WINDOWS\system32\tuvut.dll
C:\WINDOWS\system32\tuvut.ini
C:\WINDOWS\system32\tuvut.ini2
C:\WINDOWS\system32\tuvwvut.dll
C:\WINDOWS\system32\vtutsrp.dll
C:\WINDOWS\system32\vtuurro.dll
C:\WINDOWS\system32\vwguldfl.ini
C:\WINDOWS\system32\wvutsst.dll
C:\WINDOWS\system32\yayyvtt.dll
C:\WINDOWS\Temp\vid009.exe
C:\WINDOWS\Temp\vid00d.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtrspn.dll
C:\WINDOWS\system32\awtrspn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\byxyaxw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\lfdlugwv.dll
C:\WINDOWS\system32\lfdlugwv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnljjk.dll
C:\WINDOWS\system32\nnnljjk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomnnnm.dll
C:\WINDOWS\system32\qomnnnm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpmnn.dll
C:\WINDOWS\system32\ssqpmnn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.dll
C:\WINDOWS\system32\tuvut.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvut.ini
C:\WINDOWS\system32\tuvut.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.ini2
C:\WINDOWS\system32\tuvut.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvwvut.dll
C:\WINDOWS\system32\tuvwvut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutsrp.dll
C:\WINDOWS\system32\vtutsrp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtuurro.dll
C:\WINDOWS\system32\vtuurro.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vwguldfl.ini
C:\WINDOWS\system32\vwguldfl.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvutsst.dll
C:\WINDOWS\system32\wvutsst.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayyvtt.dll
C:\WINDOWS\system32\yayyvtt.dll Has been deleted!

Attempting to delete C:\WINDOWS\Temp\vid009.exe
C:\WINDOWS\Temp\vid009.exe Has been deleted!

Attempting to delete C:\WINDOWS\Temp\vid00d.exe
C:\WINDOWS\Temp\vid00d.exe Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\byxyaxw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvut.dll
C:\WINDOWS\system32\tuvut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.ini
C:\WINDOWS\system32\tuvut.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.ini2
C:\WINDOWS\system32\tuvut.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Scan started at 00:28:31 29/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\hgghgfe.dll
C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini2
C:\WINDOWS\Temp\vid00d.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\byxyaxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddabx.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\hgghgfe.dll
C:\WINDOWS\system32\hgghgfe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbadd.ini2
C:\WINDOWS\system32\xbadd.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddabx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbadd.ini2
C:\WINDOWS\system32\xbadd.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Scan started at 01:18:12 29/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\vtustqq.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 03:19:35 29/01/2008

Listing files found while scanning....

Tout seul il n'arrivait pas à effacer le vtustqq.dll, alors j'ai mis en safe boot et je l'ai supprimé ; ça a réussie mais en redémarrant des fenetres s'ouvrent, manque des dll et manque le disque??? Aïeeeeeeee
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 03:32
mon antivirus me détecte adware.virtumonde application?? et le met en quarantine!! je l'ai effacé plusieurs fois mais il revient!!
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 04:14
Mince j'avais pas vu un post,, merci bcp!
J'essaie demain car j'y vois + rien.
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 04:31
VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Scan started at 21:45:38 28/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\awtrspn.dll
C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\lfdlugwv.dll
C:\WINDOWS\system32\nnnljjk.dll
C:\WINDOWS\system32\qomnnnm.dll
C:\WINDOWS\system32\ssqpmnn.dll
C:\WINDOWS\system32\tuvut.dll
C:\WINDOWS\system32\tuvut.ini
C:\WINDOWS\system32\tuvut.ini2
C:\WINDOWS\system32\tuvwvut.dll
C:\WINDOWS\system32\vtutsrp.dll
C:\WINDOWS\system32\vtuurro.dll
C:\WINDOWS\system32\vwguldfl.ini
C:\WINDOWS\system32\wvutsst.dll
C:\WINDOWS\system32\yayyvtt.dll
C:\WINDOWS\Temp\vid009.exe
C:\WINDOWS\Temp\vid00d.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtrspn.dll
C:\WINDOWS\system32\awtrspn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\byxyaxw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\lfdlugwv.dll
C:\WINDOWS\system32\lfdlugwv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnljjk.dll
C:\WINDOWS\system32\nnnljjk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomnnnm.dll
C:\WINDOWS\system32\qomnnnm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpmnn.dll
C:\WINDOWS\system32\ssqpmnn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.dll
C:\WINDOWS\system32\tuvut.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvut.ini
C:\WINDOWS\system32\tuvut.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.ini2
C:\WINDOWS\system32\tuvut.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvwvut.dll
C:\WINDOWS\system32\tuvwvut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtutsrp.dll
C:\WINDOWS\system32\vtutsrp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtuurro.dll
C:\WINDOWS\system32\vtuurro.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vwguldfl.ini
C:\WINDOWS\system32\vwguldfl.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvutsst.dll
C:\WINDOWS\system32\wvutsst.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayyvtt.dll
C:\WINDOWS\system32\yayyvtt.dll Has been deleted!

Attempting to delete C:\WINDOWS\Temp\vid009.exe
C:\WINDOWS\Temp\vid009.exe Has been deleted!

Attempting to delete C:\WINDOWS\Temp\vid00d.exe
C:\WINDOWS\Temp\vid00d.exe Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\byxyaxw.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\tuvut.dll
C:\WINDOWS\system32\tuvut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.ini
C:\WINDOWS\system32\tuvut.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvut.ini2
C:\WINDOWS\system32\tuvut.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Scan started at 00:28:31 29/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\hgghgfe.dll
C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini2
C:\WINDOWS\Temp\vid00d.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\byxyaxw.dll
C:\WINDOWS\system32\byxyaxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddabx.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\hgghgfe.dll
C:\WINDOWS\system32\hgghgfe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbadd.ini2
C:\WINDOWS\system32\xbadd.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddabx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xbadd.ini
C:\WINDOWS\system32\xbadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbadd.ini2
C:\WINDOWS\system32\xbadd.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.10

Scan started at 01:18:12 29/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\vtustqq.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\vtustqq.dll
C:\WINDOWS\system32\vtustqq.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.10

Scan started at 03:19:35 29/01/2008

Listing files found while scanning....

C:\WINDOWS\system32\cbaax.dll
C:\WINDOWS\system32\cbxuvvu.dll
C:\WINDOWS\system32\ljjgffg.dll
C:\WINDOWS\system32\opnkhhf.dll
C:\WINDOWS\system32\xaabc.ini
C:\WINDOWS\system32\xaabc.ini2
C:\WINDOWS\system32\yayvvww.dll
C:\WINDOWS\Temp\vid00d.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\cbaax.dll
C:\WINDOWS\system32\cbaax.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\cbxuvvu.dll
C:\WINDOWS\system32\cbxuvvu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ljjgffg.dll
C:\WINDOWS\system32\ljjgffg.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\opnkhhf.dll
C:\WINDOWS\system32\opnkhhf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xaabc.ini
C:\WINDOWS\system32\xaabc.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xaabc.ini2
C:\WINDOWS\system32\xaabc.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayvvww.dll
C:\WINDOWS\system32\yayvvww.dll Has been deleted!

Attempting to delete C:\WINDOWS\Temp\vid00d.exe
C:\WINDOWS\Temp\vid00d.exe Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\cbaax.dll
C:\WINDOWS\system32\cbaax.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ljjgffg.dll
C:\WINDOWS\system32\ljjgffg.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xaabc.ini
C:\WINDOWS\system32\xaabc.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xaabc.ini2
C:\WINDOWS\system32\xaabc.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Beginning removal...

Performing Repairs to the registry.
Done!
Bon je l'ai fais en en mettant les noms en plus.
Maintenant je telécharge l'autre prog.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 13:55
ComboFix 07-08-09.3 - "Gusanodx" 2008-01-29 4:37:56.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.584 [GMT 1:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\Gusanodx\APPLIC~1\addon.dat


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\nm


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))


2008-01-29 04:34 51,200 --a------ C:\WINDOWS\nircmd.exe
2008-01-29 04:24 38,400 --a------ C:\WINDOWS\system32\opnkkhf.dll
2008-01-29 04:09 2,138 --ahs---- C:\WINDOWS\system32\tstss.ini2
2008-01-29 04:08 334,336 --a------ C:\WINDOWS\system32\sstst.dll
2008-01-29 04:06 38,400 --a------ C:\WINDOWS\system32\ljjhhhh.dll
2008-01-29 01:52 38,400 --------- C:\WINDOWS\system32\ljjgffg.dll
2008-01-28 23:59 <REP> d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\vlc
2008-01-28 21:45 <REP> d-------- C:\VundoFix Backups
2008-01-28 11:33 <REP> d--h----- C:\Program Files\ntsecurity
2008-01-27 18:56 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-01-27 18:56 <REP> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2008-01-27 18:33 <REP> d-------- C:\Program Files\VideoLAN
2008-01-24 10:21 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-01-22 21:33 <REP> d-------- C:\Program Files\Trend Micro
2008-01-19 17:49 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-19 13:44 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-01-19 00:12 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-01-16 22:13 <REP> d-------- C:\Program Files\SAGEM Wi-Fi 11g Cardbus adapter
2008-01-16 16:50 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys
2008-01-16 16:50 46,892 --a------ C:\WINDOWS\system32\adadix16.dll
2008-01-16 16:50 4,981 --a------ C:\WINDOWS\system32\AdADIx2K.dll
2008-01-16 16:50 24,576 --a------ C:\WINDOWS\enddisk32.exe
2008-01-16 16:50 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin
2008-01-16 16:50 155,648 --a------ C:\WINDOWS\system32\AdADIx32.dll
2008-01-16 16:50 143,360 --a------ C:\WINDOWS\autoclk.exe
2008-01-16 16:50 143,360 --a------ C:\WINDOWS\adiras.exe
2008-01-16 16:50 117,289 --a------ C:\WINDOWS\system32\drivers\adiusbae.sys
2008-01-16 16:50 114,688 --a------ C:\WINDOWS\system32\unaddrv.exe
2008-01-16 16:50 106,496 --a------ C:\WINDOWS\system32\coclassfast.dll
2008-01-16 16:49 <REP> d-------- C:\Program Files\SAGEM
2008-01-13 10:13 17,024 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2008-01-13 10:13 17,024 --a------ C:\WINDOWS\system32\drivers\usbohci.sys
2008-01-11 23:52 <REP> d-------- C:\Program Files\Navilog1
2008-01-11 22:52 <REP> d-------- C:\Program Files\CCleaner
2007-12-30 11:24 <REP> d-------- C:\Program Files\%temp&


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-01-29 10:58 38400 --a------ C:\WINDOWS\system32\yayvtrq.dll
2008-01-29 02:04 --------- d-------- C:\Program Files\eMule
2008-01-28 23:03 93674 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-01-28 23:03 529968 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-01-28 22:40 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\Skype
2008-01-28 21:36 --------- d-------- C:\Program Files\ods
2008-01-27 19:13 40448 --a------ C:\WINDOWS\system32\NTSpool.exe
2008-01-21 21:03 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\Azureus
2008-01-19 15:46 --------- d-------- C:\Program Files\MediaCoder
2008-01-16 22:13 --------- d--h----- C:\Program Files\InstallShield Installation Information
2008-01-16 22:09 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\U3
2008-01-16 16:50 23 --a------ C:\WINDOWS\system32\drivers\adidsl.cfg
2007-12-30 11:24 --------- d-------- C:\Program Files\%temp&
2007-12-27 23:20 --------- d-------- C:\Program Files\Azureus
2007-12-21 22:24 131348 --a------ C:\WINDOWS\hpoins11.dat
2007-12-21 21:02 --------- d-------- C:\Program Files\Fichiers communs\HP
2007-12-21 20:58 --------- d-------- C:\Program Files\Hewlett-Packard
2007-12-21 08:21 33800 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-12-21 08:20 30216 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 08:19 39944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2007-12-20 18:48 --------- d-------- C:\Program Files\Google
2007-12-20 14:58 --------- d-------- C:\Program Files\HP
2007-12-20 14:19 --------- d-------- C:\Program Files\DAEMON Tools
2007-12-18 20:10 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\SAA
2007-12-18 16:38 --------- d-------- C:\Program Files\SAA
2007-12-18 15:08 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-17 21:40 --------- d-------- C:\Program Files\Windows Live Safety Center
2007-12-17 21:13 --------- d-------- C:\Program Files\Project64 1.6
2007-12-12 19:20 --------- d-------- C:\Program Files\adslTV
2007-12-07 14:50 --------- d-------- C:\Program Files\Microsoft Works
2007-12-07 14:49 --------- d-------- C:\Program Files\MSBuild
2007-12-05 18:30 --------- d-------- C:\Program Files\IVT Corporation
2007-12-02 14:47 --------- d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-01 15:23 --------- d-------- C:\Program Files\Windows Live
2007-12-01 15:21 --------- d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-01 15:13 --------- d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-11-29 16:26 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\Notepad++
2007-11-29 16:25 --------- d-------- C:\Program Files\Notepad++
2007-11-29 12:18 --------- d-------- C:\Program Files\MSXML 6.0
2007-11-29 12:00 --------- d-------- C:\Program Files\Reference Assemblies
2007-11-07 10:28 728576 --a--c--- C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-11-07 10:28 728576 --a------ C:\WINDOWS\system32\lsasrv.dll
2007-10-31 00:23 3590656 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 18:20 360064 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 23:43 1293824 --a--c--- C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-29 23:43 1293824 --a------ C:\WINDOWS\system32\quartz.dll
2004-10-22 16:58 192512 --a------ C:\WINDOWS\inf\rmSagemCARDoem.exe
2004-03-22 19:16 338176 --a------ C:\WINDOWS\inf\setupinf\bcmwl5.sys
2003-02-28 12:32 11776 --a------ C:\WINDOWS\inf\SetScardINF_wxp.exe
2002-11-14 22:32 55808 --a------ C:\WINDOWS\inf\devconScard.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6AB73A29-6A8F-4C73-AB52-D825608601B9}]
2008-01-29 04:09 334336 --a------ C:\WINDOWS\system32\sstst.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98663E21-9CCE-4CF6-863C-911A9523A66F}]
2008-01-29 04:06 38400 --a------ C:\WINDOWS\system32\ljjhhhh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A619728A-B690-463A-BECE-8F3CCF88169A}]
C:\WINDOWS\system32\ddabx.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D1FFF36E-49C8-420F-9088-ADE9E4CD7345}]
C:\WINDOWS\system32\tuvut.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D2C70103-65F1-4F3F-AEAF-DC380846CF77}]
C:\WINDOWS\system32\cbaax.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="soundman.exe" [2001-05-28 19:02 C:\WINDOWS\soundman.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 17:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 17:38]
"CHotkey"="mHotkey.exe" [2001-07-27 16:07 C:\WINDOWS\mHotkey.exe]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 22:11]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 14:57]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 08:21]
"384ff639"="C:\WINDOWS\system32\lfdlugwv.dll" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-11-21 18:14]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"Polar Sync"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 12:24]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\Gusanodx\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-01-16 16:50:20]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-01-23 03:57:13]
SAGEM Wi-Fi 11g Cardbus adapter.lnk - C:\Program Files\SAGEM Wi-Fi 11g Cardbus adapter\Wificard.exe [2005-01-13 11:11:14]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-10-19 14:55:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"NTSpool"=NTSpool.exe
"Windows Printing Driver"=WinPrint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-10-19 14:53 293888]
"{98663E21-9CCE-4CF6-863C-911A9523A66F}"= C:\WINDOWS\system32\ljjhhhh.dll [2008-01-29 04:06 38400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhhh]
ljjhhhh.dll 2008-01-29 04:06 38400 C:\WINDOWS\system32\ljjhhhh.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\sstst

R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys
R0 sbp2port;Pilote de bus de transport/protocole SBP-2;C:\WINDOWS\system32\DRIVERS\sbp2port.sys
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys
R2 ekrn;Eset Service;"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
R2 WSearch;Recherche Windows;C:\WINDOWS\system32\SearchIndexer.exe /Embedding
R3 Afc;PPdus ASPI Shell;C:\WINDOWS\system32\drivers\Afc.sys
R3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
R3 pepifilter;Volume Adapter;C:\WINDOWS\system32\DRIVERS\lv302af.sys
R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI);C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
R3 Slntamr;Smart Link 56K Modem Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys
R3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;C:\WINDOWS\system32\Drivers\WBMS.SYS
S3 adiusbae;USB ADSL LAN Adapter;C:\WINDOWS\system32\DRIVERS\adiusbae.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys
S3 EhttpSrv;Eset HTTP Server;"C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"
S3 idsvc;Windows CardSpace;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 k750bus;Sony Ericsson 750 driver (WDM);C:\WINDOWS\system32\DRIVERS\k750bus.sys
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k750mdfl.sys
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k750mdm.sys
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k750mgmt.sys
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k750obex.sys
S3 MSIRCOMM;Microsoft IR Communications Driver;C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
S3 NBXG7031;NB 802.11g XG703 SP1 Driver;C:\WINDOWS\system32\DRIVERS\WlanUIG.sys
S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
S3 PID_08A0;QuickCam IM(PID_08A0);C:\WINDOWS\system32\DRIVERS\LV302AV.SYS
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys
S3 Start BT in service;Start BT in service;C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
S3 VHidMinidrv;Bluetooth HID Device Service;C:\WINDOWS\system32\drivers\VHIDMini.sys
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da6d19e5-ff33-11db-8dd3-0090f50d29f9}]
AutoRun\command- J:\RunGame.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]
C:\Program Files\ntsecurity\ntsecurity.exe s

Contents of the 'Scheduled Tasks' folder
2008-01-29 03:59:29 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 10:53:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

C:\Program Files\Internet Explorer\iexplore.exe [3008] 0x8633DC60


scanning hidden registry entries ...

scanning hidden files ...

C:\WINDOWS\system32\yayvtrq.dll

scan completed successfully
hidden files: 1

**************************************************************************

Completion time: 2008-01-29 11:06:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2008-01-29 11:05

--- E O F ---


"384ff639"="C:\WINDOWS\system32\lfdlugwv.dll" []
C'est ce Dll qui s'ouvre lorsque je démarre et qui ne fonctionne pas.

Merci pour l'aide.
:-)
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 14:35
Re bonjour,

Je cherche un parefeu qui utilise très peu de ressource et de bonne qualité bien sur! Que pouvez-vous me conseiller?
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
29 janv. 2008 à 18:31
Je crois que c'(est de pire en pire!!
Mon ordi met 3h à démarrer, Nod détecte et met en quarantaine plusieurs trucs!!
0
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 3
29 janv. 2008 à 20:03
Bonsoir

oulalala tout un tas de rapport

si tu ne fait pas ce que je te demande il va être très difficile de t'aider car
tu balance tout un tas de rapport et on ne sait même plus ou ion en ai

bonne nouvelle ton rapprt de combofix
nous montre pas mal de chose à voir
mais j'aurais quand même préféré procéder par étapes combo fait partit de l'étape
mais bon...

je te donne réponse à ton rapport tout à l'heure

@+
0
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 3
29 janv. 2008 à 21:05
selectionne ceci

registry::

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AB73A29-6A8F-4C73-AB52-D825608601B9}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98663E21-9CCE-4CF6-863C-911A9523A66F}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A619728A-B690-463A-BECE-8F3CCF88169A}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1FFF36E-49C8-420F-9088-ADE9E4CD7345}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2C70103-65F1-4F3F-AEAF-DC380846CF77}]

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhhhh]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=-

File::

C:\WINDOWS\system32\opnkkhf.dll
C:\WINDOWS\system32\tstss.ini2
C:\WINDOWS\system32\sstst.dll
C:\WINDOWS\system32\ljjhhhh.dll
C:\WINDOWS\system32\ljjgffg.dll
C:\DOCUME~1\Gusanodx\APPLIC~1\vlc
C:\WINDOWS\system32\yayvtrq.dll
C:\DOCUME~1\Gusanodx\APPLIC~1\Skype
C:\DOCUME~1\Gusanodx\APPLIC~1\Azureus
C:\DOCUME~1\Gusanodx\APPLIC~1\U3
C:\DOCUME~1\Gusanodx\APPLIC~1\SAA
C:\DOCUME~1\Gusanodx\APPLIC~1\Notepad++
C:\WINDOWS\inf\rmSagemCARDoem.exe
C:\WINDOWS\inf\setupinf\bcmwl5.sys
C:\WINDOWS\inf\SetScardINF_wxp.ex
C:\WINDOWS\inf\devconScard.exe


* Copie le texte sélectionné (CTRL+C).
* Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
* Colle le texte copié dans ce bloc-notes (CTRL+V).
* Sauvegarde ce fichier sous le nom de CFScript.txt
* Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
* Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
+ un nouveau rapport hijack
@+
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 00:12
Bonsoir,
J'ai exécute normalement tout ce que vous m'avez demandé de faire ; mais au re-démarrage automatique, voilà ça ne marche pas je tombe sur l'écran pour rentré un mot de passe qui normalement comme je n'ai pas de mot de passe, je tape Ok et là une fenêtre s'ouvre et me met " impossible d'ouvrir une session car il y a limitation de compte"!!
J'essaie 2 fois mais tjrs la meme chose, donc je decide de redémarer de nouveau, même problème!
Donc je démarre avec F8 et je met démarrer avec dernière point de restauration qui fonctionne! Ca marche! l'ordi re démarre et termine le combofix et me donne ce fichier!!


ComboFix 07-08-09.3 - "Gusanodx" 2008-01-29 22:56:25.2 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.458 [GMT 1:00]
Command switches used :: C:\Documents and Settings\Gusanodx\Bureau\CFScript.txt
* Created a new restore point

FILE::
C:\WINDOWS\system32\opnkkhf.dll
C:\WINDOWS\system32\tstss.ini2
C:\WINDOWS\system32\sstst.dll
C:\WINDOWS\system32\ljjhhhh.dll
C:\WINDOWS\system32\ljjgffg.dll
C:\DOCUME~1\Gusanodx\APPLIC~1\vlc
C:\WINDOWS\system32\yayvtrq.dll
C:\DOCUME~1\Gusanodx\APPLIC~1\Skype
C:\DOCUME~1\Gusanodx\APPLIC~1\Azureus
C:\DOCUME~1\Gusanodx\APPLIC~1\U3
C:\DOCUME~1\Gusanodx\APPLIC~1\SAA
C:\DOCUME~1\Gusanodx\APPLIC~1\Notepad++
C:\WINDOWS\inf\rmSagemCARDoem.exe
C:\WINDOWS\inf\setupinf\bcmwl5.sys
C:\WINDOWS\inf\SetScardINF_wxp.ex
C:\WINDOWS\inf\devconScard.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\inf\devconScard.exe
C:\WINDOWS\inf\rmSagemCARDoem.exe
C:\WINDOWS\inf\setupinf\bcmwl5.sys
C:\WINDOWS\system32\ljjgffg.dll
C:\WINDOWS\system32\ljjhhhh.dll
C:\WINDOWS\system32\opnkkhf.dll
C:\WINDOWS\system32\sstst.dll
C:\WINDOWS\system32\tstss.ini2
C:\WINDOWS\system32\yayvtrq.dll


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-29 )))))))))))))))))))))))))))))))


2008-01-29 20:59 37,888 --a------ C:\WINDOWS\system32\opnmlli.dll
2008-01-29 20:38 37,888 --a------ C:\WINDOWS\system32\iifgeeb.dll
2008-01-29 19:42 37,888 --a------ C:\WINDOWS\system32\byxywtt.dll
2008-01-29 18:45 88,640 --a------ C:\WINDOWS\system32\qiproebw.dll
2008-01-29 18:39 69,696 --a------ C:\WINDOWS\system32\iisnojkk.dll
2008-01-29 18:10 38,400 --a------ C:\WINDOWS\system32\xxyaxyy.dll
2008-01-29 16:43 38,400 --a------ C:\WINDOWS\system32\yayyxwt.dll
2008-01-29 04:34 51,200 --a------ C:\WINDOWS\nircmd.exe
2008-01-28 23:59 <REP> d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\vlc
2008-01-28 21:45 <REP> d-------- C:\VundoFix Backups
2008-01-28 11:33 <REP> d--h----- C:\Program Files\ntsecurity
2008-01-27 18:56 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-01-27 18:56 <REP> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2008-01-27 18:33 <REP> d-------- C:\Program Files\VideoLAN
2008-01-24 10:21 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-01-22 21:33 <REP> d-------- C:\Program Files\Trend Micro
2008-01-19 17:49 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-19 13:44 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
2008-01-19 00:12 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-01-16 22:13 <REP> d-------- C:\Program Files\SAGEM Wi-Fi 11g Cardbus adapter
2008-01-16 16:50 50,007 --a------ C:\WINDOWS\system32\drivers\adildr.sys
2008-01-16 16:50 46,892 --a------ C:\WINDOWS\system32\adadix16.dll
2008-01-16 16:50 4,981 --a------ C:\WINDOWS\system32\AdADIx2K.dll
2008-01-16 16:50 24,576 --a------ C:\WINDOWS\enddisk32.exe
2008-01-16 16:50 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin
2008-01-16 16:50 155,648 --a------ C:\WINDOWS\system32\AdADIx32.dll
2008-01-16 16:50 143,360 --a------ C:\WINDOWS\autoclk.exe
2008-01-16 16:50 143,360 --a------ C:\WINDOWS\adiras.exe
2008-01-16 16:50 117,289 --a------ C:\WINDOWS\system32\drivers\adiusbae.sys
2008-01-16 16:50 114,688 --a------ C:\WINDOWS\system32\unaddrv.exe
2008-01-16 16:50 106,496 --a------ C:\WINDOWS\system32\coclassfast.dll
2008-01-16 16:49 <REP> d-------- C:\Program Files\SAGEM
2008-01-13 10:13 17,024 --a--c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2008-01-13 10:13 17,024 --a------ C:\WINDOWS\system32\drivers\usbohci.sys
2008-01-11 23:52 <REP> d-------- C:\Program Files\Navilog1
2008-01-11 22:52 <REP> d-------- C:\Program Files\CCleaner
2007-12-30 11:24 <REP> d-------- C:\Program Files\%temp&


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2008-01-29 23:13 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\Skype
2008-01-29 22:50 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\Azureus
2008-01-29 18:49 --------- d-------- C:\Program Files\ods
2008-01-29 17:46 --------- d-------- C:\Program Files\eMule
2008-01-29 17:44 --------- d-------- C:\Program Files\Diablo II
2008-01-28 23:03 93674 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-01-28 23:03 529968 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-01-27 19:13 40448 --a------ C:\WINDOWS\system32\NTSpool.exe
2008-01-19 15:46 --------- d-------- C:\Program Files\MediaCoder
2008-01-16 22:13 --------- d--h----- C:\Program Files\InstallShield Installation Information
2008-01-16 22:09 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\U3
2008-01-16 16:50 23 --a------ C:\WINDOWS\system32\drivers\adidsl.cfg
2007-12-30 11:24 --------- d-------- C:\Program Files\%temp&
2007-12-27 23:20 --------- d-------- C:\Program Files\Azureus
2007-12-21 22:24 131348 --a------ C:\WINDOWS\hpoins11.dat
2007-12-21 21:02 --------- d-------- C:\Program Files\Fichiers communs\HP
2007-12-21 20:58 --------- d-------- C:\Program Files\Hewlett-Packard
2007-12-21 08:21 33800 --a------ C:\WINDOWS\system32\drivers\epfwtdir.sys
2007-12-21 08:20 30216 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 08:19 39944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2007-12-20 18:48 --------- d-------- C:\Program Files\Google
2007-12-20 14:58 --------- d-------- C:\Program Files\HP
2007-12-20 14:19 --------- d-------- C:\Program Files\DAEMON Tools
2007-12-18 20:10 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\SAA
2007-12-18 16:38 --------- d-------- C:\Program Files\SAA
2007-12-18 15:08 685816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-12-17 21:40 --------- d-------- C:\Program Files\Windows Live Safety Center
2007-12-17 21:13 --------- d-------- C:\Program Files\Project64 1.6
2007-12-12 19:20 --------- d-------- C:\Program Files\adslTV
2007-12-07 14:50 --------- d-------- C:\Program Files\Microsoft Works
2007-12-07 14:49 --------- d-------- C:\Program Files\MSBuild
2007-12-05 18:30 --------- d-------- C:\Program Files\IVT Corporation
2007-12-02 14:47 --------- d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-01 15:23 --------- d-------- C:\Program Files\Windows Live
2007-12-01 15:21 --------- d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-01 15:13 --------- d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-11-29 16:26 --------- d-------- C:\DOCUME~1\Gusanodx\APPLIC~1\Notepad++
2007-11-29 16:25 --------- d-------- C:\Program Files\Notepad++
2007-11-29 12:18 --------- d-------- C:\Program Files\MSXML 6.0
2007-11-29 12:00 --------- d-------- C:\Program Files\Reference Assemblies
2007-11-07 10:28 728576 --a--c--- C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-11-07 10:28 728576 --a------ C:\WINDOWS\system32\lsasrv.dll
2007-10-31 00:23 3590656 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 18:20 360064 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 23:43 1293824 --a--c--- C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-29 23:43 1293824 --a------ C:\WINDOWS\system32\quartz.dll
2003-02-28 12:32 11776 --a------ C:\WINDOWS\inf\SetScardINF_wxp.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="soundman.exe" [2001-05-28 19:02 C:\WINDOWS\soundman.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 17:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 17:38]
"CHotkey"="mHotkey.exe" [2001-07-27 16:07 C:\WINDOWS\mHotkey.exe]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 22:11]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 14:57]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 15:06]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 15:02]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-12-21 08:21]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"BM3b7cc5a5"="C:\WINDOWS\system32\iisnojkk.dll" [2008-01-29 18:39]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-11-21 18:14]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"Polar Sync"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 12:24]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t

C:\Documents and Settings\Gusanodx\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-01-16 16:50:20]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-01-23 03:57:13]
SAGEM Wi-Fi 11g Cardbus adapter.lnk - C:\Program Files\SAGEM Wi-Fi 11g Cardbus adapter\Wificard.exe [2005-01-13 11:11:14]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2006-10-19 14:55:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"NTSpool"=NTSpool.exe
"Windows Printing Driver"=WinPrint.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-10-19 14:53 293888]

R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\RecAgent.sys
R0 sbp2port;Pilote de bus de transport/protocole SBP-2;C:\WINDOWS\system32\DRIVERS\sbp2port.sys
R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys
R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys
R2 ekrn;Eset Service;"C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe"
R2 WSearch;Recherche Windows;C:\WINDOWS\system32\SearchIndexer.exe /Embedding
R3 Afc;PPdus ASPI Shell;C:\WINDOWS\system32\drivers\Afc.sys
R3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
R3 pepifilter;Volume Adapter;C:\WINDOWS\system32\DRIVERS\lv302af.sys
R3 PID_PEPI;Logitech QuickCam IM(PID_PEPI);C:\WINDOWS\system32\DRIVERS\LV302V32.SYS
R3 Slntamr;Smart Link 56K Modem Driver;C:\WINDOWS\system32\DRIVERS\slntamr.sys
R3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
R3 WBMS;Winbond Memory Stick Storage (MS) Device Driver;C:\WINDOWS\system32\Drivers\WBMS.SYS
S3 adiusbae;USB ADSL LAN Adapter;C:\WINDOWS\system32\DRIVERS\adiusbae.sys
S3 BTNetFilter;Bluetooth Network Filter;\??\C:\Program Files\IVT Corporation\BlueSoleil\Device\Win2k\BTNetFilter.sys
S3 EhttpSrv;Eset HTTP Server;"C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe"
S3 idsvc;Windows CardSpace;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
S3 k750bus;Sony Ericsson 750 driver (WDM);C:\WINDOWS\system32\DRIVERS\k750bus.sys
S3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k750mdfl.sys
S3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k750mdm.sys
S3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k750mgmt.sys
S3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k750obex.sys
S3 MSIRCOMM;Microsoft IR Communications Driver;C:\WINDOWS\system32\DRIVERS\MSIRCOMM.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
S3 NBXG7031;NB 802.11g XG703 SP1 Driver;C:\WINDOWS\system32\DRIVERS\WlanUIG.sys
S3 NtMtlFax;NtMtlFax;C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
S3 PID_08A0;QuickCam IM(PID_08A0);C:\WINDOWS\system32\DRIVERS\LV302AV.SYS
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\Slnthal.sys
S3 Start BT in service;Start BT in service;C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
S3 VHidMinidrv;Bluetooth HID Device Service;C:\WINDOWS\system32\drivers\VHIDMini.sys
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;"C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da6d19e5-ff33-11db-8dd3-0090f50d29f9}]
AutoRun\command- J:\RunGame.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9B71D88C-C598-4935-C5D1-43AA4DB90836}]
C:\Program Files\ntsecurity\ntsecurity.exe s

Contents of the 'Scheduled Tasks' folder
2008-01-29 22:38:55 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 23:36:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

C:\Program Files\Internet Explorer\iexplore.exe [3856] 0x8633F020


scanning hidden registry entries ...

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"OfflineDetectionPending"=dword:00000001

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2008-01-29 23:44:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2008-01-29 23:43
C:\ComboFix2.txt ... 2008-01-29 11:06

--- E O F ---

Merci de l'aide!!
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 00:28
Voià le rapport... Je n'ai fais ni touché entre et je ne fais rien avant votre réponse.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:26:20, on 30/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\SAGEM Wi-Fi 11g Cardbus adapter\Wificard.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BM3b7cc5a5] Rundll32.exe "C:\WINDOWS\system32\iisnojkk.dll",s
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Policies\Explorer\Run: [NTSpool] NTSpool.exe
O4 - HKCU\..\Policies\Explorer\Run: [Windows Printing Driver] WinPrint.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: SAGEM Wi-Fi 11g Cardbus adapter.lnk = C:\Program Files\SAGEM Wi-Fi 11g Cardbus adapter\Wificard.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{192BFB49-9AB7-44BE-BAF6-3874CBACAD65}: NameServer = 212.30.96.108,213.203.124.146
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8B834EE-BCC3-41E4-99CF-7A5441346EA9}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = geca.cf.minaz.cu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = geca.cf.minaz.cu
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = geca.cf.minaz.cu
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = geca.cf.minaz.cu
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 00:31
Est ce que je peux avoir des explications sur ce qui se passe dans l'ordi? Virus, trojan ou autre chose!!
Pourquoi windefendeur et Nod ne font rien, ils les bloques et les mettent en quarantaine et c'est tout!!??
0
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 3
30 janv. 2008 à 21:36
Bonsoir

en effet la suppression ce fait mais ca reviens :-(
windefendeur et Nod ne font pas la suppression
car très difficile à supprimer

refais la manip avec combofix mais en mode sans échec
donc copie ce texte dans le bloc note
et tu le nomme
ensuite démarre en mode sans échec et fait la manip

C:\WINDOWS\system32\opnmlli.dll
C:\WINDOWS\system32\iifgeeb.dll
C:\WINDOWS\system32\byxywtt.dll
C:\WINDOWS\system32\qiproebw.dll
C:\WINDOWS\system32\iisnojkk.dll
C:\WINDOWS\system32\xxyaxyy.dll
C:\WINDOWS\system32\yayyxwt.dll
C:\WINDOWS\nircmd.exe


ensuite en mode normal
fait un scan en ligne

avec bitdefender et colle le rapport

https://www.bitdefender.com/toolbox/

un tuto
https://kerio.probb.fr/

@+
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 21:55
je copie ce texte :
C:\WINDOWS\system32\opnmlli.dll
C:\WINDOWS\system32\iifgeeb.dll
C:\WINDOWS\system32\byxywtt.dll
C:\WINDOWS\system32\qiproebw.dll
C:\WINDOWS\system32\iisnojkk.dll
C:\WINDOWS\system32\xxyaxyy.dll
C:\WINDOWS\system32\yayyxwt.dll
C:\WINDOWS\nircmd.exe

et je le nomme comment? CFScript.txt?
0
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 3
30 janv. 2008 à 21:59
oui
CFScript.txt
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 22:02
Excusez moi je préférais une confirmation? DSL.
0
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 3
30 janv. 2008 à 22:12
pas de soucis ;-)
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 22:30
Je n'arrive pas à démarrer en mode sans echec, il faut que je re démarre en mode dernière bonne configuration sinon il me dit que il y a une limitation de compte!!
Que fais -je?
0
ep44 Messages postés 7393 Date d'inscription samedi 10 novembre 2007 Statut Contributeur Dernière intervention 11 novembre 2010 3
30 janv. 2008 à 22:39
essaye en mode normal

ensuite pense à faire le scan en ligne
@+
0
Dangmart Messages postés 72 Date d'inscription vendredi 11 janvier 2008 Statut Membre Dernière intervention 25 avril 2009
30 janv. 2008 à 22:46
Ok merci, mais pourquoi cette limitation? A cause des vir/troj?
@+
0